diff --git a/advisories/unreviewed/2022/05/GHSA-c2f9-w3c5-x385/GHSA-c2f9-w3c5-x385.json b/advisories/unreviewed/2022/05/GHSA-c2f9-w3c5-x385/GHSA-c2f9-w3c5-x385.json index cbd73c8f512..0eddcaf9d77 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2f9-w3c5-x385/GHSA-c2f9-w3c5-x385.json +++ b/advisories/unreviewed/2022/05/GHSA-c2f9-w3c5-x385/GHSA-c2f9-w3c5-x385.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2f9-w3c5-x385", - "modified": "2022-05-02T03:35:02Z", + "modified": "2025-03-27T15:30:34Z", "published": "2022-05-02T03:35:02Z", "aliases": [ "CVE-2009-2409" @@ -164,7 +164,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-4gvq-c37w-77wr/GHSA-4gvq-c37w-77wr.json b/advisories/unreviewed/2023/01/GHSA-4gvq-c37w-77wr/GHSA-4gvq-c37w-77wr.json index c563c476926..89fcf88bd54 100644 --- a/advisories/unreviewed/2023/01/GHSA-4gvq-c37w-77wr/GHSA-4gvq-c37w-77wr.json +++ b/advisories/unreviewed/2023/01/GHSA-4gvq-c37w-77wr/GHSA-4gvq-c37w-77wr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gvq-c37w-77wr", - "modified": "2023-02-07T18:30:19Z", + "modified": "2025-03-27T15:30:36Z", "published": "2023-01-31T06:30:26Z", "aliases": [ "CVE-2022-4898" diff --git a/advisories/unreviewed/2023/01/GHSA-5j7h-6h58-qc57/GHSA-5j7h-6h58-qc57.json b/advisories/unreviewed/2023/01/GHSA-5j7h-6h58-qc57/GHSA-5j7h-6h58-qc57.json index fce58b479d7..dbfa36b97af 100644 --- a/advisories/unreviewed/2023/01/GHSA-5j7h-6h58-qc57/GHSA-5j7h-6h58-qc57.json +++ b/advisories/unreviewed/2023/01/GHSA-5j7h-6h58-qc57/GHSA-5j7h-6h58-qc57.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-425" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-6rr3-mpxq-hv4x/GHSA-6rr3-mpxq-hv4x.json b/advisories/unreviewed/2023/01/GHSA-6rr3-mpxq-hv4x/GHSA-6rr3-mpxq-hv4x.json index 1f0cf2a8103..7916ca3925f 100644 --- a/advisories/unreviewed/2023/01/GHSA-6rr3-mpxq-hv4x/GHSA-6rr3-mpxq-hv4x.json +++ b/advisories/unreviewed/2023/01/GHSA-6rr3-mpxq-hv4x/GHSA-6rr3-mpxq-hv4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rr3-mpxq-hv4x", - "modified": "2023-02-08T00:30:36Z", + "modified": "2025-03-27T15:30:36Z", "published": "2023-01-31T18:30:22Z", "aliases": [ "CVE-2022-24963" diff --git a/advisories/unreviewed/2023/01/GHSA-v638-f74c-5q62/GHSA-v638-f74c-5q62.json b/advisories/unreviewed/2023/01/GHSA-v638-f74c-5q62/GHSA-v638-f74c-5q62.json index 3fa1ebeaba5..b09cb3295cb 100644 --- a/advisories/unreviewed/2023/01/GHSA-v638-f74c-5q62/GHSA-v638-f74c-5q62.json +++ b/advisories/unreviewed/2023/01/GHSA-v638-f74c-5q62/GHSA-v638-f74c-5q62.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-24r8-jmfh-r268/GHSA-24r8-jmfh-r268.json b/advisories/unreviewed/2023/02/GHSA-24r8-jmfh-r268/GHSA-24r8-jmfh-r268.json index b9129314c77..39c693e88a5 100644 --- a/advisories/unreviewed/2023/02/GHSA-24r8-jmfh-r268/GHSA-24r8-jmfh-r268.json +++ b/advisories/unreviewed/2023/02/GHSA-24r8-jmfh-r268/GHSA-24r8-jmfh-r268.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24r8-jmfh-r268", - "modified": "2023-02-08T03:30:25Z", + "modified": "2025-03-27T15:30:37Z", "published": "2023-02-01T00:30:29Z", "aliases": [ "CVE-2022-47873" diff --git a/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json b/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json index 7e3a4af55e2..e03e6735066 100644 --- a/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json +++ b/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-942" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-3vj7-j945-rq57/GHSA-3vj7-j945-rq57.json b/advisories/unreviewed/2023/02/GHSA-3vj7-j945-rq57/GHSA-3vj7-j945-rq57.json index 8428df528f0..db731c65347 100644 --- a/advisories/unreviewed/2023/02/GHSA-3vj7-j945-rq57/GHSA-3vj7-j945-rq57.json +++ b/advisories/unreviewed/2023/02/GHSA-3vj7-j945-rq57/GHSA-3vj7-j945-rq57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vj7-j945-rq57", - "modified": "2023-02-08T18:30:23Z", + "modified": "2025-03-27T15:30:40Z", "published": "2023-02-01T03:30:28Z", "aliases": [ "CVE-2023-23846" diff --git a/advisories/unreviewed/2023/02/GHSA-4mwq-46m8-4mgj/GHSA-4mwq-46m8-4mgj.json b/advisories/unreviewed/2023/02/GHSA-4mwq-46m8-4mgj/GHSA-4mwq-46m8-4mgj.json index e77ab40862c..29ef1005c9d 100644 --- a/advisories/unreviewed/2023/02/GHSA-4mwq-46m8-4mgj/GHSA-4mwq-46m8-4mgj.json +++ b/advisories/unreviewed/2023/02/GHSA-4mwq-46m8-4mgj/GHSA-4mwq-46m8-4mgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mwq-46m8-4mgj", - "modified": "2023-02-09T18:30:28Z", + "modified": "2025-03-27T15:30:47Z", "published": "2023-02-02T15:30:45Z", "aliases": [ "CVE-2022-46552" diff --git a/advisories/unreviewed/2023/02/GHSA-5qww-r3f5-w3w9/GHSA-5qww-r3f5-w3w9.json b/advisories/unreviewed/2023/02/GHSA-5qww-r3f5-w3w9/GHSA-5qww-r3f5-w3w9.json index 49fe3c80048..40e267d9064 100644 --- a/advisories/unreviewed/2023/02/GHSA-5qww-r3f5-w3w9/GHSA-5qww-r3f5-w3w9.json +++ b/advisories/unreviewed/2023/02/GHSA-5qww-r3f5-w3w9/GHSA-5qww-r3f5-w3w9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-942" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-8grr-jg9f-p7h5/GHSA-8grr-jg9f-p7h5.json b/advisories/unreviewed/2023/02/GHSA-8grr-jg9f-p7h5/GHSA-8grr-jg9f-p7h5.json index 1fd1d257ddb..7a178bfdd10 100644 --- a/advisories/unreviewed/2023/02/GHSA-8grr-jg9f-p7h5/GHSA-8grr-jg9f-p7h5.json +++ b/advisories/unreviewed/2023/02/GHSA-8grr-jg9f-p7h5/GHSA-8grr-jg9f-p7h5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8grr-jg9f-p7h5", - "modified": "2023-02-08T00:30:34Z", + "modified": "2025-03-27T15:30:39Z", "published": "2023-02-01T03:30:28Z", "aliases": [ "CVE-2023-0454" diff --git a/advisories/unreviewed/2023/02/GHSA-g4j9-pmf2-prrv/GHSA-g4j9-pmf2-prrv.json b/advisories/unreviewed/2023/02/GHSA-g4j9-pmf2-prrv/GHSA-g4j9-pmf2-prrv.json index 83d5b27ce0b..a0d81043038 100644 --- a/advisories/unreviewed/2023/02/GHSA-g4j9-pmf2-prrv/GHSA-g4j9-pmf2-prrv.json +++ b/advisories/unreviewed/2023/02/GHSA-g4j9-pmf2-prrv/GHSA-g4j9-pmf2-prrv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-319", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/02/GHSA-m6gp-qhxx-v795/GHSA-m6gp-qhxx-v795.json b/advisories/unreviewed/2023/02/GHSA-m6gp-qhxx-v795/GHSA-m6gp-qhxx-v795.json index 6daa0632b4d..6e56c223339 100644 --- a/advisories/unreviewed/2023/02/GHSA-m6gp-qhxx-v795/GHSA-m6gp-qhxx-v795.json +++ b/advisories/unreviewed/2023/02/GHSA-m6gp-qhxx-v795/GHSA-m6gp-qhxx-v795.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6gp-qhxx-v795", - "modified": "2023-02-08T03:30:26Z", + "modified": "2025-03-27T15:30:38Z", "published": "2023-02-01T03:30:29Z", "aliases": [ "CVE-2022-47768" diff --git a/advisories/unreviewed/2023/02/GHSA-mq9j-hpwc-6h8p/GHSA-mq9j-hpwc-6h8p.json b/advisories/unreviewed/2023/02/GHSA-mq9j-hpwc-6h8p/GHSA-mq9j-hpwc-6h8p.json index 598d7e1f5d3..ad13ad83f67 100644 --- a/advisories/unreviewed/2023/02/GHSA-mq9j-hpwc-6h8p/GHSA-mq9j-hpwc-6h8p.json +++ b/advisories/unreviewed/2023/02/GHSA-mq9j-hpwc-6h8p/GHSA-mq9j-hpwc-6h8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mq9j-hpwc-6h8p", - "modified": "2023-02-08T21:30:18Z", + "modified": "2025-03-27T15:30:47Z", "published": "2023-02-02T21:33:35Z", "aliases": [ "CVE-2022-48079" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48079" }, + { + "type": "WEB", + "url": "https://blog.luckysix.cc/2022/12/22/CVE-2022-48079--%E6%A2%A6%E5%A5%88%E5%AE%9D%E5%A1%94%E4%B8%BB%E6%9C%BA%E7%B3%BB%E7%BB%9FRCE" + }, { "type": "WEB", "url": "https://thanatosxingyu.github.io" @@ -29,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-pvg4-2wp8-hx6g/GHSA-pvg4-2wp8-hx6g.json b/advisories/unreviewed/2023/02/GHSA-pvg4-2wp8-hx6g/GHSA-pvg4-2wp8-hx6g.json index bb779743c23..9ac4816e660 100644 --- a/advisories/unreviewed/2023/02/GHSA-pvg4-2wp8-hx6g/GHSA-pvg4-2wp8-hx6g.json +++ b/advisories/unreviewed/2023/02/GHSA-pvg4-2wp8-hx6g/GHSA-pvg4-2wp8-hx6g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-q3p4-9xc9-mmhf/GHSA-q3p4-9xc9-mmhf.json b/advisories/unreviewed/2023/02/GHSA-q3p4-9xc9-mmhf/GHSA-q3p4-9xc9-mmhf.json index ffffdad56bf..d737e925ede 100644 --- a/advisories/unreviewed/2023/02/GHSA-q3p4-9xc9-mmhf/GHSA-q3p4-9xc9-mmhf.json +++ b/advisories/unreviewed/2023/02/GHSA-q3p4-9xc9-mmhf/GHSA-q3p4-9xc9-mmhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3p4-9xc9-mmhf", - "modified": "2023-02-08T21:30:21Z", + "modified": "2025-03-27T15:30:40Z", "published": "2023-02-01T15:30:21Z", "aliases": [ "CVE-2022-47003" @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/02/GHSA-q3q6-m34m-pq3r/GHSA-q3q6-m34m-pq3r.json b/advisories/unreviewed/2023/02/GHSA-q3q6-m34m-pq3r/GHSA-q3q6-m34m-pq3r.json index f1bb453c356..08c8d89c42e 100644 --- a/advisories/unreviewed/2023/02/GHSA-q3q6-m34m-pq3r/GHSA-q3q6-m34m-pq3r.json +++ b/advisories/unreviewed/2023/02/GHSA-q3q6-m34m-pq3r/GHSA-q3q6-m34m-pq3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3q6-m34m-pq3r", - "modified": "2023-02-09T21:30:29Z", + "modified": "2025-03-27T15:30:47Z", "published": "2023-02-02T15:30:45Z", "aliases": [ "CVE-2022-46604" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/trippo/ResponsiveFilemanager/blob/v9.9.6/changelog.txt" }, + { + "type": "WEB", + "url": "https://medium.com/%40_sadshade/file-extention-bypass-in-responsive-filemanager-9-5-5-leading-to-rce-authenticated-3290eddc54e7" + }, { "type": "WEB", "url": "https://medium.com/@_sadshade/file-extention-bypass-in-responsive-filemanager-9-5-5-leading-to-rce-authenticated-3290eddc54e7" diff --git a/advisories/unreviewed/2023/02/GHSA-q474-j5v6-f4jg/GHSA-q474-j5v6-f4jg.json b/advisories/unreviewed/2023/02/GHSA-q474-j5v6-f4jg/GHSA-q474-j5v6-f4jg.json index b8ba347fa38..cd4e1e394cd 100644 --- a/advisories/unreviewed/2023/02/GHSA-q474-j5v6-f4jg/GHSA-q474-j5v6-f4jg.json +++ b/advisories/unreviewed/2023/02/GHSA-q474-j5v6-f4jg/GHSA-q474-j5v6-f4jg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json b/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json index 437bebadcc0..a1719ccfe9c 100644 --- a/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json +++ b/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r3h-3gcc-24g5", - "modified": "2024-04-04T05:32:18Z", + "modified": "2025-03-27T15:30:39Z", "published": "2023-07-06T19:24:08Z", "aliases": [ "CVE-2023-0524" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json b/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json index 602f3188fae..bed2e0dc5a6 100644 --- a/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json +++ b/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38v3-cwq5-jprx", - "modified": "2024-04-04T05:32:16Z", + "modified": "2025-03-27T15:30:46Z", "published": "2023-07-06T19:24:08Z", "aliases": [ "CVE-2022-31364" diff --git a/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json b/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json index da9674482e9..dd979b42af1 100644 --- a/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json +++ b/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf45-p3p9-ghwp", - "modified": "2024-04-04T05:32:19Z", + "modified": "2025-03-27T15:30:46Z", "published": "2023-07-06T19:24:08Z", "aliases": [ "CVE-2022-31363" diff --git a/advisories/unreviewed/2024/02/GHSA-57f3-xqmx-39gv/GHSA-57f3-xqmx-39gv.json b/advisories/unreviewed/2024/02/GHSA-57f3-xqmx-39gv/GHSA-57f3-xqmx-39gv.json index d45091ee4f5..c00f5b47fb4 100644 --- a/advisories/unreviewed/2024/02/GHSA-57f3-xqmx-39gv/GHSA-57f3-xqmx-39gv.json +++ b/advisories/unreviewed/2024/02/GHSA-57f3-xqmx-39gv/GHSA-57f3-xqmx-39gv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-57f3-xqmx-39gv", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:53Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26300" ], - "details": "A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.\n\n", + "details": "A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-6hmj-wm73-g83p/GHSA-6hmj-wm73-g83p.json b/advisories/unreviewed/2024/02/GHSA-6hmj-wm73-g83p/GHSA-6hmj-wm73-g83p.json index 0b03116cd15..05e9c8e0674 100644 --- a/advisories/unreviewed/2024/02/GHSA-6hmj-wm73-g83p/GHSA-6hmj-wm73-g83p.json +++ b/advisories/unreviewed/2024/02/GHSA-6hmj-wm73-g83p/GHSA-6hmj-wm73-g83p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-763w-c5w6-4pw8/GHSA-763w-c5w6-4pw8.json b/advisories/unreviewed/2024/02/GHSA-763w-c5w6-4pw8/GHSA-763w-c5w6-4pw8.json index 7b95ae3ef44..6c93235a91f 100644 --- a/advisories/unreviewed/2024/02/GHSA-763w-c5w6-4pw8/GHSA-763w-c5w6-4pw8.json +++ b/advisories/unreviewed/2024/02/GHSA-763w-c5w6-4pw8/GHSA-763w-c5w6-4pw8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-763w-c5w6-4pw8", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:53Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26298" ], - "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.\n\n", + "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-7q9h-g4j7-9vvh/GHSA-7q9h-g4j7-9vvh.json b/advisories/unreviewed/2024/02/GHSA-7q9h-g4j7-9vvh/GHSA-7q9h-g4j7-9vvh.json index 5f6f80ea8ad..20c86050310 100644 --- a/advisories/unreviewed/2024/02/GHSA-7q9h-g4j7-9vvh/GHSA-7q9h-g4j7-9vvh.json +++ b/advisories/unreviewed/2024/02/GHSA-7q9h-g4j7-9vvh/GHSA-7q9h-g4j7-9vvh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-89hg-c7w7-4f4p/GHSA-89hg-c7w7-4f4p.json b/advisories/unreviewed/2024/02/GHSA-89hg-c7w7-4f4p/GHSA-89hg-c7w7-4f4p.json index a1c27eac81a..2e41a13fddc 100644 --- a/advisories/unreviewed/2024/02/GHSA-89hg-c7w7-4f4p/GHSA-89hg-c7w7-4f4p.json +++ b/advisories/unreviewed/2024/02/GHSA-89hg-c7w7-4f4p/GHSA-89hg-c7w7-4f4p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-8hf3-685j-g9xf/GHSA-8hf3-685j-g9xf.json b/advisories/unreviewed/2024/02/GHSA-8hf3-685j-g9xf/GHSA-8hf3-685j-g9xf.json index 973f67c6ba0..957b258bd28 100644 --- a/advisories/unreviewed/2024/02/GHSA-8hf3-685j-g9xf/GHSA-8hf3-685j-g9xf.json +++ b/advisories/unreviewed/2024/02/GHSA-8hf3-685j-g9xf/GHSA-8hf3-685j-g9xf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8hf3-685j-g9xf", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:52Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26294" ], - "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.\n\n", + "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-j6mw-3p6q-wxcc/GHSA-j6mw-3p6q-wxcc.json b/advisories/unreviewed/2024/02/GHSA-j6mw-3p6q-wxcc/GHSA-j6mw-3p6q-wxcc.json index bfa6794a647..f2f4d0ed3e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-j6mw-3p6q-wxcc/GHSA-j6mw-3p6q-wxcc.json +++ b/advisories/unreviewed/2024/02/GHSA-j6mw-3p6q-wxcc/GHSA-j6mw-3p6q-wxcc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6mw-3p6q-wxcc", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:53Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26299" ], - "details": "A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.\n\n", + "details": "A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-jxq3-2hwh-v5qg/GHSA-jxq3-2hwh-v5qg.json b/advisories/unreviewed/2024/02/GHSA-jxq3-2hwh-v5qg/GHSA-jxq3-2hwh-v5qg.json index 6f5c4198ceb..88dc92c0c2f 100644 --- a/advisories/unreviewed/2024/02/GHSA-jxq3-2hwh-v5qg/GHSA-jxq3-2hwh-v5qg.json +++ b/advisories/unreviewed/2024/02/GHSA-jxq3-2hwh-v5qg/GHSA-jxq3-2hwh-v5qg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jxq3-2hwh-v5qg", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:52Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26295" ], - "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.\n\n", + "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-p52j-p77c-rqf9/GHSA-p52j-p77c-rqf9.json b/advisories/unreviewed/2024/02/GHSA-p52j-p77c-rqf9/GHSA-p52j-p77c-rqf9.json index 51fab383f7a..c3c91c25243 100644 --- a/advisories/unreviewed/2024/02/GHSA-p52j-p77c-rqf9/GHSA-p52j-p77c-rqf9.json +++ b/advisories/unreviewed/2024/02/GHSA-p52j-p77c-rqf9/GHSA-p52j-p77c-rqf9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p52j-p77c-rqf9", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:52Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26297" ], - "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.\n\n", + "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json b/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json index ce8db7ad75e..207d9d46492 100644 --- a/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json +++ b/advisories/unreviewed/2024/02/GHSA-p647-4jrw-p827/GHSA-p647-4jrw-p827.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p647-4jrw-p827", - "modified": "2024-06-10T18:30:52Z", + "modified": "2025-03-27T15:30:49Z", "published": "2024-02-19T03:30:24Z", "aliases": [ "CVE-2022-48624" ], "details": "close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-19T01:15:48Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pp42-3grw-xrgx/GHSA-pp42-3grw-xrgx.json b/advisories/unreviewed/2024/02/GHSA-pp42-3grw-xrgx/GHSA-pp42-3grw-xrgx.json index d0c349c870e..33e23fed967 100644 --- a/advisories/unreviewed/2024/02/GHSA-pp42-3grw-xrgx/GHSA-pp42-3grw-xrgx.json +++ b/advisories/unreviewed/2024/02/GHSA-pp42-3grw-xrgx/GHSA-pp42-3grw-xrgx.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json index b4f422f7304..29a67e9c6fa 100644 --- a/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json +++ b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-664" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q5ch-6whv-v4gp/GHSA-q5ch-6whv-v4gp.json b/advisories/unreviewed/2024/02/GHSA-q5ch-6whv-v4gp/GHSA-q5ch-6whv-v4gp.json index a9d185fc3be..b54491045b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-q5ch-6whv-v4gp/GHSA-q5ch-6whv-v4gp.json +++ b/advisories/unreviewed/2024/02/GHSA-q5ch-6whv-v4gp/GHSA-q5ch-6whv-v4gp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q5ch-6whv-v4gp", - "modified": "2024-02-28T00:31:55Z", + "modified": "2025-03-27T15:30:52Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26296" ], - "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.