From 4f96b1e73f0f4f4519ec80e02d2f60dc6beaf521 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 28 Jan 2025 21:32:06 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7r6v-mxc2-pg49.json | 2 +- .../GHSA-93cg-vfx4-pxr4.json | 5 +- .../GHSA-3rhc-44qf-c226.json | 3 +- .../GHSA-8mxm-mxmw-hjrg.json | 6 +- .../GHSA-fgc6-vr5x-6xch.json | 3 +- .../GHSA-wq2r-8c3h-3jr4.json | 1 + .../GHSA-fw24-9x85-rmf8.json | 2 +- .../GHSA-xq4r-4xfh-vch8.json | 2 +- .../GHSA-7chf-chrh-74q7.json | 1 + .../GHSA-fhrf-5824-hj9w.json | 2 +- .../GHSA-h74m-whwv-f8j4.json | 4 +- .../GHSA-mfrg-mc7h-8xrw.json | 2 +- .../GHSA-mfv7-6rh8-77p4.json | 6 +- .../GHSA-vq44-9mcp-gv3x.json | 4 +- .../GHSA-78gp-j22r-4mpj.json | 6 +- .../GHSA-q3q6-3x37-g8gw.json | 6 +- .../GHSA-78q8-8pcx-x7p6.json | 6 +- .../GHSA-8vj6-3p64-gcfr.json | 6 +- .../GHSA-hgvv-c4m6-65wv.json | 6 +- .../GHSA-jc8g-jr84-hpjx.json | 6 +- .../GHSA-mh75-c4h2-v887.json | 6 +- .../GHSA-qggf-x7gv-2c34.json | 6 +- .../GHSA-wqr4-54vx-9x9m.json | 6 +- .../GHSA-982x-mjmg-rfmg.json | 6 +- .../GHSA-x5qf-rm27-rgf2.json | 6 +- .../GHSA-m582-gvhc-6wg7.json | 3 +- .../GHSA-2hgr-prp4-cr9p.json | 36 ++++++++++++ .../GHSA-2qh5-xjr3-fwj3.json | 15 +++-- .../GHSA-2r3p-xw5g-5q9x.json | 15 +++-- .../GHSA-2wgx-r653-jrmq.json | 15 +++-- .../GHSA-2xfh-jfm3-6xpr.json | 15 +++-- .../GHSA-345g-rh3c-p73g.json | 50 +++++++++++++++++ .../GHSA-3j5m-4qj3-wjqr.json | 36 ++++++++++++ .../GHSA-3q27-5m93-xfm4.json | 36 ++++++++++++ .../GHSA-3v4j-7fgr-fp96.json | 15 +++-- .../GHSA-47hm-pp24-wmmp.json | 15 +++-- .../GHSA-4cf6-q58x-cj63.json | 15 +++-- .../GHSA-4h7q-63rq-hcw7.json | 15 +++-- .../GHSA-4mrr-3cmp-q26r.json | 15 +++-- .../GHSA-4mwx-vgq4-7vr5.json | 15 +++-- .../GHSA-53v8-f936-c2xp.json | 15 +++-- .../GHSA-5j2j-3qxv-fcmx.json | 15 +++-- .../GHSA-5q2h-rcfj-xc9g.json | 36 ++++++++++++ .../GHSA-679g-g57f-hfc6.json | 15 +++-- .../GHSA-6m9w-gxx9-4gqr.json | 15 +++-- .../GHSA-6v24-x43m-jfhm.json | 36 ++++++++++++ .../GHSA-6wqf-f4xj-mxq4.json | 15 +++-- .../GHSA-72rq-mhpg-9q3m.json | 15 +++-- .../GHSA-7jq5-8rmw-j9wh.json | 11 +++- .../GHSA-8787-qmx9-7w46.json | 15 +++-- .../GHSA-88q7-6vxh-w5q7.json | 33 +++++++++++ .../GHSA-8fjm-9j4r-q49r.json | 40 +++++++++++++ .../GHSA-8jc8-vxw9-8xxp.json | 40 +++++++++++++ .../GHSA-8xh7-m55w-7ww7.json | 15 +++-- .../GHSA-93hw-75c6-jqv2.json | 15 +++-- .../GHSA-97mv-g3jg-wg68.json | 15 +++-- .../GHSA-9q3v-94jq-7v4q.json | 15 +++-- .../GHSA-9qc8-8f6v-4qc3.json | 15 +++-- .../GHSA-9w2g-9v3r-27rp.json | 15 +++-- .../GHSA-cwgj-88jc-p385.json | 15 +++-- .../GHSA-cwp3-3mxc-v33w.json | 56 +++++++++++++++++++ .../GHSA-f39m-g6qq-h3xv.json | 15 +++-- .../GHSA-f8mp-8r5c-5pw4.json | 15 +++-- .../GHSA-fv95-67f8-c94p.json | 36 ++++++++++++ .../GHSA-g39c-whf8-f5f9.json | 36 ++++++++++++ .../GHSA-g5q2-2254-cw52.json | 36 ++++++++++++ .../GHSA-g99x-gcm8-hch3.json | 15 +++-- .../GHSA-gg32-cp5g-4m8x.json | 15 +++-- .../GHSA-gh56-9g95-mhj6.json | 15 +++-- .../GHSA-gvc8-8jhg-7556.json | 15 +++-- .../GHSA-h4fw-wmp3-pv59.json | 15 +++-- .../GHSA-h5px-98xh-rpjj.json | 15 +++-- .../GHSA-h5qg-fjxf-6rch.json | 15 +++-- .../GHSA-h75c-q767-27j6.json | 15 +++-- .../GHSA-hf39-rpqx-2w3q.json | 36 ++++++++++++ .../GHSA-j263-jwmh-6jmf.json | 33 +++++++++++ .../GHSA-jqpc-q3rg-3f4f.json | 15 +++-- .../GHSA-jrx3-7w53-466r.json | 15 +++-- .../GHSA-mjp5-6cq8-qv5g.json | 36 ++++++++++++ .../GHSA-p44p-wgq8-46qm.json | 15 +++-- .../GHSA-p59h-7g7v-xp8x.json | 15 +++-- .../GHSA-p853-4v42-h45f.json | 36 ++++++++++++ .../GHSA-q4mr-xqpc-5xvx.json | 15 +++-- .../GHSA-qv2m-4wv2-f33h.json | 15 +++-- .../GHSA-qx57-5369-xrr8.json | 15 +++-- .../GHSA-r24f-5x7x-cfp5.json | 15 +++-- .../GHSA-r2h5-cvfq-6cgj.json | 15 +++-- .../GHSA-r396-g535-84pc.json | 15 +++-- .../GHSA-r5hp-6mxm-95xh.json | 15 +++-- .../GHSA-r86g-243j-mqp7.json | 15 +++-- .../GHSA-rrg9-j69g-xfm7.json | 15 +++-- .../GHSA-rx3r-45qh-9rcc.json | 15 +++-- .../GHSA-vwg3-f59h-rpvc.json | 36 ++++++++++++ .../GHSA-w4p3-vcx6-ggv5.json | 36 ++++++++++++ .../GHSA-w7hg-77m4-rh58.json | 15 +++-- .../GHSA-wf2q-62vr-q7gv.json | 15 +++-- .../GHSA-wmwg-vmx2-qg37.json | 33 +++++++++++ .../GHSA-wp75-3w5f-vg4w.json | 15 +++-- .../GHSA-wq23-xq9q-wf8w.json | 33 +++++++++++ .../GHSA-wx72-xp52-v927.json | 36 ++++++++++++ .../GHSA-x36x-qfrj-p4p5.json | 15 +++-- .../GHSA-x76x-v36q-wqrf.json | 15 +++-- .../GHSA-xh5q-pch5-g3xq.json | 6 +- .../GHSA-xxvc-c328-56m6.json | 36 ++++++++++++ 104 files changed, 1529 insertions(+), 253 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2hgr-prp4-cr9p/GHSA-2hgr-prp4-cr9p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-345g-rh3c-p73g/GHSA-345g-rh3c-p73g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3j5m-4qj3-wjqr/GHSA-3j5m-4qj3-wjqr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3q27-5m93-xfm4/GHSA-3q27-5m93-xfm4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5q2h-rcfj-xc9g/GHSA-5q2h-rcfj-xc9g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6v24-x43m-jfhm/GHSA-6v24-x43m-jfhm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8fjm-9j4r-q49r/GHSA-8fjm-9j4r-q49r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8jc8-vxw9-8xxp/GHSA-8jc8-vxw9-8xxp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cwp3-3mxc-v33w/GHSA-cwp3-3mxc-v33w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fv95-67f8-c94p/GHSA-fv95-67f8-c94p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g39c-whf8-f5f9/GHSA-g39c-whf8-f5f9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g5q2-2254-cw52/GHSA-g5q2-2254-cw52.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hf39-rpqx-2w3q/GHSA-hf39-rpqx-2w3q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j263-jwmh-6jmf/GHSA-j263-jwmh-6jmf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mjp5-6cq8-qv5g/GHSA-mjp5-6cq8-qv5g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p853-4v42-h45f/GHSA-p853-4v42-h45f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vwg3-f59h-rpvc/GHSA-vwg3-f59h-rpvc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w4p3-vcx6-ggv5/GHSA-w4p3-vcx6-ggv5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wmwg-vmx2-qg37/GHSA-wmwg-vmx2-qg37.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wx72-xp52-v927/GHSA-wx72-xp52-v927.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xxvc-c328-56m6/GHSA-xxvc-c328-56m6.json diff --git a/advisories/unreviewed/2022/05/GHSA-7r6v-mxc2-pg49/GHSA-7r6v-mxc2-pg49.json b/advisories/unreviewed/2022/05/GHSA-7r6v-mxc2-pg49/GHSA-7r6v-mxc2-pg49.json index e644ef2893f..8eda2b6ca70 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r6v-mxc2-pg49/GHSA-7r6v-mxc2-pg49.json +++ b/advisories/unreviewed/2022/05/GHSA-7r6v-mxc2-pg49/GHSA-7r6v-mxc2-pg49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r6v-mxc2-pg49", - "modified": "2023-12-21T03:30:24Z", + "modified": "2025-01-28T21:30:58Z", "published": "2022-05-14T01:14:49Z", "aliases": [ "CVE-2015-4852" diff --git a/advisories/unreviewed/2022/05/GHSA-93cg-vfx4-pxr4/GHSA-93cg-vfx4-pxr4.json b/advisories/unreviewed/2022/05/GHSA-93cg-vfx4-pxr4/GHSA-93cg-vfx4-pxr4.json index e4440d640c1..79560118033 100644 --- a/advisories/unreviewed/2022/05/GHSA-93cg-vfx4-pxr4/GHSA-93cg-vfx4-pxr4.json +++ b/advisories/unreviewed/2022/05/GHSA-93cg-vfx4-pxr4/GHSA-93cg-vfx4-pxr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93cg-vfx4-pxr4", - "modified": "2022-05-14T02:09:45Z", + "modified": "2025-01-28T21:30:58Z", "published": "2022-05-14T02:09:45Z", "aliases": [ "CVE-2016-1646" @@ -66,7 +66,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-3rhc-44qf-c226/GHSA-3rhc-44qf-c226.json b/advisories/unreviewed/2023/05/GHSA-3rhc-44qf-c226/GHSA-3rhc-44qf-c226.json index 46a840c8ed0..09ab9454d41 100644 --- a/advisories/unreviewed/2023/05/GHSA-3rhc-44qf-c226/GHSA-3rhc-44qf-c226.json +++ b/advisories/unreviewed/2023/05/GHSA-3rhc-44qf-c226/GHSA-3rhc-44qf-c226.