From 5017e7fc19bedace6f289f0cceac4bf09e2dbb14 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Apr 2025 12:34:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r7jx-5m6m-cpg9.json | 13 ++++- .../GHSA-2w6r-mvp4-65v2.json | 56 +++++++++++++++++++ .../GHSA-3pq5-82wc-xqgh.json | 36 ++++++++++++ .../GHSA-3q5h-jx74-65fh.json | 36 ++++++++++++ .../GHSA-496c-5frj-9m2m.json | 36 ++++++++++++ .../GHSA-4fr5-x8r3-mvxg.json | 36 ++++++++++++ .../GHSA-4jc9-gj5x-jr9j.json | 36 ++++++++++++ .../GHSA-4m65-9g68-65w5.json | 36 ++++++++++++ .../GHSA-4q5q-cfpq-3h3j.json | 36 ++++++++++++ .../GHSA-4rmv-m7cx-wvg4.json | 36 ++++++++++++ .../GHSA-59p6-hq92-2jp7.json | 36 ++++++++++++ .../GHSA-5x2r-rgf5-p2pp.json | 36 ++++++++++++ .../GHSA-633m-895c-3f9g.json | 31 ++++++++++ .../GHSA-7h9m-rpxw-5xf6.json | 36 ++++++++++++ .../GHSA-8gwj-4mvc-6737.json | 36 ++++++++++++ .../GHSA-8phc-9jc2-384h.json | 36 ++++++++++++ .../GHSA-9fmx-h3qh-94wc.json | 36 ++++++++++++ .../GHSA-c8ww-p8qh-gjr8.json | 36 ++++++++++++ .../GHSA-cvpx-hvjx-v6qr.json | 36 ++++++++++++ .../GHSA-f4p6-w7ph-5gqm.json | 36 ++++++++++++ .../GHSA-f55p-fqh6-jjmf.json | 36 ++++++++++++ .../GHSA-gcg7-3r72-3vfr.json | 56 +++++++++++++++++++ .../GHSA-hf9p-447v-5g26.json | 36 ++++++++++++ .../GHSA-jgqg-9w53-x8wg.json | 36 ++++++++++++ .../GHSA-jwcw-j33g-q5w2.json | 36 ++++++++++++ .../GHSA-mrr6-w84f-5xh8.json | 36 ++++++++++++ .../GHSA-p224-gmpm-3vmg.json | 56 +++++++++++++++++++ .../GHSA-p89v-wfmh-g3w7.json | 36 ++++++++++++ .../GHSA-p9f7-mwqh-hwrj.json | 36 ++++++++++++ .../GHSA-pwvp-7q9f-hp59.json | 36 ++++++++++++ .../GHSA-qgmj-rw56-xh9r.json | 36 ++++++++++++ .../GHSA-qwvv-jxhc-mf6r.json | 36 ++++++++++++ .../GHSA-r5vv-rjc7-pfg5.json | 36 ++++++++++++ .../GHSA-rgff-5rpc-xc3q.json | 36 ++++++++++++ .../GHSA-rw9m-2gw8-75r7.json | 56 +++++++++++++++++++ .../GHSA-v97v-vwrw-5r2q.json | 36 ++++++++++++ .../GHSA-vfgm-qf58-xjrr.json | 56 +++++++++++++++++++ .../GHSA-vfh3-25rf-469v.json | 36 ++++++++++++ .../GHSA-vq9p-4m2j-2749.json | 36 ++++++++++++ .../GHSA-w36r-rq68-49g7.json | 52 +++++++++++++++++ .../GHSA-wrqq-6949-75w5.json | 36 ++++++++++++ .../GHSA-xpwg-v658-286m.json | 36 ++++++++++++ 42 files changed, 1597 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3pq5-82wc-xqgh/GHSA-3pq5-82wc-xqgh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3q5h-jx74-65fh/GHSA-3q5h-jx74-65fh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-496c-5frj-9m2m/GHSA-496c-5frj-9m2m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4fr5-x8r3-mvxg/GHSA-4fr5-x8r3-mvxg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4jc9-gj5x-jr9j/GHSA-4jc9-gj5x-jr9j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4m65-9g68-65w5/GHSA-4m65-9g68-65w5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4q5q-cfpq-3h3j/GHSA-4q5q-cfpq-3h3j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4rmv-m7cx-wvg4/GHSA-4rmv-m7cx-wvg4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-59p6-hq92-2jp7/GHSA-59p6-hq92-2jp7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5x2r-rgf5-p2pp/GHSA-5x2r-rgf5-p2pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7h9m-rpxw-5xf6/GHSA-7h9m-rpxw-5xf6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8gwj-4mvc-6737/GHSA-8gwj-4mvc-6737.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8phc-9jc2-384h/GHSA-8phc-9jc2-384h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9fmx-h3qh-94wc/GHSA-9fmx-h3qh-94wc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c8ww-p8qh-gjr8/GHSA-c8ww-p8qh-gjr8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cvpx-hvjx-v6qr/GHSA-cvpx-hvjx-v6qr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f4p6-w7ph-5gqm/GHSA-f4p6-w7ph-5gqm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f55p-fqh6-jjmf/GHSA-f55p-fqh6-jjmf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gcg7-3r72-3vfr/GHSA-gcg7-3r72-3vfr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hf9p-447v-5g26/GHSA-hf9p-447v-5g26.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jgqg-9w53-x8wg/GHSA-jgqg-9w53-x8wg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jwcw-j33g-q5w2/GHSA-jwcw-j33g-q5w2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mrr6-w84f-5xh8/GHSA-mrr6-w84f-5xh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p224-gmpm-3vmg/GHSA-p224-gmpm-3vmg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p89v-wfmh-g3w7/GHSA-p89v-wfmh-g3w7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p9f7-mwqh-hwrj/GHSA-p9f7-mwqh-hwrj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pwvp-7q9f-hp59/GHSA-pwvp-7q9f-hp59.