\n\n", + "details": "Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-r78h-8xqv-6cr8/GHSA-r78h-8xqv-6cr8.json b/advisories/unreviewed/2024/02/GHSA-r78h-8xqv-6cr8/GHSA-r78h-8xqv-6cr8.json index 2b3a67780a3..5f045a9466e 100644 --- a/advisories/unreviewed/2024/02/GHSA-r78h-8xqv-6cr8/GHSA-r78h-8xqv-6cr8.json +++ b/advisories/unreviewed/2024/02/GHSA-r78h-8xqv-6cr8/GHSA-r78h-8xqv-6cr8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json b/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json index 33b37d44319..3058dd33388 100644 --- a/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json +++ b/advisories/unreviewed/2024/03/GHSA-5hmm-p9xx-45x3/GHSA-5hmm-p9xx-45x3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5hmm-p9xx-45x3", - "modified": "2024-03-23T03:30:25Z", + "modified": "2025-03-27T15:30:57Z", "published": "2024-03-18T18:32:19Z", "aliases": [ "CVE-2024-28054" ], "details": "Amavis before 2.12.3 and 2.13.x before 2.13.1, in part because of its use of MIME-tools, has an Interpretation Conflict (relative to some mail user agents) when there are multiple boundary parameters in a MIME email message. Consequently, there can be an incorrect check for banned files or malware.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-436" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T17:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-79vv-2m5g-frvv/GHSA-79vv-2m5g-frvv.json b/advisories/unreviewed/2024/03/GHSA-79vv-2m5g-frvv/GHSA-79vv-2m5g-frvv.json index 41ec131bed8..774b1da0230 100644 --- a/advisories/unreviewed/2024/03/GHSA-79vv-2m5g-frvv/GHSA-79vv-2m5g-frvv.json +++ b/advisories/unreviewed/2024/03/GHSA-79vv-2m5g-frvv/GHSA-79vv-2m5g-frvv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79vv-2m5g-frvv", - "modified": "2024-03-18T21:31:21Z", + "modified": "2025-03-27T15:30:57Z", "published": "2024-03-18T21:31:21Z", "aliases": [ "CVE-2023-6821" ], "details": "The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 contains a vulnerability that allows you to read and download PHP logs without authorization", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T19:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-854j-h67v-pp6q/GHSA-854j-h67v-pp6q.json b/advisories/unreviewed/2024/03/GHSA-854j-h67v-pp6q/GHSA-854j-h67v-pp6q.json index bd2e160191f..4862cc464c0 100644 --- a/advisories/unreviewed/2024/03/GHSA-854j-h67v-pp6q/GHSA-854j-h67v-pp6q.json +++ b/advisories/unreviewed/2024/03/GHSA-854j-h67v-pp6q/GHSA-854j-h67v-pp6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-854j-h67v-pp6q", - "modified": "2024-03-22T03:30:44Z", + "modified": "2025-03-27T15:30:57Z", "published": "2024-03-22T03:30:44Z", "aliases": [ "CVE-2024-26557" ], "details": "Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8736-3hpp-94vj/GHSA-8736-3hpp-94vj.json b/advisories/unreviewed/2024/03/GHSA-8736-3hpp-94vj/GHSA-8736-3hpp-94vj.json index c43fdf8d9e5..fde7c6b8050 100644 --- a/advisories/unreviewed/2024/03/GHSA-8736-3hpp-94vj/GHSA-8736-3hpp-94vj.json +++ b/advisories/unreviewed/2024/03/GHSA-8736-3hpp-94vj/GHSA-8736-3hpp-94vj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6wmc-pfvg-7c68/GHSA-6wmc-pfvg-7c68.json b/advisories/unreviewed/2024/04/GHSA-6wmc-pfvg-7c68/GHSA-6wmc-pfvg-7c68.json index 286144e2305..fcc897ba287 100644 --- a/advisories/unreviewed/2024/04/GHSA-6wmc-pfvg-7c68/GHSA-6wmc-pfvg-7c68.json +++ b/advisories/unreviewed/2024/04/GHSA-6wmc-pfvg-7c68/GHSA-6wmc-pfvg-7c68.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json b/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json index 38f3ab69736..34c738601ff 100644 --- a/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json +++ b/advisories/unreviewed/2024/04/GHSA-jgfj-pqpg-7r5f/GHSA-jgfj-pqpg-7r5f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jgfj-pqpg-7r5f", - "modified": "2024-04-26T06:30:35Z", + "modified": "2025-03-27T15:30:57Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-3075" ], "details": "The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T05:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json b/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json index 155b9776ed1..02fccb48ccf 100644 --- a/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json +++ b/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-121" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-989m-gr7j-mv6g/GHSA-989m-gr7j-mv6g.json b/advisories/unreviewed/2024/05/GHSA-989m-gr7j-mv6g/GHSA-989m-gr7j-mv6g.json index 61b34d64806..b5eb10f6cca 100644 --- a/advisories/unreviewed/2024/05/GHSA-989m-gr7j-mv6g/GHSA-989m-gr7j-mv6g.json +++ b/advisories/unreviewed/2024/05/GHSA-989m-gr7j-mv6g/GHSA-989m-gr7j-mv6g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9g97-rgrc-9vhg/GHSA-9g97-rgrc-9vhg.json b/advisories/unreviewed/2024/05/GHSA-9g97-rgrc-9vhg/GHSA-9g97-rgrc-9vhg.json index 7b522f2acae..7341e7604c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g97-rgrc-9vhg/GHSA-9g97-rgrc-9vhg.json +++ b/advisories/unreviewed/2024/05/GHSA-9g97-rgrc-9vhg/GHSA-9g97-rgrc-9vhg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9g97-rgrc-9vhg", - "modified": "2024-05-14T18:30:59Z", + "modified": "2025-03-27T15:30:58Z", "published": "2024-05-14T18:30:59Z", "aliases": [ "CVE-2024-22268" ], - "details": "VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.\n\n", + "details": "VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json b/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json index ddc567cf01f..cc4e5e75087 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json +++ b/advisories/unreviewed/2024/05/GHSA-cxq3-mwqc-vjv7/GHSA-cxq3-mwqc-vjv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cxq3-mwqc-vjv7", - "modified": "2024-05-05T00:30:30Z", + "modified": "2025-03-27T15:30:57Z", "published": "2024-05-05T00:30:30Z", "aliases": [ "CVE-2024-34473" ], "details": "An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-04T23:15:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json b/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json index 8ed1ea564f7..c3767a1ec49 100644 --- a/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json +++ b/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv3g-6pg3-v9j8", - "modified": "2024-07-22T18:31:47Z", + "modified": "2025-03-27T15:30:58Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-33600" ], - "details": "nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference. This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", - "severity": [], + "details": "nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference. This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T20:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qj33-w9rx-fhcw/GHSA-qj33-w9rx-fhcw.json b/advisories/unreviewed/2024/05/GHSA-qj33-w9rx-fhcw/GHSA-qj33-w9rx-fhcw.json index 96fb295b36b..ccc2fc4de17 100644 --- a/advisories/unreviewed/2024/05/GHSA-qj33-w9rx-fhcw/GHSA-qj33-w9rx-fhcw.json +++ b/advisories/unreviewed/2024/05/GHSA-qj33-w9rx-fhcw/GHSA-qj33-w9rx-fhcw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qj33-w9rx-fhcw", - "modified": "2024-05-03T15:30:54Z", + "modified": "2025-03-27T15:30:58Z", "published": "2024-05-03T15:30:54Z", "aliases": [ "CVE-2024-1067" ], - "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali GPU kernel driver configurations that would allow the GPU operations to affect the userspace memory of other processes.\nThis issue affects Bifrost GPU Kernel Driver: from r41p0 through r47p0; Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n", - "severity": [], + "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali GPU kernel driver configurations that would allow the GPU operations to affect the userspace memory of other processes.\nThis issue affects Bifrost GPU Kernel Driver: from r41p0 through r47p0; Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json b/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json index 430edc4c5ae..1a3ddff85f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json +++ b/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r868-7jmm-2qf4", - "modified": "2024-05-22T06:30:38Z", + "modified": "2025-03-27T15:30:59Z", "published": "2024-05-22T06:30:38Z", "aliases": [ "CVE-2024-31394" ], "details": "Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may obtain arbitrary files on the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T05:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json b/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json index 529b025a64e..829bb1f4df3 100644 --- a/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json +++ b/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-r67x-mwhq-xx7f/GHSA-r67x-mwhq-xx7f.json b/advisories/unreviewed/2024/06/GHSA-r67x-mwhq-xx7f/GHSA-r67x-mwhq-xx7f.json index a6f4db65135..c2ecc3d00be 100644 --- a/advisories/unreviewed/2024/06/GHSA-r67x-mwhq-xx7f/GHSA-r67x-mwhq-xx7f.json +++ b/advisories/unreviewed/2024/06/GHSA-r67x-mwhq-xx7f/GHSA-r67x-mwhq-xx7f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r67x-mwhq-xx7f", - "modified": "2024-06-04T06:30:37Z", + "modified": "2025-03-27T15:30:59Z", "published": "2024-06-04T06:30:37Z", "aliases": [ "CVE-2024-4856" ], "details": "The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-23g4-q58q-5pxc/GHSA-23g4-q58q-5pxc.json b/advisories/unreviewed/2025/03/GHSA-23g4-q58q-5pxc/GHSA-23g4-q58q-5pxc.json new file mode 100644 index 00000000000..d8ffef3cb38 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-23g4-q58q-5pxc/GHSA-23g4-q58q-5pxc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23g4-q58q-5pxc", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21876" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix suspicious RCU usage\n\nCommit (\"iommu/vt-d: Allocate DMAR fault interrupts\nlocally\") moved the call to enable_drhd_fault_handling() to a code\npath that does not hold any lock while traversing the drhd list. Fix\nit by ensuring the dmar_global_lock lock is held when traversing the\ndrhd list.