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-494" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-8mxm-mxmw-hjrg/GHSA-8mxm-mxmw-hjrg.json b/advisories/unreviewed/2023/05/GHSA-8mxm-mxmw-hjrg/GHSA-8mxm-mxmw-hjrg.json index 95fd7b64fc9..b2af1fa9fc0 100644 --- a/advisories/unreviewed/2023/05/GHSA-8mxm-mxmw-hjrg/GHSA-8mxm-mxmw-hjrg.json +++ b/advisories/unreviewed/2023/05/GHSA-8mxm-mxmw-hjrg/GHSA-8mxm-mxmw-hjrg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mxm-mxmw-hjrg", - "modified": "2024-04-04T03:58:11Z", + "modified": "2025-01-28T21:30:59Z", "published": "2023-05-10T00:30:16Z", "aliases": [ "CVE-2023-28128" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://forums.ivanti.com/s/article/ZDI-CAN-17812-Ivanti-Avalanche-FileStoreConfig-Arbitrary-File-Upload-Remote-Code-Execution-Vulnerability?language=en_US" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/172398" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/172398/Ivanti-Avalanche-FileStoreConfig-Shell-Upload.html" diff --git a/advisories/unreviewed/2023/05/GHSA-fgc6-vr5x-6xch/GHSA-fgc6-vr5x-6xch.json b/advisories/unreviewed/2023/05/GHSA-fgc6-vr5x-6xch/GHSA-fgc6-vr5x-6xch.json index 9195da71a0a..41aa8e66906 100644 --- a/advisories/unreviewed/2023/05/GHSA-fgc6-vr5x-6xch/GHSA-fgc6-vr5x-6xch.json +++ b/advisories/unreviewed/2023/05/GHSA-fgc6-vr5x-6xch/GHSA-fgc6-vr5x-6xch.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-346" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-wq2r-8c3h-3jr4/GHSA-wq2r-8c3h-3jr4.json b/advisories/unreviewed/2023/05/GHSA-wq2r-8c3h-3jr4/GHSA-wq2r-8c3h-3jr4.json index 2facb58a636..222499fdd09 100644 --- a/advisories/unreviewed/2023/05/GHSA-wq2r-8c3h-3jr4/GHSA-wq2r-8c3h-3jr4.json +++ b/advisories/unreviewed/2023/05/GHSA-wq2r-8c3h-3jr4/GHSA-wq2r-8c3h-3jr4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-732", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-fw24-9x85-rmf8/GHSA-fw24-9x85-rmf8.json b/advisories/unreviewed/2023/07/GHSA-fw24-9x85-rmf8/GHSA-fw24-9x85-rmf8.json index 4dc4336858e..a9fc5e6cd9a 100644 --- a/advisories/unreviewed/2023/07/GHSA-fw24-9x85-rmf8/GHSA-fw24-9x85-rmf8.json +++ b/advisories/unreviewed/2023/07/GHSA-fw24-9x85-rmf8/GHSA-fw24-9x85-rmf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw24-9x85-rmf8", - "modified": "2024-04-04T05:40:29Z", + "modified": "2025-01-28T21:30:58Z", "published": "2023-07-06T21:14:54Z", "aliases": [ "CVE-2023-22788" diff --git a/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json b/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json index 7c45f564172..47c4e9b67a9 100644 --- a/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json +++ b/advisories/unreviewed/2024/02/GHSA-xq4r-4xfh-vch8/GHSA-xq4r-4xfh-vch8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq4r-4xfh-vch8", - "modified": "2024-02-20T15:31:05Z", + "modified": "2025-01-28T21:30:59Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-26270" diff --git a/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json b/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json index 9aa25830618..fad49c5e9fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json +++ b/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json b/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json index 63e549ad965..da62aadf308 100644 --- a/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json +++ b/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhrf-5824-hj9w", - "modified": "2024-03-27T03:31:17Z", + "modified": "2025-01-28T21:30:59Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-2203" diff --git a/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json b/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json index a521bf5da1b..1574bc26ec6 100644 --- a/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json +++ b/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json b/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json index 6fddf5db0dc..c034afd88b7 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json +++ b/advisories/unreviewed/2024/03/GHSA-mfrg-mc7h-8xrw/GHSA-mfrg-mc7h-8xrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfrg-mc7h-8xrw", - "modified": "2024-08-27T15:32:42Z", + "modified": "2025-01-28T21:30:59Z", "published": "2024-03-18T00:30:44Z", "aliases": [ "CVE-2024-23139" diff --git a/advisories/unreviewed/2024/03/GHSA-mfv7-6rh8-77p4/GHSA-mfv7-6rh8-77p4.json b/advisories/unreviewed/2024/03/GHSA-mfv7-6rh8-77p4/GHSA-mfv7-6rh8-77p4.json index 60eb6a808d4..e4fd9ed5a32 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfv7-6rh8-77p4/GHSA-mfv7-6rh8-77p4.json +++ b/advisories/unreviewed/2024/03/GHSA-mfv7-6rh8-77p4/GHSA-mfv7-6rh8-77p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfv7-6rh8-77p4", - "modified": "2024-03-27T09:30:40Z", + "modified": "2025-01-28T21:30:59Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-2120" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vq44-9mcp-gv3x/GHSA-vq44-9mcp-gv3x.json b/advisories/unreviewed/2024/03/GHSA-vq44-9mcp-gv3x/GHSA-vq44-9mcp-gv3x.json index 45b7003b83e..45501c5693c 100644 --- a/advisories/unreviewed/2024/03/GHSA-vq44-9mcp-gv3x/GHSA-vq44-9mcp-gv3x.json +++ b/advisories/unreviewed/2024/03/GHSA-vq44-9mcp-gv3x/GHSA-vq44-9mcp-gv3x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json b/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json index c103ed7a221..1ddc42d29fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json +++ b/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78gp-j22r-4mpj", - "modified": "2024-04-10T15:30:39Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-04-10T15:30:39Z", "aliases": [ "CVE-2024-1042" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json index 6be92d82ebe..2ea1ab9a8c0 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json +++ b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3q6-3x37-g8gw", - "modified": "2024-04-09T21:32:00Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-04-09T21:32:00Z", "aliases": [ "CVE-2024-3214" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1236" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-78q8-8pcx-x7p6/GHSA-78q8-8pcx-x7p6.json b/advisories/unreviewed/2024/05/GHSA-78q8-8pcx-x7p6/GHSA-78q8-8pcx-x7p6.json index 1ebdbd03328..00bcd82df3c 100644 --- a/advisories/unreviewed/2024/05/GHSA-78q8-8pcx-x7p6/GHSA-78q8-8pcx-x7p6.json +++ b/advisories/unreviewed/2024/05/GHSA-78q8-8pcx-x7p6/GHSA-78q8-8pcx-x7p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78q8-8pcx-x7p6", - "modified": "2024-05-02T18:30:52Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-02T18:30:52Z", "aliases": [ "CVE-2024-2084" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8vj6-3p64-gcfr/GHSA-8vj6-3p64-gcfr.json b/advisories/unreviewed/2024/05/GHSA-8vj6-3p64-gcfr/GHSA-8vj6-3p64-gcfr.json index 07793c701d3..bd0b087dcc3 100644 --- a/advisories/unreviewed/2024/05/GHSA-8vj6-3p64-gcfr/GHSA-8vj6-3p64-gcfr.json +++ b/advisories/unreviewed/2024/05/GHSA-8vj6-3p64-gcfr/GHSA-8vj6-3p64-gcfr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vj6-3p64-gcfr", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-2085" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json