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qgmj-rw56-xh9r/GHSA-qgmj-rw56-xh9r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qwvv-jxhc-mf6r/GHSA-qwvv-jxhc-mf6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r5vv-rjc7-pfg5/GHSA-r5vv-rjc7-pfg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rgff-5rpc-xc3q/GHSA-rgff-5rpc-xc3q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rw9m-2gw8-75r7/GHSA-rw9m-2gw8-75r7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v97v-vwrw-5r2q/GHSA-v97v-vwrw-5r2q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vfgm-qf58-xjrr/GHSA-vfgm-qf58-xjrr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vfh3-25rf-469v/GHSA-vfh3-25rf-469v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vq9p-4m2j-2749/GHSA-vq9p-4m2j-2749.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w36r-rq68-49g7/GHSA-w36r-rq68-49g7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wrqq-6949-75w5/GHSA-wrqq-6949-75w5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xpwg-v658-286m/GHSA-xpwg-v658-286m.json diff --git a/advisories/github-reviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json b/advisories/github-reviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json index e5a2c9e3d77..22a5ff91e0e 100644 --- a/advisories/github-reviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json +++ b/advisories/github-reviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7jx-5m6m-cpg9", - "modified": "2025-03-14T20:08:42Z", + "modified": "2025-04-07T12:34:01Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57075" @@ -28,11 +28,14 @@ "introduced": "0" }, { - "last_affected": "4.0.1" + "fixed": "4.1.0" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "<= 4.0.1" + } } ], "references": [ @@ -40,6 +43,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57075" }, + { + "type": "WEB", + "url": "https://github.com/shakyShane/eazy-logger/commit/a8baa6fe441d19ffa9916eba367016b7937a28fd" + }, { "type": "WEB", "url": "https://gist.github.com/tariqhawis/c601f7f85146510ca899a7406a03aba5" diff --git a/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json b/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json new file mode 100644 index 00000000000..d60d4801521 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w6r-mvp4-65v2", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2025-3346" + ], + "details": "A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3346" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/AC7formSetPPTPServer/formSetPPTPServer.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551927" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3pq5-82wc-xqgh/GHSA-3pq5-82wc-xqgh.json b/advisories/unreviewed/2025/04/GHSA-3pq5-82wc-xqgh/GHSA-3pq5-82wc-xqgh.json new file mode 100644 index 00000000000..f256560b5e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3pq5-82wc-xqgh/GHSA-3pq5-82wc-xqgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pq5-82wc-xqgh", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-49848" + ], + "details": "Memory corruption while processing multiple IOCTL calls from HLOS to DSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49848" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3q5h-jx74-65fh/GHSA-3q5h-jx74-65fh.json b/advisories/unreviewed/2025/04/GHSA-3q5h-jx74-65fh/GHSA-3q5h-jx74-65fh.json new file mode 100644 index 00000000000..c3b42ac30c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3q5h-jx74-65fh/GHSA-3q5h-jx74-65fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q5h-jx74-65fh", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45544" + ], + "details": "Memory corruption while processing IOCTL calls to add route entry in the HW.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45544" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-496c-5frj-9m2m/GHSA-496c-5frj-9m2m.json b/advisories/unreviewed/2025/04/GHSA-496c-5frj-9m2m/GHSA-496c-5frj-9m2m.json new file mode 100644 index 00000000000..9b02e563cf3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-496c-5frj-9m2m/GHSA-496c-5frj-9m2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-496c-5frj-9m2m", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21447" + ], + "details": "Memory corruption may occur while processing device IO control call for session control.