\n\nWithout this fix, the following warning is triggered:\n =============================\n WARNING: suspicious RCU usage\n 6.14.0-rc3 #55 Not tainted\n -----------------------------\n drivers/iommu/intel/dmar.c:2046 RCU-list traversed in non-reader section!!\n other info that might help us debug this:\n rcu_scheduler_active = 1, debug_locks = 1\n 2 locks held by cpuhp/1/23:\n #0: ffffffff84a67c50 (cpu_hotplug_lock){++++}-{0:0}, at: cpuhp_thread_fun+0x87/0x2c0\n #1: ffffffff84a6a380 (cpuhp_state-up){+.+.}-{0:0}, at: cpuhp_thread_fun+0x87/0x2c0\n stack backtrace:\n CPU: 1 UID: 0 PID: 23 Comm: cpuhp/1 Not tainted 6.14.0-rc3 #55\n Call Trace:\n \n dump_stack_lvl+0xb7/0xd0\n lockdep_rcu_suspicious+0x159/0x1f0\n ? __pfx_enable_drhd_fault_handling+0x10/0x10\n enable_drhd_fault_handling+0x151/0x180\n cpuhp_invoke_callback+0x1df/0x990\n cpuhp_thread_fun+0x1ea/0x2c0\n smpboot_thread_fn+0x1f5/0x2e0\n ? __pfx_smpboot_thread_fn+0x10/0x10\n kthread+0x12a/0x2d0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x4a/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nHolding the lock in enable_drhd_fault_handling() triggers a lockdep splat\nabout a possible deadlock between dmar_global_lock and cpu_hotplug_lock.\nThis is avoided by not holding dmar_global_lock when calling\niommu_device_register(), which initiates the device probe process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21876" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4117c72938493a77ab53cc4b8284be8fb6ec8065" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b150654f74bf0df8e6a7936d5ec51400d9ec06d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c603ccbe91d189849e1439134598ec567088dcec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-23jj-xc4c-c6gr/GHSA-23jj-xc4c-c6gr.json b/advisories/unreviewed/2025/03/GHSA-23jj-xc4c-c6gr/GHSA-23jj-xc4c-c6gr.json new file mode 100644 index 00000000000..2bb92639de7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-23jj-xc4c-c6gr/GHSA-23jj-xc4c-c6gr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23jj-xc4c-c6gr", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:07Z", + "aliases": [ + "CVE-2024-9773" + ], + "details": "An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9773" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2671808" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/498557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-29m8-wh9p-5wc4/GHSA-29m8-wh9p-5wc4.json b/advisories/unreviewed/2025/03/GHSA-29m8-wh9p-5wc4/GHSA-29m8-wh9p-5wc4.json new file mode 100644 index 00000000000..7b00afefd52 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29m8-wh9p-5wc4/GHSA-29m8-wh9p-5wc4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29m8-wh9p-5wc4", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-30067" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. \nIf an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You are fine as long as the Kylin's system and project admin access is well protected.\n\nThis issue affects Apache Kylin: from 4.0.0 through 5.0.1.\n\nUsers are recommended to upgrade to version 5.0.2 or above, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30067" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/6j19pt8yoqfphf1lprtrzoqkvz1gwbnc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2pv7-j3wp-jhrp/GHSA-2pv7-j3wp-jhrp.json b/advisories/unreviewed/2025/03/GHSA-2pv7-j3wp-jhrp/GHSA-2pv7-j3wp-jhrp.json new file mode 100644 index 00000000000..a786a0322bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2pv7-j3wp-jhrp/GHSA-2pv7-j3wp-jhrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pv7-j3wp-jhrp", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-1997" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1997" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2rcm-fq84-jjch/GHSA-2rcm-fq84-jjch.json b/advisories/unreviewed/2025/03/GHSA-2rcm-fq84-jjch/GHSA-2rcm-fq84-jjch.json index c4706859a60..1255faf4150 100644 --- a/advisories/unreviewed/2025/03/GHSA-2rcm-fq84-jjch/GHSA-2rcm-fq84-jjch.json +++ b/advisories/unreviewed/2025/03/GHSA-2rcm-fq84-jjch/GHSA-2rcm-fq84-jjch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2rcm-fq84-jjch", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:05Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26003" ], "details": "Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-36xc-3g6q-fjj6/GHSA-36xc-3g6q-fjj6.json b/advisories/unreviewed/2025/03/GHSA-36xc-3g6q-fjj6/GHSA-36xc-3g6q-fjj6.json new file mode 100644 index 00000000000..1d2c1af11ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-36xc-3g6q-fjj6/GHSA-36xc-3g6q-fjj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xc-3g6q-fjj6", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-22672" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows Server Side Request Forgery.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-for-ultimate-member/vulnerability/wordpress-video-photo-gallery-for-ultimate-member-plugin-1-1-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3f28-vrfj-2cwc/GHSA-3f28-vrfj-2cwc.json b/advisories/unreviewed/2025/03/GHSA-3f28-vrfj-2cwc/GHSA-3f28-vrfj-2cwc.json new file mode 100644 index 00000000000..0145734a42d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3f28-vrfj-2cwc/GHSA-3f28-vrfj-2cwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f28-vrfj-2cwc", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-22646" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/athemes-addons-for-elementor-lite/vulnerability/wordpress-athemes-addons-for-elementor-plugin-1-0-8-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3jrc-j5p2-v7xj/GHSA-3jrc-j5p2-v7xj.json b/advisories/unreviewed/2025/03/GHSA-3jrc-j5p2-v7xj/GHSA-3jrc-j5p2-v7xj.json new file mode 100644 index 00000000000..4cbaae11256 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3jrc-j5p2-v7xj/GHSA-3jrc-j5p2-v7xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jrc-j5p2-v7xj", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2024-56469" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56469" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3v3f-r75q-x3fq/GHSA-3v3f-r75q-x3fq.json b/advisories/unreviewed/2025/03/GHSA-3v3f-r75q-x3fq/GHSA-3v3f-r75q-x3fq.json new file mode 100644 index 00000000000..70fe0980ac9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3v3f-r75q-x3fq/GHSA-3v3f-r75q-x3fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v3f-r75q-x3fq", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26732" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BurgerThemes StoreBiz allows DOM-Based XSS.This issue affects StoreBiz: from n/a through 1.0.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/storebiz/vulnerability/wordpress-storebiz-plugin-1-0-32-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3v67-545x-ffc3/GHSA-3v67-545x-ffc3.json b/advisories/unreviewed/2025/03/GHSA-3v67-545x-ffc3/GHSA-3v67-545x-ffc3.json new file mode 100644 index 00000000000..33d0165adc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3v67-545x-ffc3/GHSA-3v67-545x-ffc3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v67-545x-ffc3", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2024-48944" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke \"/kylin/api/xxx/diag\" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another internal host has the \"/kylin/api/xxx/diag\" api\n\nendpoint open for service.\n\n\nThis issue affects Apache Kylin: from 5.0.0 \nthrough \n\n5.0.1.\n\nUsers are recommended to upgrade to version 5.0.2, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48944" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/1xxxtdfh9hzqsqgb1pd9grb8hvqdyc9x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3w57-3p47-w8ch/GHSA-3w57-3p47-w8ch.json b/advisories/unreviewed/2025/03/GHSA-3w57-3p47-w8ch/GHSA-3w57-3p47-w8ch.json new file mode 100644 index 00000000000..2c7a3735bce --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3w57-3p47-w8ch/GHSA-3w57-3p47-w8ch.