b/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json index a1f148f3b9c..8d29ffbc1a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json +++ b/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hgvv-c4m6-65wv", - "modified": "2024-05-21T09:31:17Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-21T09:31:17Z", "aliases": [ "CVE-2024-4875" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jc8g-jr84-hpjx/GHSA-jc8g-jr84-hpjx.json b/advisories/unreviewed/2024/05/GHSA-jc8g-jr84-hpjx/GHSA-jc8g-jr84-hpjx.json index 7a944ba3b44..d267e662ab8 100644 --- a/advisories/unreviewed/2024/05/GHSA-jc8g-jr84-hpjx/GHSA-jc8g-jr84-hpjx.json +++ b/advisories/unreviewed/2024/05/GHSA-jc8g-jr84-hpjx/GHSA-jc8g-jr84-hpjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc8g-jr84-hpjx", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3308" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mh75-c4h2-v887/GHSA-mh75-c4h2-v887.json b/advisories/unreviewed/2024/05/GHSA-mh75-c4h2-v887/GHSA-mh75-c4h2-v887.json index faf6ecde481..b0b68ff9d21 100644 --- a/advisories/unreviewed/2024/05/GHSA-mh75-c4h2-v887/GHSA-mh75-c4h2-v887.json +++ b/advisories/unreviewed/2024/05/GHSA-mh75-c4h2-v887/GHSA-mh75-c4h2-v887.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh75-c4h2-v887", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3307" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qggf-x7gv-2c34/GHSA-qggf-x7gv-2c34.json b/advisories/unreviewed/2024/05/GHSA-qggf-x7gv-2c34/GHSA-qggf-x7gv-2c34.json index a786f98e5ae..f9fca7f0a7d 100644 --- a/advisories/unreviewed/2024/05/GHSA-qggf-x7gv-2c34/GHSA-qggf-x7gv-2c34.json +++ b/advisories/unreviewed/2024/05/GHSA-qggf-x7gv-2c34/GHSA-qggf-x7gv-2c34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qggf-x7gv-2c34", - "modified": "2024-05-14T18:30:53Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-14T18:30:53Z", "aliases": [ "CVE-2024-3990" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wqr4-54vx-9x9m/GHSA-wqr4-54vx-9x9m.json b/advisories/unreviewed/2024/05/GHSA-wqr4-54vx-9x9m/GHSA-wqr4-54vx-9x9m.json index e2ba32fa3ea..76e24a0af15 100644 --- a/advisories/unreviewed/2024/05/GHSA-wqr4-54vx-9x9m/GHSA-wqr4-54vx-9x9m.json +++ b/advisories/unreviewed/2024/05/GHSA-wqr4-54vx-9x9m/GHSA-wqr4-54vx-9x9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqr4-54vx-9x9m", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-2790" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json b/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json index 849c0841f9d..bd8765ef47a 100644 --- a/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json +++ b/advisories/unreviewed/2024/06/GHSA-982x-mjmg-rfmg/GHSA-982x-mjmg-rfmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-982x-mjmg-rfmg", - "modified": "2024-06-26T03:31:50Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-06-26T03:31:50Z", "aliases": [ "CVE-2024-5173" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-x5qf-rm27-rgf2/GHSA-x5qf-rm27-rgf2.json b/advisories/unreviewed/2024/06/GHSA-x5qf-rm27-rgf2/GHSA-x5qf-rm27-rgf2.json index f4a3ec227ea..b2cfa4e7ac8 100644 --- a/advisories/unreviewed/2024/06/GHSA-x5qf-rm27-rgf2/GHSA-x5qf-rm27-rgf2.json +++ b/advisories/unreviewed/2024/06/GHSA-x5qf-rm27-rgf2/GHSA-x5qf-rm27-rgf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5qf-rm27-rgf2", - "modified": "2024-06-26T09:37:03Z", + "modified": "2025-01-28T21:31:00Z", "published": "2024-06-26T09:37:03Z", "aliases": [ "CVE-2024-5215" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-m582-gvhc-6wg7/GHSA-m582-gvhc-6wg7.json b/advisories/unreviewed/2024/10/GHSA-m582-gvhc-6wg7/GHSA-m582-gvhc-6wg7.json index e025b958c6f..93d58109a11 100644 --- a/advisories/unreviewed/2024/10/GHSA-m582-gvhc-6wg7/GHSA-m582-gvhc-6wg7.json +++ b/advisories/unreviewed/2024/10/GHSA-m582-gvhc-6wg7/GHSA-m582-gvhc-6wg7.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-2hgr-prp4-cr9p/GHSA-2hgr-prp4-cr9p.json b/advisories/unreviewed/2025/01/GHSA-2hgr-prp4-cr9p/GHSA-2hgr-prp4-cr9p.json new file mode 100644 index 00000000000..ff26b860293 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2hgr-prp4-cr9p/GHSA-2hgr-prp4-cr9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hgr-prp4-cr9p", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-34732" + ], + "details": "In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34732" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2qh5-xjr3-fwj3/GHSA-2qh5-xjr3-fwj3.json b/advisories/unreviewed/2025/01/GHSA-2qh5-xjr3-fwj3/GHSA-2qh5-xjr3-fwj3.json index 9c0d56dc642..977c3460e60 100644 --- a/advisories/unreviewed/2025/01/GHSA-2qh5-xjr3-fwj3/GHSA-2qh5-xjr3-fwj3.json +++ b/advisories/unreviewed/2025/01/GHSA-2qh5-xjr3-fwj3/GHSA-2qh5-xjr3-fwj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qh5-xjr3-fwj3", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-48418" ], "details": "In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json b/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json index 4bdb2006454..a9fa98b06ad 100644 --- a/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json +++ b/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r3p-xw5g-5q9x", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-54728" ], "details": "Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2wgx-r653-jrmq/GHSA-2wgx-r653-jrmq.json b/advisories/unreviewed/2025/01/GHSA-2wgx-r653-jrmq/GHSA-2wgx-r653-jrmq.json index 2d765cda293..04ebf2eaf7b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2wgx-r653-jrmq/GHSA-2wgx-r653-jrmq.json +++ b/advisories/unreviewed/2025/01/GHSA-2wgx-r653-jrmq/GHSA-2wgx-r653-jrmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wgx-r653-jrmq", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56951" ], "details": "An issue in Hangzhou Bobo Technology Co Ltd UU Game Booster iOS 10.6.13 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2xfh-jfm3-6xpr/GHSA-2xfh-jfm3-6xpr.json b/advisories/unreviewed/2025/01/GHSA-2xfh-jfm3-6xpr/GHSA-2xfh-jfm3-6xpr.json index dfddebc0295..9932feeef3b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2xfh-jfm3-6xpr/GHSA-2xfh-jfm3-6xpr.json +++ b/advisories/unreviewed/2025/01/GHSA-2xfh-jfm3-6xpr/GHSA-2xfh-jfm3-6xpr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xfh-jfm3-6xpr", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-57272" ], "details": "SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-345g-rh3c-p73g/GHSA-345g-rh3c-p73g.json b/advisories/unreviewed/2025/01/GHSA-345g-rh3c-p73g/GHSA-345g-rh3c-p73g.json new file mode 100644 index 00000000000..7584d132230 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-345g-rh3c-p73g/GHSA-345g-rh3c-p73g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-345g-rh3c-p73g", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2025-0784" + ], + "details": "A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0784" + }, + { + "type": "WEB", + "url": "https://eldruin.notion.site/Intelbras-InControl-v2-21-57-Password-exposed-in-clear-text-17d27474cccb806fba1efda195c78258?