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21447" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4fr5-x8r3-mvxg/GHSA-4fr5-x8r3-mvxg.json b/advisories/unreviewed/2025/04/GHSA-4fr5-x8r3-mvxg/GHSA-4fr5-x8r3-mvxg.json new file mode 100644 index 00000000000..6a79870cd99 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4fr5-x8r3-mvxg/GHSA-4fr5-x8r3-mvxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fr5-x8r3-mvxg", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21439" + ], + "details": "Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21439" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4jc9-gj5x-jr9j/GHSA-4jc9-gj5x-jr9j.json b/advisories/unreviewed/2025/04/GHSA-4jc9-gj5x-jr9j/GHSA-4jc9-gj5x-jr9j.json new file mode 100644 index 00000000000..569cc41e134 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4jc9-gj5x-jr9j/GHSA-4jc9-gj5x-jr9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jc9-gj5x-jr9j", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45557" + ], + "details": "Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45557" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4m65-9g68-65w5/GHSA-4m65-9g68-65w5.json b/advisories/unreviewed/2025/04/GHSA-4m65-9g68-65w5/GHSA-4m65-9g68-65w5.json new file mode 100644 index 00000000000..140cda49758 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4m65-9g68-65w5/GHSA-4m65-9g68-65w5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m65-9g68-65w5", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21440" + ], + "details": "Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21440" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4q5q-cfpq-3h3j/GHSA-4q5q-cfpq-3h3j.json b/advisories/unreviewed/2025/04/GHSA-4q5q-cfpq-3h3j/GHSA-4q5q-cfpq-3h3j.json new file mode 100644 index 00000000000..91afdf59ca5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4q5q-cfpq-3h3j/GHSA-4q5q-cfpq-3h3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q5q-cfpq-3h3j", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21435" + ], + "details": "Transient DOS may occur while parsing extended IE in beacon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21435" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4rmv-m7cx-wvg4/GHSA-4rmv-m7cx-wvg4.json b/advisories/unreviewed/2025/04/GHSA-4rmv-m7cx-wvg4/GHSA-4rmv-m7cx-wvg4.json new file mode 100644 index 00000000000..bc96d909632 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4rmv-m7cx-wvg4/GHSA-4rmv-m7cx-wvg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rmv-m7cx-wvg4", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21428" + ], + "details": "Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21428" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59p6-hq92-2jp7/GHSA-59p6-hq92-2jp7.json b/advisories/unreviewed/2025/04/GHSA-59p6-hq92-2jp7/GHSA-59p6-hq92-2jp7.json new file mode 100644 index 00000000000..fb23d3323a5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59p6-hq92-2jp7/GHSA-59p6-hq92-2jp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59p6-hq92-2jp7", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21434" + ], + "details": "Transient DOS may occur while parsing EHT operation IE or EHT capability IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21434" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5x2r-rgf5-p2pp/GHSA-5x2r-rgf5-p2pp.json b/advisories/unreviewed/2025/04/GHSA-5x2r-rgf5-p2pp/GHSA-5x2r-rgf5-p2pp.json new file mode 100644 index 00000000000..3bc38ba0efa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5x2r-rgf5-p2pp/GHSA-5x2r-rgf5-p2pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x2r-rgf5-p2pp", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-43066" + ], + "details": "Memory corruption while handling file descriptor during listener registration/de-registration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43066" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json b/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json new file mode 100644 index 00000000000..a354300f081 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-633m-895c-3f9g", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-0050" + ], + "details": "Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or