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w57-3p47-w8ch", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-21868" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: allow small head cache usage with large MAX_SKB_FRAGS values\n\nSabrina reported the following splat:\n\n WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/0xba0\n Modules linked in:\n CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.14.0-rc1-net-00092-g011b03359038 #996\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n RIP: 0010:netif_napi_add_weight_locked+0x8f2/0xba0\n Code: e8 c3 e6 6a fe 48 83 c4 28 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc c7 44 24 10 ff ff ff ff e9 8f fb ff ff e8 9e e6 6a fe <0f> 0b e9 d3 fe ff ff e8 92 e6 6a fe 48 8b 04 24 be ff ff ff ff 48\n RSP: 0000:ffffc9000001fc60 EFLAGS: 00010293\n RAX: 0000000000000000 RBX: ffff88806ce48128 RCX: 1ffff11001664b9e\n RDX: ffff888008f00040 RSI: ffffffff8317ca42 RDI: ffff88800b325cb6\n RBP: ffff88800b325c40 R08: 0000000000000001 R09: ffffed100167502c\n R10: ffff88800b3a8163 R11: 0000000000000000 R12: ffff88800ac1c168\n R13: ffff88800ac1c168 R14: ffff88800ac1c168 R15: 0000000000000007\n FS: 0000000000000000(0000) GS:ffff88806ce00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffff888008201000 CR3: 0000000004c94001 CR4: 0000000000370ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n gro_cells_init+0x1ba/0x270\n xfrm_input_init+0x4b/0x2a0\n xfrm_init+0x38/0x50\n ip_rt_init+0x2d7/0x350\n ip_init+0xf/0x20\n inet_init+0x406/0x590\n do_one_initcall+0x9d/0x2e0\n do_initcalls+0x23b/0x280\n kernel_init_freeable+0x445/0x490\n kernel_init+0x20/0x1d0\n ret_from_fork+0x46/0x80\n ret_from_fork_asm+0x1a/0x30\n \n irq event stamp: 584330\n hardirqs last enabled at (584338): [] __up_console_sem+0x77/0xb0\n hardirqs last disabled at (584345): [] __up_console_sem+0x5c/0xb0\n softirqs last enabled at (583242): [] netlink_insert+0x14d/0x470\n softirqs last disabled at (583754): [] netif_napi_add_weight_locked+0x77d/0xba0\n\non kernel built with MAX_SKB_FRAGS=45, where SKB_WITH_OVERHEAD(1024)\nis smaller than GRO_MAX_HEAD.\n\nSuch built additionally contains the revert of the single page frag cache\nso that napi_get_frags() ends up using the page frag allocator, triggering\nthe splat.\n\nNote that the underlying issue is independent from the mentioned\nrevert; address it ensuring that the small head cache will fit either TCP\nand GRO allocation and updating napi_alloc_skb() and __netdev_alloc_skb()\nto select kmalloc() usage for any allocation fitting such cache.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21868" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14ad6ed30a10afbe91b0749d6378285f4225d482" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/648e440c98e260dec835e48a5d7a9993477b1f9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed0ca7d2127c63991cfaf1932b827e3f4f8ee480" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3wx9-g76r-9crv/GHSA-3wx9-g76r-9crv.json b/advisories/unreviewed/2025/03/GHSA-3wx9-g76r-9crv/GHSA-3wx9-g76r-9crv.json new file mode 100644 index 00000000000..28967b801a1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3wx9-g76r-9crv/GHSA-3wx9-g76r-9crv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wx9-g76r-9crv", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22665" + ], + "details": "Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RapidLoad: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22665" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/unusedcss/vulnerability/wordpress-rapidload-plugin-2-4-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xg4-2966-c7r4/GHSA-3xg4-2966-c7r4.json b/advisories/unreviewed/2025/03/GHSA-3xg4-2966-c7r4/GHSA-3xg4-2966-c7r4.json index d64a3700e6d..54a302b781e 100644 --- a/advisories/unreviewed/2025/03/GHSA-3xg4-2966-c7r4/GHSA-3xg4-2966-c7r4.json +++ b/advisories/unreviewed/2025/03/GHSA-3xg4-2966-c7r4/GHSA-3xg4-2966-c7r4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3xg4-2966-c7r4", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26009" ], "details": "Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-43cr-v8vv-86x6/GHSA-43cr-v8vv-86x6.json b/advisories/unreviewed/2025/03/GHSA-43cr-v8vv-86x6/GHSA-43cr-v8vv-86x6.json new file mode 100644 index 00000000000..6bda16922f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-43cr-v8vv-86x6/GHSA-43cr-v8vv-86x6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43cr-v8vv-86x6", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-29496" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29496" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz14.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cmr-423j-3xxc/GHSA-4cmr-423j-3xxc.json b/advisories/unreviewed/2025/03/GHSA-4cmr-423j-3xxc/GHSA-4cmr-423j-3xxc.json index 6e8a6ec28b1..d6487b08a15 100644 --- a/advisories/unreviewed/2025/03/GHSA-4cmr-423j-3xxc/GHSA-4cmr-423j-3xxc.json +++ b/advisories/unreviewed/2025/03/GHSA-4cmr-423j-3xxc/GHSA-4cmr-423j-3xxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4cmr-423j-3xxc", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:05Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26006" ], "details": "Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4fxf-g9xg-xh26/GHSA-4fxf-g9xg-xh26.json b/advisories/unreviewed/2025/03/GHSA-4fxf-g9xg-xh26/GHSA-4fxf-g9xg-xh26.json index ab87f8a4f11..3c47067f6df 100644 --- a/advisories/unreviewed/2025/03/GHSA-4fxf-g9xg-xh26/GHSA-4fxf-g9xg-xh26.json +++ b/advisories/unreviewed/2025/03/GHSA-4fxf-g9xg-xh26/GHSA-4fxf-g9xg-xh26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4fxf-g9xg-xh26", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26011" ], "details": "Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4q32-287f-wf74/GHSA-4q32-287f-wf74.json b/advisories/unreviewed/2025/03/GHSA-4q32-287f-wf74/GHSA-4q32-287f-wf74.json new file mode 100644 index 00000000000..ef1620b04c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4q32-287f-wf74/GHSA-4q32-287f-wf74.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q32-287f-wf74", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21886" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix implicit ODP hang on parent deregistration\n\nFix the destroy_unused_implicit_child_mr() to prevent hanging during\nparent deregistration as of below [1].\n\nUpon entering destroy_unused_implicit_child_mr(), the reference count\nfor the implicit MR parent is incremented using:\nrefcount_inc_not_zero().\n\nA corresponding decrement must be performed if\nfree_implicit_child_mr_work() is not called.\n\nThe code has been updated to properly manage the reference count that\nwas incremented.\n\n[1]\nINFO: task python3:2157 blocked for more than 120 seconds.\nNot tainted 6.12.0-rc7+ #1633\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:python3 state:D stack:0 pid:2157 tgid:2157 ppid:1685 flags:0x00000000\nCall Trace:\n\n__schedule+0x420/0xd30\nschedule+0x47/0x130\n__mlx5_ib_dereg_mr+0x379/0x5d0 [mlx5_ib]\n? __pfx_autoremove_wake_function+0x10/0x10\nib_dereg_mr_user+0x5f/0x120 [ib_core]\n? lock_release+0xc6/0x280\ndestroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs]\nuverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs]\nuobj_destroy+0x3f/0x70 [ib_uverbs]\nib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs]\n? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs]\n? lock_acquire+0xc1/0x2f0\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0x116/0x170 [ib_uverbs]\n? lock_release+0xc6/0x280\nib_uverbs_ioctl+0xe7/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n __x64_sys_ioctl+0x1b0/0xa70\n? kmem_cache_free+0x221/0x400\ndo_syscall_64+0x6b/0x140\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f20f21f017b\nRSP: 002b:00007ffcfc4a77c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffcfc4a78d8 RCX: 00007f20f21f017b\nRDX: 00007ffcfc4a78c0 RSI: 00000000c0181b01 RDI: 0000000000000003\nRBP: 00007ffcfc4a78a0 R08: 000056147d125190 R09: 00007f20f1f14c60\nR10: 0000000000000001 R11: 0000000000000246 R12: 00007ffcfc4a7890\nR13: 000000000000001c R14: 000056147d100fc0 R15: 00007f20e365c9d0\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21886" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d8c6f26893d55fab218ad086719de1fc9bb86ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a095ede2daca49d15e74d66d014883f2fa8bb924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb96ae783e7249e8e5a50c22952c0bb2983133df" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-554v-gm73-8gvq/GHSA-554v-gm73-8gvq.json b/advisories/unreviewed/2025/03/GHSA-554v-gm73-8gvq/GHSA-554v-gm73-8gvq.json new file mode 100644 index 00000000000..a6ed711becb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-554v-gm73-8gvq/GHSA-554v-gm73-8gvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-554v-gm73-8gvq", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22660" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include Mastodon Feed allows DOM-Based XSS.This issue affects Include Mastodon Feed: from n/a through 1.