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.483835" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3j5m-4qj3-wjqr/GHSA-3j5m-4qj3-wjqr.json b/advisories/unreviewed/2025/01/GHSA-3j5m-4qj3-wjqr/GHSA-3j5m-4qj3-wjqr.json new file mode 100644 index 00000000000..e8369fc6aea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3j5m-4qj3-wjqr/GHSA-3j5m-4qj3-wjqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j5m-4qj3-wjqr", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-40670" + ], + "details": "In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40670" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3q27-5m93-xfm4/GHSA-3q27-5m93-xfm4.json b/advisories/unreviewed/2025/01/GHSA-3q27-5m93-xfm4/GHSA-3q27-5m93-xfm4.json new file mode 100644 index 00000000000..dc2477f6b15 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3q27-5m93-xfm4/GHSA-3q27-5m93-xfm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q27-5m93-xfm4", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-22217" + ], + "details": "Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. \n\nA malicious user with network access may be able to use specially crafted SQL queries to gain database access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22217" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3v4j-7fgr-fp96/GHSA-3v4j-7fgr-fp96.json b/advisories/unreviewed/2025/01/GHSA-3v4j-7fgr-fp96/GHSA-3v4j-7fgr-fp96.json index a2bb904a3c1..3eaa710ce84 100644 --- a/advisories/unreviewed/2025/01/GHSA-3v4j-7fgr-fp96/GHSA-3v4j-7fgr-fp96.json +++ b/advisories/unreviewed/2025/01/GHSA-3v4j-7fgr-fp96/GHSA-3v4j-7fgr-fp96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3v4j-7fgr-fp96", - "modified": "2025-01-27T15:30:57Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T15:30:57Z", "aliases": [ "CVE-2024-57590" ], "details": "TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface \"ntp_sync.cgi\",which allows remote attackers to execute arbitrary commands via parameter \"ntp_server\" passed to the \"ntp_sync.cgi\" binary through a POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T15:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-47hm-pp24-wmmp/GHSA-47hm-pp24-wmmp.json b/advisories/unreviewed/2025/01/GHSA-47hm-pp24-wmmp/GHSA-47hm-pp24-wmmp.json index f65e7dfdc98..2ebab3bdab5 100644 --- a/advisories/unreviewed/2025/01/GHSA-47hm-pp24-wmmp/GHSA-47hm-pp24-wmmp.json +++ b/advisories/unreviewed/2025/01/GHSA-47hm-pp24-wmmp/GHSA-47hm-pp24-wmmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-47hm-pp24-wmmp", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56959" ], "details": "An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json b/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json index 5fa5ee3f3dc..ae2816c2f4f 100644 --- a/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json +++ b/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4cf6-q58x-cj63", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57052" ], "details": "An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-384" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4h7q-63rq-hcw7/GHSA-4h7q-63rq-hcw7.json b/advisories/unreviewed/2025/01/GHSA-4h7q-63rq-hcw7/GHSA-4h7q-63rq-hcw7.json index e57221eca45..3ff3b8e2b23 100644 --- a/advisories/unreviewed/2025/01/GHSA-4h7q-63rq-hcw7/GHSA-4h7q-63rq-hcw7.json +++ b/advisories/unreviewed/2025/01/GHSA-4h7q-63rq-hcw7/GHSA-4h7q-63rq-hcw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4h7q-63rq-hcw7", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56968" ], "details": "An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4mrr-3cmp-q26r/GHSA-4mrr-3cmp-q26r.json b/advisories/unreviewed/2025/01/GHSA-4mrr-3cmp-q26r/GHSA-4mrr-3cmp-q26r.json index e7ed5540b1b..9807f9cbadd 100644 --- a/advisories/unreviewed/2025/01/GHSA-4mrr-3cmp-q26r/GHSA-4mrr-3cmp-q26r.json +++ b/advisories/unreviewed/2025/01/GHSA-4mrr-3cmp-q26r/GHSA-4mrr-3cmp-q26r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4mrr-3cmp-q26r", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56952" ], "details": "An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json b/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json index f4507472e23..1956bd7f9fe 100644 --- a/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json +++ b/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4mwx-vgq4-7vr5", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37003" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-53v8-f936-c2xp/GHSA-53v8-f936-c2xp.json b/advisories/unreviewed/2025/01/GHSA-53v8-f936-c2xp/GHSA-53v8-f936-c2xp.json index df7c7d74068..e6f1215ce43 100644 --- a/advisories/unreviewed/2025/01/GHSA-53v8-f936-c2xp/GHSA-53v8-f936-c2xp.json +++ b/advisories/unreviewed/2025/01/GHSA-53v8-f936-c2xp/GHSA-53v8-f936-c2xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53v8-f936-c2xp", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56954" ], "details": "An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5j2j-3qxv-fcmx/GHSA-5j2j-3qxv-fcmx.json b/advisories/unreviewed/2025/01/GHSA-5j2j-3qxv-fcmx/GHSA-5j2j-3qxv-fcmx.json index 21a58ac21eb..a9616aeadf9 100644 --- a/advisories/unreviewed/2025/01/GHSA-5j2j-3qxv-fcmx/GHSA-5j2j-3qxv-fcmx.json +++ b/advisories/unreviewed/2025/01/GHSA-5j2j-3qxv-fcmx/GHSA-5j2j-3qxv-fcmx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5j2j-3qxv-fcmx", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56962" ], "details": "An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5q2h-rcfj-xc9g/GHSA-5q2h-rcfj-xc9g.json b/advisories/unreviewed/2025/01/GHSA-5q2h-rcfj-xc9g/GHSA-5q2h-rcfj-xc9g.json new file mode 100644 index 00000000000..bd788d8b950 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5q2h-rcfj-xc9g/GHSA-5q2h-rcfj-xc9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q2h-rcfj-xc9g", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-24479" + ], + "details": "A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24479" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1719.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-679g-g57f-hfc6/GHSA-679g-g57f-hfc6.json b/advisories/unreviewed/2025/01/GHSA-679g-g57f-hfc6/GHSA-679g-g57f-hfc6.json index 1cd371c1ec7..f41116fe464 100644 --- a/advisories/unreviewed/2025/01/GHSA-679g-g57f-hfc6/GHSA-679g-g57f-hfc6.json +++ b/advisories/unreviewed/2025/01/GHSA-679g-g57f-hfc6/GHSA-679g-g57f-hfc6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-679g-g57f-hfc6", - "modified": "2025-01-27T21:30:53Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T21:30:53Z", "aliases": [ "CVE-2024-56948" ], "details": "An issue in KuGou Technology CO. LTD KuGou Music iOS v20.0.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json b/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json index b4a0f2d0f91..5751ad2656b 100644 --- a/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json +++ b/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6m9w-gxx9-4gqr", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57547" ], "details": "Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6v24-x43m-jfhm/GHSA-6v24-x43m-jfhm.json b/advisories/unreviewed/2025/01/GHSA-6v24-x43m-jfhm/GHSA-6v24-x43m-jfhm.json new file mode 100644 index 00000000000..e9ebc36b640 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v24-x43m-jfhm/GHSA-6v24-x43m-jfhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v24-x43m-jfhm", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-40651" + ], + "details": "In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40651" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6wqf-f4xj-mxq4/GHSA-6wqf-f4xj-mxq4.json b/advisories/unreviewed/2025/01/GHSA-6wqf-f4xj-mxq4/GHSA-6wqf-f4xj-mxq4.json index cbb417b177c..e9f1f341a01 100644 --- a/advisories/unreviewed/2025/01/GHSA-6wqf-f4xj-mxq4/GHSA-6wqf-f4xj-mxq4.json +++ b/advisories/unreviewed/2025/01/GHSA-6wqf-f4xj-mxq4/GHSA-6wqf-f4xj-mxq4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wqf-f4xj-mxq4", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-48419" ], "details": "Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with \"root\" privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-72rq-mhpg-9q3m/GHSA-72rq-mhpg-9q3m.json b/advisories/unreviewed/2025/01/GHSA-72rq-mhpg-9q3m/GHSA-72rq-mhpg-9q3m.json index 442ef7fe95f..187863cc23a 100644 --- a/advisories/unreviewed/2025/01/GHSA-72rq-mhpg-9q3m/GHSA-72rq-mhpg-9q3m.json +++ b/advisories/unreviewed/2025/01/GHSA-72rq-mhpg-9q3m/GHSA-72rq-mhpg-9q3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-72rq-mhpg-9q3m", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56966" ], "details": "An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json b/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json index d1f9d043baf..595a40ac9a1 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json +++ b/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jq5-8rmw-j9wh", - "modified": "2025-01-27T06:30:26Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T06:30:26Z", "aliases": [ "CVE-2024-13095" ], "details": "The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T06:15:23Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8787-qmx9-7w46/GHSA-8787-qmx9-7w46.json b/advisories/unreviewed/2025/01/GHSA-8787-qmx9-7w46/GHSA-8787-qmx9-7w46.json index f2bb10723fe..94fb7a81643 100644 --- a/advisories/unreviewed/2025/01/GHSA-8787-qmx9-7w46/GHSA-8787-qmx9-7w46.json +++ b/advisories/unreviewed/2025/01/GHSA-8787-qmx9-7w46/GHSA-8787-qmx9-7w46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8787-qmx9-7w46", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-48420" ], "details": "Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json b/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json new file mode 100644 index 00000000000..6918e7e2f17 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88q7-6vxh-w5q7", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40676" + ], + "details": "In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40676" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/e8a53246607b52b15269f97aef9ba7e928ba2473" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8fjm-9j4r-q49r/GHSA-8fjm-9j4r-q49r.json b/advisories/unreviewed/2025/01/GHSA-8fjm-9j4r-q49r/GHSA-8fjm-9j4r-q49r.json new file mode 100644 index 00000000000..ec6b208ac09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8fjm-9j4r-q49r/GHSA-8fjm-9j4r-q49r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fjm-9j4r-q49r", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40672" + ], + "details": "In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40672" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/modules/IntentResolver/+/ccd29124d0d2276a3071c0418c14dec188cd3727" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8jc8-vxw9-8xxp/GHSA-8jc8-vxw9-8xxp.json b/advisories/unreviewed/2025/01/GHSA-8jc8-vxw9-8xxp/GHSA-8jc8-vxw9-8xxp.json new file mode 100644 index 00000000000..b523c69efdb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8jc8-vxw9-8xxp/GHSA-8jc8-vxw9-8xxp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jc8-vxw9-8xxp", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40677" + ], + "details": "In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40677" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/apps/Settings/+/db26138f07db830e3fb78283d37de3c0296d93cb" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8xh7-m55w-7ww7/GHSA-8xh7-m55w-7ww7.json b/advisories/unreviewed/2025/01/GHSA-8xh7-m55w-7ww7/GHSA-8xh7-m55w-7ww7.json index 70a5dfbe1c2..bd5298d0225 100644 --- a/advisories/unreviewed/2025/01/GHSA-8xh7-m55w-7ww7/GHSA-8xh7-m55w-7ww7.json +++ b/advisories/unreviewed/2025/01/GHSA-8xh7-m55w-7ww7/GHSA-8xh7-m55w-7ww7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xh7-m55w-7ww7", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56950" ], "details": "An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-93hw-75c6-jqv2/GHSA-93hw-75c6-jqv2.json b/advisories/unreviewed/2025/01/GHSA-93hw-75c6-jqv2/GHSA-93hw-75c6-jqv2.json index 9046e0aff8e..8046ec1694c 100644 --- a/advisories/unreviewed/2025/01/GHSA-93hw-75c6-jqv2/GHSA-93hw-75c6-jqv2.json +++ b/advisories/unreviewed/2025/01/GHSA-93hw-75c6-jqv2/GHSA-93hw-75c6-jqv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93hw-75c6-jqv2", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56960" ], "details": "An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json b/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json index c5a5a68fbaa..0a05ba868d3 100644 --- a/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json +++ b/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97mv-g3jg-wg68", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-56178" ], "details": "An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9q3v-94jq-7v4q/GHSA-9q3v-94jq-7v4q.json b/advisories/unreviewed/2025/01/GHSA-9q3v-94jq-7v4q/GHSA-9q3v-94jq-7v4q.json index f9f939f2449..666c7758581 100644 --- a/advisories/unreviewed/2025/01/GHSA-9q3v-94jq-7v4q/GHSA-9q3v-94jq-7v4q.json +++ b/advisories/unreviewed/2025/01/GHSA-9q3v-94jq-7v4q/GHSA-9q3v-94jq-7v4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9q3v-94jq-7v4q", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-48416" ], "details": "Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9qc8-8f6v-4qc3/GHSA-9qc8-8f6v-4qc3.json b/advisories/unreviewed/2025/01/GHSA-9qc8-8f6v-4qc3/GHSA-9qc8-8f6v-4qc3.json index 5571e67399b..3643874c6b6 100644 --- a/advisories/unreviewed/2025/01/GHSA-9qc8-8f6v-4qc3/GHSA-9qc8-8f6v-4qc3.json +++ b/advisories/unreviewed/2025/01/GHSA-9qc8-8f6v-4qc3/GHSA-9qc8-8f6v-4qc3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9qc8-8f6v-4qc3", - "modified": "2025-01-27T18:32:01Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:01Z", "aliases": [ "CVE-2024-48417" ], "details": "Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T17:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9w2g-9v3r-27rp/GHSA-9w2g-9v3r-27rp.json b/advisories/unreviewed/2025/01/GHSA-9w2g-9v3r-27rp/GHSA-9w2g-9v3r-27rp.json index d46f794846c..13dfe84679e 100644 --- a/advisories/unreviewed/2025/01/GHSA-9w2g-9v3r-27rp/GHSA-9w2g-9v3r-27rp.json +++ b/advisories/unreviewed/2025/01/GHSA-9w2g-9v3r-27rp/GHSA-9w2g-9v3r-27rp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9w2g-9v3r-27rp", - "modified": "2025-01-27T21:30:53Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:53Z", "aliases": [ "CVE-2024-56949" ], "details": "An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json b/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json index 5551193fd0f..ea692c0f529 100644 --- a/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json +++ b/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwgj-88jc-p385", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37002" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cwp3-3mxc-v33w/GHSA-cwp3-3mxc-v33w.json b/advisories/unreviewed/2025/01/GHSA-cwp3-3mxc-v33w/GHSA-cwp3-3mxc-v33w.json new file mode 100644 index 