WebGPU, to access a limited amount outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r0p0 through r49p2, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r19p0 through r49p2, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p2, from r50p0 through r53p0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0050" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/documentation/110435/latest" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7h9m-rpxw-5xf6/GHSA-7h9m-rpxw-5xf6.json b/advisories/unreviewed/2025/04/GHSA-7h9m-rpxw-5xf6/GHSA-7h9m-rpxw-5xf6.json new file mode 100644 index 00000000000..5f2eabdb23c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7h9m-rpxw-5xf6/GHSA-7h9m-rpxw-5xf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h9m-rpxw-5xf6", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45543" + ], + "details": "Memory corruption while accessing MSM channel map and mixer functions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45543" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8gwj-4mvc-6737/GHSA-8gwj-4mvc-6737.json b/advisories/unreviewed/2025/04/GHSA-8gwj-4mvc-6737/GHSA-8gwj-4mvc-6737.json new file mode 100644 index 00000000000..b1323ef032c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8gwj-4mvc-6737/GHSA-8gwj-4mvc-6737.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gwj-4mvc-6737", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21438" + ], + "details": "Memory corruption while IOCTL call is invoked from user-space to read board data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21438" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8phc-9jc2-384h/GHSA-8phc-9jc2-384h.json b/advisories/unreviewed/2025/04/GHSA-8phc-9jc2-384h/GHSA-8phc-9jc2-384h.json new file mode 100644 index 00000000000..32eadf04eb6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8phc-9jc2-384h/GHSA-8phc-9jc2-384h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8phc-9jc2-384h", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45556" + ], + "details": "Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45556" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1262" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9fmx-h3qh-94wc/GHSA-9fmx-h3qh-94wc.json b/advisories/unreviewed/2025/04/GHSA-9fmx-h3qh-94wc/GHSA-9fmx-h3qh-94wc.json new file mode 100644 index 00000000000..b4effebdb64 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9fmx-h3qh-94wc/GHSA-9fmx-h3qh-94wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fmx-h3qh-94wc", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45549" + ], + "details": "Information disclosure while creating MQ channels.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45549" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8ww-p8qh-gjr8/GHSA-c8ww-p8qh-gjr8.json b/advisories/unreviewed/2025/04/GHSA-c8ww-p8qh-gjr8/GHSA-c8ww-p8qh-gjr8.json new file mode 100644 index 00000000000..5f90ae1a878 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8ww-p8qh-gjr8/GHSA-c8ww-p8qh-gjr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8ww-p8qh-gjr8", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21430" + ], + "details": "Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21430" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cvpx-hvjx-v6qr/GHSA-cvpx-hvjx-v6qr.json b/advisories/unreviewed/2025/04/GHSA-cvpx-hvjx-v6qr/GHSA-cvpx-hvjx-v6qr.json new file mode 100644 index 00000000000..4126414d431 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cvpx-hvjx-v6qr/GHSA-cvpx-hvjx-v6qr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpx-hvjx-v6qr", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21442" + ], + "details": "Memory corruption while transmitting packet mapping information with invalid header payload size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21442" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-680" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f4p6-w7ph-5gqm/GHSA-f4p6-w7ph-5gqm.json b/advisories/unreviewed/2025/04/GHSA-f4p6-w7ph-5gqm/GHSA-f4p6-w7ph-5gqm.json new file mode 100644 index 00000000000..ba1106de913 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f4p6-w7ph-5gqm/GHSA-f4p6-w7ph-5gqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4p6-w7ph-5gqm", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21448" + ], + "details": "Transient