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22660" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/include-mastodon-feed/vulnerability/wordpress-include-mastodon-feed-plugin-1-9-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fc4-wfxq-2rjr/GHSA-5fc4-wfxq-2rjr.json b/advisories/unreviewed/2025/03/GHSA-5fc4-wfxq-2rjr/GHSA-5fc4-wfxq-2rjr.json new file mode 100644 index 00000000000..a76840edea1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fc4-wfxq-2rjr/GHSA-5fc4-wfxq-2rjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fc4-wfxq-2rjr", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-22648" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, Posts and Category Filter for Elementor allows Stored XSS.This issue affects Blog, Posts and Category Filter for Elementor: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blog-posts-and-category-for-elementor/vulnerability/wordpress-blog-posts-and-category-filter-for-elementor-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5h76-6cjf-jv37/GHSA-5h76-6cjf-jv37.json b/advisories/unreviewed/2025/03/GHSA-5h76-6cjf-jv37/GHSA-5h76-6cjf-jv37.json new file mode 100644 index 00000000000..0acb9b3de90 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5h76-6cjf-jv37/GHSA-5h76-6cjf-jv37.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h76-6cjf-jv37", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21885" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix the page details for the srq created by kernel consumers\n\nWhile using nvme target with use_srq on, below kernel panic is noticed.\n\n[ 549.698111] bnxt_en 0000:41:00.0 enp65s0np0: FEC autoneg off encoding: Clause 91 RS(544,514)\n[ 566.393619] Oops: divide error: 0000 [#1] PREEMPT SMP NOPTI\n..\n[ 566.393799] \n[ 566.393807] ? __die_body+0x1a/0x60\n[ 566.393823] ? die+0x38/0x60\n[ 566.393835] ? do_trap+0xe4/0x110\n[ 566.393847] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[ 566.393867] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[ 566.393881] ? do_error_trap+0x7c/0x120\n[ 566.393890] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[ 566.393911] ? exc_divide_error+0x34/0x50\n[ 566.393923] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[ 566.393939] ? asm_exc_divide_error+0x16/0x20\n[ 566.393966] ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[ 566.393997] bnxt_qplib_create_srq+0xc9/0x340 [bnxt_re]\n[ 566.394040] bnxt_re_create_srq+0x335/0x3b0 [bnxt_re]\n[ 566.394057] ? srso_return_thunk+0x5/0x5f\n[ 566.394068] ? __init_swait_queue_head+0x4a/0x60\n[ 566.394090] ib_create_srq_user+0xa7/0x150 [ib_core]\n[ 566.394147] nvmet_rdma_queue_connect+0x7d0/0xbe0 [nvmet_rdma]\n[ 566.394174] ? lock_release+0x22c/0x3f0\n[ 566.394187] ? srso_return_thunk+0x5/0x5f\n\nPage size and shift info is set only for the user space SRQs.\nSet page size and page shift for kernel space SRQs also.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2cf8e6b52aecb8fbb71c41fe5add3212814031a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/722c3db62bf60cd23acbdc8c4f445bfedae4498e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b66535356a4834a234f99e16a97eb51f2c6c5a7d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json b/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json new file mode 100644 index 00000000000..d639283bd97 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65g2-8fcx-v5pc", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29483" + ], + "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29483" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69qf-f58q-rm7m/GHSA-69qf-f58q-rm7m.json b/advisories/unreviewed/2025/03/GHSA-69qf-f58q-rm7m/GHSA-69qf-f58q-rm7m.json new file mode 100644 index 00000000000..b8d5084f981 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69qf-f58q-rm7m/GHSA-69qf-f58q-rm7m.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69qf-f58q-rm7m", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21873" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: bsg: Fix crash when arpmb command fails\n\nIf the device doesn't support arpmb we'll crash due to copying user data in\nbsg_transport_sg_io_fn().\n\nIn the case where ufs_bsg_exec_advanced_rpmb_req() returns an error, do not\nset the job's reply_len.\n\nMemory crash backtrace:\n3,1290,531166405,-;ufshcd 0000:00:12.5: ARPMB OP failed: error code -22\n\n4,1308,531166555,-;Call Trace:\n\n4,1309,531166559,-; \n\n4,1310,531166565,-; ? show_regs+0x6d/0x80\n\n4,1311,531166575,-; ? die+0x37/0xa0\n\n4,1312,531166583,-; ? do_trap+0xd4/0xf0\n\n4,1313,531166593,-; ? do_error_trap+0x71/0xb0\n\n4,1314,531166601,-; ? usercopy_abort+0x6c/0x80\n\n4,1315,531166610,-; ? exc_invalid_op+0x52/0x80\n\n4,1316,531166622,-; ? usercopy_abort+0x6c/0x80\n\n4,1317,531166630,-; ? asm_exc_invalid_op+0x1b/0x20\n\n4,1318,531166643,-; ? usercopy_abort+0x6c/0x80\n\n4,1319,531166652,-; __check_heap_object+0xe3/0x120\n\n4,1320,531166661,-; check_heap_object+0x185/0x1d0\n\n4,1321,531166670,-; __check_object_size.part.0+0x72/0x150\n\n4,1322,531166679,-; __check_object_size+0x23/0x30\n\n4,1323,531166688,-; bsg_transport_sg_io_fn+0x314/0x3b0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21873" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32fb5ec825f6f76bc28902181c65429a904a07fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59455f968c1004ed897ba873237657745d81ce0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e3c96ff5c5f3206984ed077b2aa8c9b7c4e0327" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f27a95845b01e86d67c8b014b4f41bd3327daa63" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6fj2-q3x5-whq9/GHSA-6fj2-q3x5-whq9.json b/advisories/unreviewed/2025/03/GHSA-6fj2-q3x5-whq9/GHSA-6fj2-q3x5-whq9.json new file mode 100644 index 00000000000..d6cbe3a175c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6fj2-q3x5-whq9/GHSA-6fj2-q3x5-whq9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fj2-q3x5-whq9", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21880" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/userptr: fix EFAULT handling\n\nCurrently we treat EFAULT from hmm_range_fault() as a non-fatal error\nwhen called from xe_vm_userptr_pin() with the idea that we want to avoid\nkilling the entire vm and chucking an error, under the assumption that\nthe user just did an unmap or something, and has no intention of\nactually touching that memory from the GPU. At this point we have\nalready zapped the PTEs so any access should generate a page fault, and\nif the pin fails there also it will then become fatal.\n\nHowever it looks like it's possible for the userptr vma to still be on\nthe rebind list in preempt_rebind_work_func(), if we had to retry the\npin again due to something happening in the caller before we did the\nrebind step, but in the meantime needing to re-validate the userptr and\nthis time hitting the EFAULT.\n\nThis explains an internal user report of hitting:\n\n[ 191.738349] WARNING: CPU: 1 PID: 157 at drivers/gpu/drm/xe/xe_res_cursor.h:158 xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe]\n[ 191.738551] Workqueue: xe-ordered-wq preempt_rebind_work_func [xe]\n[ 191.738616] RIP: 0010:xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe]\n[ 191.738690] Call Trace:\n[ 191.738692] \n[ 191.738694] ? show_regs+0x69/0x80\n[ 191.738698] ? __warn+0x93/0x1a0\n[ 191.738703] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe]\n[ 191.738759] ? report_bug+0x18f/0x1a0\n[ 191.738764] ? handle_bug+0x63/0xa0\n[ 191.738767] ? exc_invalid_op+0x19/0x70\n[ 191.738770] ? asm_exc_invalid_op+0x1b/0x20\n[ 191.738777] ? xe_pt_stage_bind.constprop.0+0x60a/0x6b0 [xe]\n[ 191.738834] ? ret_from_fork_asm+0x1a/0x30\n[ 191.738849] bind_op_prepare+0x105/0x7b0 [xe]\n[ 191.738906] ? dma_resv_reserve_fences+0x301/0x380\n[ 191.738912] xe_pt_update_ops_prepare+0x28c/0x4b0 [xe]\n[ 191.738966] ? kmemleak_alloc+0x4b/0x80\n[ 191.738973] ops_execute+0x188/0x9d0 [xe]\n[ 191.739036] xe_vm_rebind+0x4ce/0x5a0 [xe]\n[ 191.739098] ? trace_hardirqs_on+0x4d/0x60\n[ 191.739112] preempt_rebind_work_func+0x76f/0xd00 [xe]\n\nFollowed by NPD, when running some workload, since the sg was never\nactually populated but the vma is still marked for rebind when it should\nbe skipped for this special EFAULT case. This is confirmed to fix the\nuser report.\n\nv2 (MattB):\n - Move earlier.\nv3 (MattB):\n - Update the commit message to make it clear that this indeed fixes the\n issue.\n\n(cherry picked from commit 6b93cb98910c826c2e2004942f8b060311e43618)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21880" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51cc278f8ffacd5f9dc7d13191b81b912829db59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9f4fa3a7efa65615ff7db13023ac84516e99e21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/daad16d0a538fa938e344fd83927bbcfcd8a66ec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6ggc-7mcr-53wr/GHSA-6ggc-7mcr-53wr.json b/advisories/unreviewed/2025/03/GHSA-6ggc-7mcr-53wr/GHSA-6ggc-7mcr-53wr.json new file mode 100644 index 00000000000..87e62bd366a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6ggc-7mcr-53wr/GHSA-6ggc-7mcr-53wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ggc-7mcr-53wr", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-22673" + ], + "details": "Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through 5.