00000000000..6308d3b197b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cwp3-3mxc-v33w/GHSA-cwp3-3mxc-v33w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwp3-3mxc-v33w", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-0783" + ], + "details": "A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0783" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1FCJveTlXtJd8EJRW2-LXwuhno92JaVt3_98Iqrdoc6M/edit?tab=t.0#heading=h.bbpri264qnth" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1KqzS5bMyPtgO9eIk_-que50tZU097RVi/view" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f39m-g6qq-h3xv/GHSA-f39m-g6qq-h3xv.json b/advisories/unreviewed/2025/01/GHSA-f39m-g6qq-h3xv/GHSA-f39m-g6qq-h3xv.json index 5b8d87057dc..393fad50639 100644 --- a/advisories/unreviewed/2025/01/GHSA-f39m-g6qq-h3xv/GHSA-f39m-g6qq-h3xv.json +++ b/advisories/unreviewed/2025/01/GHSA-f39m-g6qq-h3xv/GHSA-f39m-g6qq-h3xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f39m-g6qq-h3xv", - "modified": "2025-01-27T06:30:24Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T06:30:24Z", "aliases": [ "CVE-2024-12280" ], "details": "The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T06:15:21Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f8mp-8r5c-5pw4/GHSA-f8mp-8r5c-5pw4.json b/advisories/unreviewed/2025/01/GHSA-f8mp-8r5c-5pw4/GHSA-f8mp-8r5c-5pw4.json index 2f4929f9940..f1b20941696 100644 --- a/advisories/unreviewed/2025/01/GHSA-f8mp-8r5c-5pw4/GHSA-f8mp-8r5c-5pw4.json +++ b/advisories/unreviewed/2025/01/GHSA-f8mp-8r5c-5pw4/GHSA-f8mp-8r5c-5pw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f8mp-8r5c-5pw4", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56964" ], "details": "An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fv95-67f8-c94p/GHSA-fv95-67f8-c94p.json b/advisories/unreviewed/2025/01/GHSA-fv95-67f8-c94p/GHSA-fv95-67f8-c94p.json new file mode 100644 index 00000000000..1fd92f7ccda --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fv95-67f8-c94p/GHSA-fv95-67f8-c94p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv95-67f8-c94p", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2025-24481" + ], + "details": "An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24481" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1720.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g39c-whf8-f5f9/GHSA-g39c-whf8-f5f9.json b/advisories/unreviewed/2025/01/GHSA-g39c-whf8-f5f9/GHSA-g39c-whf8-f5f9.json new file mode 100644 index 00000000000..c21c8f3df8d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g39c-whf8-f5f9/GHSA-g39c-whf8-f5f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g39c-whf8-f5f9", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-34748" + ], + "details": "In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34748" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5q2-2254-cw52/GHSA-g5q2-2254-cw52.json b/advisories/unreviewed/2025/01/GHSA-g5q2-2254-cw52/GHSA-g5q2-2254-cw52.json new file mode 100644 index 00000000000..0f96949a192 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5q2-2254-cw52/GHSA-g5q2-2254-cw52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5q2-2254-cw52", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-40669" + ], + "details": "In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40669" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g99x-gcm8-hch3/GHSA-g99x-gcm8-hch3.json b/advisories/unreviewed/2025/01/GHSA-g99x-gcm8-hch3/GHSA-g99x-gcm8-hch3.json index ce90bf10c24..2f1240e1d33 100644 --- a/advisories/unreviewed/2025/01/GHSA-g99x-gcm8-hch3/GHSA-g99x-gcm8-hch3.json +++ b/advisories/unreviewed/2025/01/GHSA-g99x-gcm8-hch3/GHSA-g99x-gcm8-hch3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g99x-gcm8-hch3", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56953" ], "details": "An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gg32-cp5g-4m8x/GHSA-gg32-cp5g-4m8x.json b/advisories/unreviewed/2025/01/GHSA-gg32-cp5g-4m8x/GHSA-gg32-cp5g-4m8x.json index 1a3cc8d3669..c43f6ad11a6 100644 --- a/advisories/unreviewed/2025/01/GHSA-gg32-cp5g-4m8x/GHSA-gg32-cp5g-4m8x.json +++ b/advisories/unreviewed/2025/01/GHSA-gg32-cp5g-4m8x/GHSA-gg32-cp5g-4m8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gg32-cp5g-4m8x", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56963" ], "details": "An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gh56-9g95-mhj6/GHSA-gh56-9g95-mhj6.json b/advisories/unreviewed/2025/01/GHSA-gh56-9g95-mhj6/GHSA-gh56-9g95-mhj6.json index 0e0b4a723ae..f546cb2b02a 100644 --- a/advisories/unreviewed/2025/01/GHSA-gh56-9g95-mhj6/GHSA-gh56-9g95-mhj6.json +++ b/advisories/unreviewed/2025/01/GHSA-gh56-9g95-mhj6/GHSA-gh56-9g95-mhj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gh56-9g95-mhj6", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56969" ], "details": "An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json index 729cee24be2..fb9e61139f7 100644 --- a/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json +++ b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvc8-8jhg-7556", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57373" ], "details": "Cross Site Request Forgery vulnerability in LifestyleStore v.1.0 allows a remote attacker to execute arbitrary cod and obtain sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json b/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json index b53c597fc2d..782b0dd137a 100644 --- a/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json +++ b/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h4fw-wmp3-pv59", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-48662" ], "details": "Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json b/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json index d5a8053adf9..daf5479ffad 100644 --- a/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json +++ b/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h5px-98xh-rpjj", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24156" ], "details": "An integer overflow was addressed through improved input validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to elevate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h5qg-fjxf-6rch/GHSA-h5qg-fjxf-6rch.json b/advisories/unreviewed/2025/01/GHSA-h5qg-fjxf-6rch/GHSA-h5qg-fjxf-6rch.json index 9830dbfdba9..49149e06ef1 100644 --- a/advisories/unreviewed/2025/01/GHSA-h5qg-fjxf-6rch/GHSA-h5qg-fjxf-6rch.json +++ b/advisories/unreviewed/2025/01/GHSA-h5qg-fjxf-6rch/GHSA-h5qg-fjxf-6rch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h5qg-fjxf-6rch", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56967" ], "details": "An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json b/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json index 9c58897ca33..622314839d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json +++ b/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h75c-q767-27j6", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57546" ], "details": "An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hf39-rpqx-2w3q/GHSA-hf39-rpqx-2w3q.json b/advisories/unreviewed/2025/01/GHSA-hf39-rpqx-2w3q/GHSA-hf39-rpqx-2w3q.json new file mode 100644 index 00000000000..d8f8eab74ee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hf39-rpqx-2w3q/GHSA-hf39-rpqx-2w3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf39-rpqx-2w3q", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2025-24826" + ], + "details": "Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24826" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-6436" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j263-jwmh-6jmf/GHSA-j263-jwmh-6jmf.json b/advisories/unreviewed/2025/01/GHSA-j263-jwmh-6jmf/GHSA-j263-jwmh-6jmf.json new file mode 100644 index 00000000000..409e2a16bc8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j263-jwmh-6jmf/GHSA-j263-jwmh-6jmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j263-jwmh-6jmf", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40674" + ], + "details": "In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40674" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/modules/Wifi/+/debc548ac085ba1ab0582172b97d965e9a1ea43a" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json b/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json index da3f2c95bed..0560032cc17 100644 --- a/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json +++ b/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqpc-q3rg-3f4f", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57369" ], "details": "Clickjacking vulnerability in typecho v1.2.