DOS may occur while parsing SSID in action frames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21448" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f55p-fqh6-jjmf/GHSA-f55p-fqh6-jjmf.json b/advisories/unreviewed/2025/04/GHSA-f55p-fqh6-jjmf/GHSA-f55p-fqh6-jjmf.json new file mode 100644 index 00000000000..00f3c719fc3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f55p-fqh6-jjmf/GHSA-f55p-fqh6-jjmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f55p-fqh6-jjmf", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21437" + ], + "details": "Memory corruption while processing memory map or unmap IOCTL operations simultaneously.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21437" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gcg7-3r72-3vfr/GHSA-gcg7-3r72-3vfr.json b/advisories/unreviewed/2025/04/GHSA-gcg7-3r72-3vfr/GHSA-gcg7-3r72-3vfr.json new file mode 100644 index 00000000000..73fa2f9305f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gcg7-3r72-3vfr/GHSA-gcg7-3r72-3vfr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcg7-3r72-3vfr", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-3348" + ], + "details": "A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3348" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/hyx123123/cve1/blob/main/cve2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf9p-447v-5g26/GHSA-hf9p-447v-5g26.json b/advisories/unreviewed/2025/04/GHSA-hf9p-447v-5g26/GHSA-hf9p-447v-5g26.json new file mode 100644 index 00000000000..8c962511ac7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf9p-447v-5g26/GHSA-hf9p-447v-5g26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf9p-447v-5g26", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45551" + ], + "details": "Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45551" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jgqg-9w53-x8wg/GHSA-jgqg-9w53-x8wg.json b/advisories/unreviewed/2025/04/GHSA-jgqg-9w53-x8wg/GHSA-jgqg-9w53-x8wg.json new file mode 100644 index 00000000000..4930b2d102b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jgqg-9w53-x8wg/GHSA-jgqg-9w53-x8wg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgqg-9w53-x8wg", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-43067" + ], + "details": "Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43067" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jwcw-j33g-q5w2/GHSA-jwcw-j33g-q5w2.json b/advisories/unreviewed/2025/04/GHSA-jwcw-j33g-q5w2/GHSA-jwcw-j33g-q5w2.json new file mode 100644 index 00000000000..f49e52fe43f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jwcw-j33g-q5w2/GHSA-jwcw-j33g-q5w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwcw-j33g-q5w2", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-43065" + ], + "details": "Cryptographic issues while generating an asymmetric key pair for RKP use cases.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43065" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrr6-w84f-5xh8/GHSA-mrr6-w84f-5xh8.json b/advisories/unreviewed/2025/04/GHSA-mrr6-w84f-5xh8/GHSA-mrr6-w84f-5xh8.json new file mode 100644 index 00000000000..ba56776263a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mrr6-w84f-5xh8/GHSA-mrr6-w84f-5xh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrr6-w84f-5xh8", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21429" + ], + "details": "Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21429" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p224-gmpm-3vmg/GHSA-p224-gmpm-3vmg.json b/advisories/unreviewed/2025/04/GHSA-p224-gmpm-3vmg/GHSA-p224-gmpm-3vmg.json new file mode 100644 index 00000000000..7013f392782 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p224-gmpm-3vmg/GHSA-p224-gmpm-3vmg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p224-gmpm-3vmg", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2025-3347" + ], + "details": "A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_pending.