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ean-for-woocommerce/vulnerability/wordpress-ean-barcode-generator-5-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hqc-57w7-hx9q/GHSA-6hqc-57w7-hx9q.json b/advisories/unreviewed/2025/03/GHSA-6hqc-57w7-hx9q/GHSA-6hqc-57w7-hx9q.json new file mode 100644 index 00000000000..983bd3360c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hqc-57w7-hx9q/GHSA-6hqc-57w7-hx9q.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hqc-57w7-hx9q", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21878" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: npcm: disable interrupt enable bit before devm_request_irq\n\nThe customer reports that there is a soft lockup issue related to\nthe i2c driver. After checking, the i2c module was doing a tx transfer\nand the bmc machine reboots in the middle of the i2c transaction, the i2c\nmodule keeps the status without being reset.\n\nDue to such an i2c module status, the i2c irq handler keeps getting\ntriggered since the i2c irq handler is registered in the kernel booting\nprocess after the bmc machine is doing a warm rebooting.\nThe continuous triggering is stopped by the soft lockup watchdog timer.\n\nDisable the interrupt enable bit in the i2c module before calling\ndevm_request_irq to fix this issue since the i2c relative status bit\nis read-only.\n\nHere is the soft lockup log.\n[ 28.176395] watchdog: BUG: soft lockup - CPU#0 stuck for 26s! [swapper/0:1]\n[ 28.183351] Modules linked in:\n[ 28.186407] CPU: 0 PID: 1 Comm: swapper/0 Not tainted 5.15.120-yocto-s-dirty-bbebc78 #1\n[ 28.201174] pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 28.208128] pc : __do_softirq+0xb0/0x368\n[ 28.212055] lr : __do_softirq+0x70/0x368\n[ 28.215972] sp : ffffff8035ebca00\n[ 28.219278] x29: ffffff8035ebca00 x28: 0000000000000002 x27: ffffff80071a3780\n[ 28.226412] x26: ffffffc008bdc000 x25: ffffffc008bcc640 x24: ffffffc008be50c0\n[ 28.233546] x23: ffffffc00800200c x22: 0000000000000000 x21: 000000000000001b\n[ 28.240679] x20: 0000000000000000 x19: ffffff80001c3200 x18: ffffffffffffffff\n[ 28.247812] x17: ffffffc02d2e0000 x16: ffffff8035eb8b40 x15: 00001e8480000000\n[ 28.254945] x14: 02c3647e37dbfcb6 x13: 02c364f2ab14200c x12: 0000000002c364f2\n[ 28.262078] x11: 00000000fa83b2da x10: 000000000000b67e x9 : ffffffc008010250\n[ 28.269211] x8 : 000000009d983d00 x7 : 7fffffffffffffff x6 : 0000036d74732434\n[ 28.276344] x5 : 00ffffffffffffff x4 : 0000000000000015 x3 : 0000000000000198\n[ 28.283476] x2 : ffffffc02d2e0000 x1 : 00000000000000e0 x0 : ffffffc008bdcb40\n[ 28.290611] Call trace:\n[ 28.293052] __do_softirq+0xb0/0x368\n[ 28.296625] __irq_exit_rcu+0xe0/0x100\n[ 28.300374] irq_exit+0x14/0x20\n[ 28.303513] handle_domain_irq+0x68/0x90\n[ 28.307440] gic_handle_irq+0x78/0xb0\n[ 28.311098] call_on_irq_stack+0x20/0x38\n[ 28.315019] do_interrupt_handler+0x54/0x5c\n[ 28.319199] el1_interrupt+0x2c/0x4c\n[ 28.322777] el1h_64_irq_handler+0x14/0x20\n[ 28.326872] el1h_64_irq+0x74/0x78\n[ 28.330269] __setup_irq+0x454/0x780\n[ 28.333841] request_threaded_irq+0xd0/0x1b4\n[ 28.338107] devm_request_threaded_irq+0x84/0x100\n[ 28.342809] npcm_i2c_probe_bus+0x188/0x3d0\n[ 28.346990] platform_probe+0x6c/0xc4\n[ 28.350653] really_probe+0xcc/0x45c\n[ 28.354227] __driver_probe_device+0x8c/0x160\n[ 28.358578] driver_probe_device+0x44/0xe0\n[ 28.362670] __driver_attach+0x124/0x1d0\n[ 28.366589] bus_for_each_dev+0x7c/0xe0\n[ 28.370426] driver_attach+0x28/0x30\n[ 28.373997] bus_add_driver+0x124/0x240\n[ 28.377830] driver_register+0x7c/0x124\n[ 28.381662] __platform_driver_register+0x2c/0x34\n[ 28.386362] npcm_i2c_init+0x3c/0x5c\n[ 28.389937] do_one_initcall+0x74/0x230\n[ 28.393768] kernel_init_freeable+0x24c/0x2b4\n[ 28.398126] kernel_init+0x28/0x130\n[ 28.401614] ret_from_fork+0x10/0x20\n[ 28.405189] Kernel panic - not syncing: softlockup: hung tasks\n[ 28.411011] SMP: stopping secondary CPUs\n[ 28.414933] Kernel Offset: disabled\n[ 28.418412] CPU features: 0x00000000,00000802\n[ 28.427644] Rebooting in 20 seconds..", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21878" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12d0e39916705b68d2d8ba20a8e35d1d27afc260" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b267e1b87d52b16e7dfcc7ab2ab760f6f8f9ca9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/545b563eb00d0576775da4011b3f7ffefc9e8c60" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/846e371631c57365eeb89e5db1ab0f344169af93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd1998e243f5fa25d348a384ba0b6c84d980f2b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3aea1dba97d31eceed7b622000af0406988b9c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f32d7b4dc6e791523c70e83049645dcba2a2aa33" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mjh-29cc-g228/GHSA-6mjh-29cc-g228.json b/advisories/unreviewed/2025/03/GHSA-6mjh-29cc-g228/GHSA-6mjh-29cc-g228.json new file mode 100644 index 00000000000..d7165c898f2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6mjh-29cc-g228/GHSA-6mjh-29cc-g228.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mjh-29cc-g228", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29491" + ], + "details": "An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29491" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz10.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6v68-gpqv-3rpv/GHSA-6v68-gpqv-3rpv.json b/advisories/unreviewed/2025/03/GHSA-6v68-gpqv-3rpv/GHSA-6v68-gpqv-3rpv.json index ac789816864..1b5d263cbac 100644 --- a/advisories/unreviewed/2025/03/GHSA-6v68-gpqv-3rpv/GHSA-6v68-gpqv-3rpv.json +++ b/advisories/unreviewed/2025/03/GHSA-6v68-gpqv-3rpv/GHSA-6v68-gpqv-3rpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v68-gpqv-3rpv", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:05Z", "published": "2025-03-26T21:31:06Z", "aliases": [ "CVE-2025-26002" ], "details": "Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6v9h-fq6x-7vxx/GHSA-6v9h-fq6x-7vxx.json b/advisories/unreviewed/2025/03/GHSA-6v9h-fq6x-7vxx/GHSA-6v9h-fq6x-7vxx.json new file mode 100644 index 00000000000..0ba7a3801bc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6v9h-fq6x-7vxx/GHSA-6v9h-fq6x-7vxx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v9h-fq6x-7vxx", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-29494" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29494" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz12.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json b/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json new file mode 100644 index 00000000000..a876709cd15 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x2j-qcg5-5j7v", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29485" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29485" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz4.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6xh6-m46q-mr84/GHSA-6xh6-m46q-mr84.json b/advisories/unreviewed/2025/03/GHSA-6xh6-m46q-mr84/GHSA-6xh6-m46q-mr84.json new file mode 100644 index 00000000000..cb36e779ba9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6xh6-m46q-mr84/GHSA-6xh6-m46q-mr84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xh6-m46q-mr84", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-22647" + ], + "details": "Missing Authorization vulnerability in smackcoders AIO Performance Profiler, Monitor, Optimize, Compress & Debug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22647" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-in-one-performance-accelerator/vulnerability/wordpress-aio-performance-profiler-plugin-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77cg-5fj2-g4fx/GHSA-77cg-5fj2-g4fx.json b/advisories/unreviewed/2025/03/GHSA-77cg-5fj2-g4fx/GHSA-77cg-5fj2-g4fx.json index 1f0e07125d2..42107cd9898 100644 --- a/advisories/unreviewed/2025/03/GHSA-77cg-5fj2-g4fx/GHSA-77cg-5fj2-g4fx.json +++ b/advisories/unreviewed/2025/03/GHSA-77cg-5fj2-g4fx/GHSA-77cg-5fj2-g4fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-77cg-5fj2-g4fx", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-28361" ], "details": "Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-78gx-q8f9-m49q/GHSA-78gx-q8f9-m49q.json b/advisories/unreviewed/2025/03/GHSA-78gx-q8f9-m49q/GHSA-78gx-q8f9-m49q.json new file mode 100644 index 00000000000..dbf589e550e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78gx-q8f9-m49q/GHSA-78gx-q8f9-m49q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78gx-q8f9-m49q", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-22816" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeTrendy Power Mag allows DOM-Based XSS.This issue affects Power Mag: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/power-mag/vulnerability/wordpress-power-mag-theme-1-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-83gv-643r-fr5r/GHSA-83gv-643r-fr5r.json b/advisories/unreviewed/2025/03/GHSA-83gv-643r-fr5r/GHSA-83gv-643r-fr5r.json new file mode 100644 index 00000000000..931e3a6e279 