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T20:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json b/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json index 791dfd0af67..42ec756945b 100644 --- a/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json +++ b/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrx3-7w53-466r", - "modified": "2025-01-28T18:31:28Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T18:31:28Z", "aliases": [ "CVE-2017-13317" ], "details": "In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T17:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mjp5-6cq8-qv5g/GHSA-mjp5-6cq8-qv5g.json b/advisories/unreviewed/2025/01/GHSA-mjp5-6cq8-qv5g/GHSA-mjp5-6cq8-qv5g.json new file mode 100644 index 00000000000..535e9f47c84 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mjp5-6cq8-qv5g/GHSA-mjp5-6cq8-qv5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjp5-6cq8-qv5g", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-40649" + ], + "details": "In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40649" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json b/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json index 58b9b382bd4..e74262947b0 100644 --- a/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json +++ b/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p44p-wgq8-46qm", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37006" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Request Ack` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json b/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json index 3bca3dba105..288ee40e433 100644 --- a/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json +++ b/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p59h-7g7v-xp8x", - "modified": "2025-01-28T18:31:28Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T18:31:28Z", "aliases": [ "CVE-2018-9378" ], "details": "In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T17:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p853-4v42-h45f/GHSA-p853-4v42-h45f.json b/advisories/unreviewed/2025/01/GHSA-p853-4v42-h45f/GHSA-p853-4v42-h45f.json new file mode 100644 index 00000000000..3265a5028f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p853-4v42-h45f/GHSA-p853-4v42-h45f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p853-4v42-h45f", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-24480" + ], + "details": "A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24480" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1719.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q4mr-xqpc-5xvx/GHSA-q4mr-xqpc-5xvx.json b/advisories/unreviewed/2025/01/GHSA-q4mr-xqpc-5xvx/GHSA-q4mr-xqpc-5xvx.json index 9e15bd91893..6130100735a 100644 --- a/advisories/unreviewed/2025/01/GHSA-q4mr-xqpc-5xvx/GHSA-q4mr-xqpc-5xvx.json +++ b/advisories/unreviewed/2025/01/GHSA-q4mr-xqpc-5xvx/GHSA-q4mr-xqpc-5xvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4mr-xqpc-5xvx", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56972" ], "details": "An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json b/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json index abe6af04e09..caf3f6d6bdb 100644 --- a/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json +++ b/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv2m-4wv2-f33h", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37004" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json b/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json index 4faa44c540d..2e84338f1bd 100644 --- a/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json +++ b/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qx57-5369-xrr8", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57548" ], "details": "CMSimple 5.16 allows the user to edit log.php file via print page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r24f-5x7x-cfp5/GHSA-r24f-5x7x-cfp5.json b/advisories/unreviewed/2025/01/GHSA-r24f-5x7x-cfp5/GHSA-r24f-5x7x-cfp5.json index a5edebe58a9..e0858ea05f5 100644 --- a/advisories/unreviewed/2025/01/GHSA-r24f-5x7x-cfp5/GHSA-r24f-5x7x-cfp5.json +++ b/advisories/unreviewed/2025/01/GHSA-r24f-5x7x-cfp5/GHSA-r24f-5x7x-cfp5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r24f-5x7x-cfp5", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56965" ], "details": "An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json b/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json index ca1cbd45576..61c254dc447 100644 --- a/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json +++ b/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r2h5-cvfq-6cgj", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57549" ], "details": "CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json b/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json index d7fd5262357..97414ac22fd 100644 --- a/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json +++ b/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r396-g535-84pc", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-56316" ], "details": "In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of Service via crafted TR069 requests on TCP port 9675 or 7547. Rebooting does not resolve the permanent Denial of Service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r5hp-6mxm-95xh/GHSA-r5hp-6mxm-95xh.json b/advisories/unreviewed/2025/01/GHSA-r5hp-6mxm-95xh/GHSA-r5hp-6mxm-95xh.json index 0ead2f295eb..df7b04f6c95 100644 --- a/advisories/unreviewed/2025/01/GHSA-r5hp-6mxm-95xh/GHSA-r5hp-6mxm-95xh.json +++ b/advisories/unreviewed/2025/01/GHSA-r5hp-6mxm-95xh/GHSA-r5hp-6mxm-95xh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5hp-6mxm-95xh", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56957" ], "details": "An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r86g-243j-mqp7/GHSA-r86g-243j-mqp7.json b/advisories/unreviewed/2025/01/GHSA-r86g-243j-mqp7/GHSA-r86g-243j-mqp7.json index 9e395940490..899f69ef726 100644 --- a/advisories/unreviewed/2025/01/GHSA-r86g-243j-mqp7/GHSA-r86g-243j-mqp7.json +++ b/advisories/unreviewed/2025/01/GHSA-r86g-243j-mqp7/GHSA-r86g-243j-mqp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r86g-243j-mqp7", - "modified": "2025-01-27T21:30:53Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T21:30:53Z", "aliases": [ "CVE-2024-56947" ], "details": "An issue in Xiamen Meitu Technology Co., Ltd. BeautyCam iOS v12.3.60 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json b/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json index 5b80fdae530..1e3982584f5 