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3347" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/hyx123123/cve1/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551939" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p89v-wfmh-g3w7/GHSA-p89v-wfmh-g3w7.json b/advisories/unreviewed/2025/04/GHSA-p89v-wfmh-g3w7/GHSA-p89v-wfmh-g3w7.json new file mode 100644 index 00000000000..05e7da45638 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p89v-wfmh-g3w7/GHSA-p89v-wfmh-g3w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p89v-wfmh-g3w7", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21425" + ], + "details": "Memory corruption may occur due top improper access control in HAB process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21425" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p9f7-mwqh-hwrj/GHSA-p9f7-mwqh-hwrj.json b/advisories/unreviewed/2025/04/GHSA-p9f7-mwqh-hwrj/GHSA-p9f7-mwqh-hwrj.json new file mode 100644 index 00000000000..dad68d9846f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p9f7-mwqh-hwrj/GHSA-p9f7-mwqh-hwrj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9f7-mwqh-hwrj", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21431" + ], + "details": "Information disclosure may be there when a guest VM is connected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21431" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pwvp-7q9f-hp59/GHSA-pwvp-7q9f-hp59.json b/advisories/unreviewed/2025/04/GHSA-pwvp-7q9f-hp59/GHSA-pwvp-7q9f-hp59.json new file mode 100644 index 00000000000..76d01247fda --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pwvp-7q9f-hp59/GHSA-pwvp-7q9f-hp59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwvp-7q9f-hp59", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21441" + ], + "details": "Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21441" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgmj-rw56-xh9r/GHSA-qgmj-rw56-xh9r.json b/advisories/unreviewed/2025/04/GHSA-qgmj-rw56-xh9r/GHSA-qgmj-rw56-xh9r.json new file mode 100644 index 00000000000..c9b4e9b2cfd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qgmj-rw56-xh9r/GHSA-qgmj-rw56-xh9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgmj-rw56-xh9r", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21423" + ], + "details": "Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21423" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qwvv-jxhc-mf6r/GHSA-qwvv-jxhc-mf6r.json b/advisories/unreviewed/2025/04/GHSA-qwvv-jxhc-mf6r/GHSA-qwvv-jxhc-mf6r.json new file mode 100644 index 00000000000..6b01ac1b962 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qwvv-jxhc-mf6r/GHSA-qwvv-jxhc-mf6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwvv-jxhc-mf6r", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-21443" + ], + "details": "Memory corruption while processing message content in eAVB.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21443" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r5vv-rjc7-pfg5/GHSA-r5vv-rjc7-pfg5.json b/advisories/unreviewed/2025/04/GHSA-r5vv-rjc7-pfg5/GHSA-r5vv-rjc7-pfg5.json new file mode 100644 index 00000000000..c8f821d5a0a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r5vv-rjc7-pfg5/GHSA-r5vv-rjc7-pfg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5vv-rjc7-pfg5", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-43046" + ], + "details": "There may be information disclosure during memory re-allocation in TZ Secure OS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43046" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgff-5rpc-xc3q/GHSA-rgff-5rpc-xc3q.json b/advisories/unreviewed/2025/04/GHSA-rgff-5rpc-xc3q/GHSA-rgff-5rpc-xc3q.json new file mode 100644 index 00000000000..738b5ad75b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgff-5rpc-xc3q/GHSA-rgff-5rpc-xc3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgff-5rpc-xc3q", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-43058" + ], + "details": "Memory corruption while processing IOCTL calls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43058" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rw9m-2gw8-75r7/GHSA-rw9m-2gw8-75r7.json b/advisories/unreviewed/2025/04/GHSA-rw9m-2gw8-75r7/GHSA-rw9m-2gw8-75r7.json new file mode 100644 index 00000000000..dbb3993cec2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rw9m-2gw8-75r7/GHSA-rw9m-2gw8-75r7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw9m-2gw8-75r7", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-3351" + ], + "details": "A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3351" + }, + { + "type": "WEB", + "url": "https://github.com/n0name-yang/myCVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303565" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303565" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v97v-vwrw-5r2q/GHSA-v97v-vwrw-5r2q.json