100644 --- a/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json +++ b/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rrg9-j69g-xfm7", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24137" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected application termination or arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rx3r-45qh-9rcc/GHSA-rx3r-45qh-9rcc.json b/advisories/unreviewed/2025/01/GHSA-rx3r-45qh-9rcc/GHSA-rx3r-45qh-9rcc.json index 68e7691df46..c281cec6afd 100644 --- a/advisories/unreviewed/2025/01/GHSA-rx3r-45qh-9rcc/GHSA-rx3r-45qh-9rcc.json +++ b/advisories/unreviewed/2025/01/GHSA-rx3r-45qh-9rcc/GHSA-rx3r-45qh-9rcc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rx3r-45qh-9rcc", - "modified": "2025-01-27T18:32:02Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-27T18:32:02Z", "aliases": [ "CVE-2024-26317" ], "details": "In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T18:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vwg3-f59h-rpvc/GHSA-vwg3-f59h-rpvc.json b/advisories/unreviewed/2025/01/GHSA-vwg3-f59h-rpvc/GHSA-vwg3-f59h-rpvc.json new file mode 100644 index 00000000000..7d6e96abc31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vwg3-f59h-rpvc/GHSA-vwg3-f59h-rpvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwg3-f59h-rpvc", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2024-34733" + ], + "details": "In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34733" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w4p3-vcx6-ggv5/GHSA-w4p3-vcx6-ggv5.json b/advisories/unreviewed/2025/01/GHSA-w4p3-vcx6-ggv5/GHSA-w4p3-vcx6-ggv5.json new file mode 100644 index 00000000000..ce2281fee94 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w4p3-vcx6-ggv5/GHSA-w4p3-vcx6-ggv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4p3-vcx6-ggv5", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-24478" + ], + "details": "A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24478" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1718.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json b/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json index 28d0ab0f932..38e2168b5f8 100644 --- a/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json +++ b/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7hg-77m4-rh58", - "modified": "2025-01-28T18:31:28Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T18:31:28Z", "aliases": [ "CVE-2017-13318" ], "details": "In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T17:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wf2q-62vr-q7gv/GHSA-wf2q-62vr-q7gv.json b/advisories/unreviewed/2025/01/GHSA-wf2q-62vr-q7gv/GHSA-wf2q-62vr-q7gv.json index 5e323a2ed8c..d0b701133f5 100644 --- a/advisories/unreviewed/2025/01/GHSA-wf2q-62vr-q7gv/GHSA-wf2q-62vr-q7gv.json +++ b/advisories/unreviewed/2025/01/GHSA-wf2q-62vr-q7gv/GHSA-wf2q-62vr-q7gv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wf2q-62vr-q7gv", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56955" ], "details": "An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wmwg-vmx2-qg37/GHSA-wmwg-vmx2-qg37.json b/advisories/unreviewed/2025/01/GHSA-wmwg-vmx2-qg37/GHSA-wmwg-vmx2-qg37.json new file mode 100644 index 00000000000..9f8da9cc01b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wmwg-vmx2-qg37/GHSA-wmwg-vmx2-qg37.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmwg-vmx2-qg37", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40673" + ], + "details": "In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40673" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/libcore/+/b17fd2f8fe468e7d32e713b442f610cd33e4e7a9" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json b/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json index e72754cf74a..4b8efb4ec40 100644 --- a/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json +++ b/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wp75-3w5f-vg4w", - "modified": "2025-01-28T18:31:28Z", + "modified": "2025-01-28T21:31:03Z", "published": "2025-01-28T18:31:28Z", "aliases": [ "CVE-2018-9373" ], "details": "In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T17:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json b/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json new file mode 100644 index 00000000000..00bb7d9bb86 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq23-xq9q-wf8w", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2024-40675" + ], + "details": "In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40675" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/c6b5490ec659b5854fd429f453f75de5befa6359" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-10-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wx72-xp52-v927/GHSA-wx72-xp52-v927.json b/advisories/unreviewed/2025/01/GHSA-wx72-xp52-v927/GHSA-wx72-xp52-v927.json new file mode 100644 index 00000000000..73e0539f1ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wx72-xp52-v927/GHSA-wx72-xp52-v927.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx72-xp52-v927", + "modified": "2025-01-28T21:31:04Z", + "published": "2025-01-28T21:31:04Z", + "aliases": [ + "CVE-2025-24482" + ], + "details": "A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24482" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1720.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x36x-qfrj-p4p5/GHSA-x36x-qfrj-p4p5.json b/advisories/unreviewed/2025/01/GHSA-x36x-qfrj-p4p5/GHSA-x36x-qfrj-p4p5.json index a978af9f4d2..8f7acab2945 100644 --- a/advisories/unreviewed/2025/01/GHSA-x36x-qfrj-p4p5/GHSA-x36x-qfrj-p4p5.json +++ b/advisories/unreviewed/2025/01/GHSA-x36x-qfrj-p4p5/GHSA-x36x-qfrj-p4p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x36x-qfrj-p4p5", - "modified": "2025-01-27T21:30:54Z", + "modified": "2025-01-28T21:31:02Z", "published": "2025-01-27T21:30:54Z", "aliases": [ "CVE-2024-56971" ], "details": "An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json b/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json index a91ab92a4a7..a48c1005fcf 100644 --- a/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json +++ b/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x76x-v36q-wqrf", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37005" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json index b32a53becdb..bd6c015d2ad 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5q-pch5-g3xq", - "modified": "2025-01-28T09:32:33Z", + "modified": "2025-01-28T21:31:01Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12085" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:0714" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0774" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12085" diff --git a/advisories/unreviewed/2025/01/GHSA-xxvc-c328-56m6/GHSA-xxvc-c328-56m6.json b/advisories/unreviewed/2025/01/GHSA-xxvc-c328-56m6/GHSA-xxvc-c328-56m6.json new file mode 100644 index 00000000000..bfbbed9ff7b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xxvc-c328-56m6/GHSA-xxvc-c328-56m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxvc-c328-56m6", + "modified": "2025-01-28T21:31:03Z", + "published": "2025-01-28T21:31:03Z", + "aliases": [ + "CVE-2025-0631" + ], + "details": "A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0631" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1717.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T19:15:14Z" + } +} \ No newline at end of file