b/advisories/unreviewed/2025/04/GHSA-v97v-vwrw-5r2q/GHSA-v97v-vwrw-5r2q.json new file mode 100644 index 00000000000..a993ef4908b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v97v-vwrw-5r2q/GHSA-v97v-vwrw-5r2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v97v-vwrw-5r2q", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21436" + ], + "details": "Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21436" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vfgm-qf58-xjrr/GHSA-vfgm-qf58-xjrr.json b/advisories/unreviewed/2025/04/GHSA-vfgm-qf58-xjrr/GHSA-vfgm-qf58-xjrr.json new file mode 100644 index 00000000000..39818efb818 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vfgm-qf58-xjrr/GHSA-vfgm-qf58-xjrr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfgm-qf58-xjrr", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-3350" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3350" + }, + { + "type": "WEB", + "url": "https://github.com/n0name-yang/myCVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303564" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303564" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vfh3-25rf-469v/GHSA-vfh3-25rf-469v.json b/advisories/unreviewed/2025/04/GHSA-vfh3-25rf-469v/GHSA-vfh3-25rf-469v.json new file mode 100644 index 00000000000..4f83d581846 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vfh3-25rf-469v/GHSA-vfh3-25rf-469v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfh3-25rf-469v", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-33058" + ], + "details": "Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33058" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vq9p-4m2j-2749/GHSA-vq9p-4m2j-2749.json b/advisories/unreviewed/2025/04/GHSA-vq9p-4m2j-2749/GHSA-vq9p-4m2j-2749.json new file mode 100644 index 00000000000..34618f3485c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vq9p-4m2j-2749/GHSA-vq9p-4m2j-2749.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq9p-4m2j-2749", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2025-21421" + ], + "details": "Memory corruption while processing escape code in API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21421" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w36r-rq68-49g7/GHSA-w36r-rq68-49g7.json b/advisories/unreviewed/2025/04/GHSA-w36r-rq68-49g7/GHSA-w36r-rq68-49g7.json new file mode 100644 index 00000000000..32f64da1492 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w36r-rq68-49g7/GHSA-w36r-rq68-49g7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w36r-rq68-49g7", + "modified": "2025-04-07T12:33:19Z", + "published": "2025-04-07T12:33:19Z", + "aliases": [ + "CVE-2025-3349" + ], + "details": "A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3349" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303563" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303563" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wrqq-6949-75w5/GHSA-wrqq-6949-75w5.json b/advisories/unreviewed/2025/04/GHSA-wrqq-6949-75w5/GHSA-wrqq-6949-75w5.json new file mode 100644 index 00000000000..08c5809ec08 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wrqq-6949-75w5/GHSA-wrqq-6949-75w5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrqq-6949-75w5", + "modified": "2025-04-07T12:33:17Z", + "published": "2025-04-07T12:33:17Z", + "aliases": [ + "CVE-2024-45540" + ], + "details": "Memory corruption while invoking IOCTL map buffer request from userspace.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45540" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpwg-v658-286m/GHSA-xpwg-v658-286m.json b/advisories/unreviewed/2025/04/GHSA-xpwg-v658-286m/GHSA-xpwg-v658-286m.json new file mode 100644 index 00000000000..40165266330 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xpwg-v658-286m/GHSA-xpwg-v658-286m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpwg-v658-286m", + "modified": "2025-04-07T12:33:18Z", + "published": "2025-04-07T12:33:18Z", + "aliases": [ + "CVE-2024-45552" + ], + "details": "Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45552" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T11:15:49Z" + } +} \ No newline at end of file