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-83gv-643r-fr5r/GHSA-83gv-643r-fr5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83gv-643r-fr5r", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-22770" + ], + "details": "Missing Authorization vulnerability in EnvoThemes Envo Multipurpose allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Multipurpose: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/envo-multipurpose/vulnerability/wordpress-envo-multipurpose-theme-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-85vr-qp4r-xf3g/GHSA-85vr-qp4r-xf3g.json b/advisories/unreviewed/2025/03/GHSA-85vr-qp4r-xf3g/GHSA-85vr-qp4r-xf3g.json new file mode 100644 index 00000000000..0c7a69e2cae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-85vr-qp4r-xf3g/GHSA-85vr-qp4r-xf3g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85vr-qp4r-xf3g", + "modified": "2025-03-27T15:31:15Z", + "published": "2025-03-27T15:31:15Z", + "aliases": [ + "CVE-2025-31180" + ], + "details": "A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31180" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31180" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355339" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json b/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json new file mode 100644 index 00000000000..6d7d511ec62 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-892m-ppf5-vm26", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-29492" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29492" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz9.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json b/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json new file mode 100644 index 00000000000..c7b2da14ead --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c63-c298-4546", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-29497" + ], + "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29497" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz15.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8crq-pjp2-xx5g/GHSA-8crq-pjp2-xx5g.json b/advisories/unreviewed/2025/03/GHSA-8crq-pjp2-xx5g/GHSA-8crq-pjp2-xx5g.json index 4135453f383..e05cecbb034 100644 --- a/advisories/unreviewed/2025/03/GHSA-8crq-pjp2-xx5g/GHSA-8crq-pjp2-xx5g.json +++ b/advisories/unreviewed/2025/03/GHSA-8crq-pjp2-xx5g/GHSA-8crq-pjp2-xx5g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8crq-pjp2-xx5g", - "modified": "2025-03-26T21:31:06Z", + "modified": "2025-03-27T15:31:05Z", "published": "2025-03-26T21:31:06Z", "aliases": [ "CVE-2025-26004" ], "details": "Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8h26-hc89-g7w7/GHSA-8h26-hc89-g7w7.json b/advisories/unreviewed/2025/03/GHSA-8h26-hc89-g7w7/GHSA-8h26-hc89-g7w7.json index e5bb679459f..c0082633e56 100644 --- a/advisories/unreviewed/2025/03/GHSA-8h26-hc89-g7w7/GHSA-8h26-hc89-g7w7.json +++ b/advisories/unreviewed/2025/03/GHSA-8h26-hc89-g7w7/GHSA-8h26-hc89-g7w7.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-191" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-8p7r-x8qv-vv63/GHSA-8p7r-x8qv-vv63.json b/advisories/unreviewed/2025/03/GHSA-8p7r-x8qv-vv63/GHSA-8p7r-x8qv-vv63.json new file mode 100644 index 00000000000..80ff5eae83b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8p7r-x8qv-vv63/GHSA-8p7r-x8qv-vv63.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p7r-x8qv-vv63", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21875" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: always handle address removal under msk socket lock\n\nSyzkaller reported a lockdep splat in the PM control path:\n\n WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 sock_owned_by_me include/net/sock.h:1711 [inline]\n WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 msk_owned_by_me net/mptcp/protocol.h:363 [inline]\n WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 mptcp_pm_nl_addr_send_ack+0x57c/0x610 net/mptcp/pm_netlink.c:788\n Modules linked in:\n CPU: 0 UID: 0 PID: 6693 Comm: syz.0.205 Not tainted 6.14.0-rc2-syzkaller-00303-gad1b832bf1cf #0\n Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024\n RIP: 0010:sock_owned_by_me include/net/sock.h:1711 [inline]\n RIP: 0010:msk_owned_by_me net/mptcp/protocol.h:363 [inline]\n RIP: 0010:mptcp_pm_nl_addr_send_ack+0x57c/0x610 net/mptcp/pm_netlink.c:788\n Code: 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 ca 7b d3 f5 eb b9 e8 c3 7b d3 f5 90 0f 0b 90 e9 dd fb ff ff e8 b5 7b d3 f5 90 <0f> 0b 90 e9 3e fb ff ff 44 89 f1 80 e1 07 38 c1 0f 8c eb fb ff ff\n RSP: 0000:ffffc900034f6f60 EFLAGS: 00010283\n RAX: ffffffff8bee3c2b RBX: 0000000000000001 RCX: 0000000000080000\n RDX: ffffc90004d42000 RSI: 000000000000a407 RDI: 000000000000a408\n RBP: ffffc900034f7030 R08: ffffffff8bee37f6 R09: 0100000000000000\n R10: dffffc0000000000 R11: ffffed100bcc62e4 R12: ffff88805e6316e0\n R13: ffff88805e630c00 R14: dffffc0000000000 R15: ffff88805e630c00\n FS: 00007f7e9a7e96c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000001b2fd18ff8 CR3: 0000000032c24000 CR4: 00000000003526f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n mptcp_pm_remove_addr+0x103/0x1d0 net/mptcp/pm.c:59\n mptcp_pm_remove_anno_addr+0x1f4/0x2f0 net/mptcp/pm_netlink.c:1486\n mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_netlink.c:1518 [inline]\n mptcp_pm_nl_del_addr_doit+0x118d/0x1af0 net/mptcp/pm_netlink.c:1629\n genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline]\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0xb1f/0xec0 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x206/0x480 net/netlink/af_netlink.c:2543\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1322 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1348\n netlink_sendmsg+0x8de/0xcb0 net/netlink/af_netlink.c:1892\n sock_sendmsg_nosec net/socket.c:718 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:733\n ____sys_sendmsg+0x53a/0x860 net/socket.c:2573\n ___sys_sendmsg net/socket.c:2627 [inline]\n __sys_sendmsg+0x269/0x350 net/socket.c:2659\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f7e9998cde9\n Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\n RSP: 002b:00007f7e9a7e9038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n RAX: ffffffffffffffda RBX: 00007f7e99ba5fa0 RCX: 00007f7e9998cde9\n RDX: 000000002000c094 RSI: 0000400000000000 RDI: 0000000000000007\n RBP: 00007f7e99a0e2a0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 0000000000000000 R14: 00007f7e99ba5fa0 R15: 00007fff49231088\n\nIndeed the PM can try to send a RM_ADDR over a msk without acquiring\nfirst the msk socket lock.\n\nThe bugged code-path comes from an early optimization: when there\nare no subflows, the PM should (usually) not send RM_ADDR\nnotifications.\n\nThe above statement is incorrect, as without locks another process\ncould concur\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21875" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c3de6dff4373f1036e003f49a32629359530bdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4124b782ec2b1e2e490cf0bbf10f53dfd3479890" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/494ec285535632732eaa5786297a9ae4f731b5ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7cca31035c05819643ffb5d7518e9a331b3f6651" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8116fb4acd5d3f06cd37f84887dbe962b6703b1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a05da2be18aae7e82572f8d795f41bb49f5dfc7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f865c24bc55158313d5779fc81116023a6940ca3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8q6h-p3g8-vf5g/GHSA-8q6h-p3g8-vf5g.json b/advisories/unreviewed/2025/03/GHSA-8q6h-p3g8-vf5g/GHSA-8q6h-p3g8-vf5g.json index aeea2fc0102..64112b7228f 100644 --- a/advisories/unreviewed/2025/03/GHSA-8q6h-p3g8-vf5g/GHSA-8q6h-p3g8-vf5g.json +++ b/advisories/unreviewed/2025/03/GHSA-8q6h-p3g8-vf5g/GHSA-8q6h-p3g8-vf5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8q6h-p3g8-vf5g", - "modified": "2025-03-21T06:30:27Z", + "modified": "2025-03-27T15:31:01Z", "published": "2025-03-21T06:30:27Z", "aliases": [ "CVE-2024-50053" diff --git a/advisories/unreviewed/2025/03/GHSA-8q6v-m8cx-v8fj/GHSA-8q6v-m8cx-v8fj.json b/advisories/unreviewed/2025/03/GHSA-8q6v-m8cx-v8fj/GHSA-8q6v-m8cx-v8fj.json new file mode 100644 index 00000000000..4c1a6180dd6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8q6v-m8cx-v8fj/GHSA-8q6v-m8cx-v8fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q6v-m8cx-v8fj", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26738" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Interest Slider allows DOM-Based XSS.This issue affects Quick Interest Slider: from n/a through 3.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-interest-slider/vulnerability/wordpress-quick-interest-slider-plugin-3-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8xr4-8v2f-pqrx/GHSA-8xr4-8v2f-pqrx.json b/advisories/unreviewed/2025/03/GHSA-8xr4-8v2f-pqrx/GHSA-8xr4-8v2f-pqrx.json new file mode 100644 index 00000000000..404f78c07c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8xr4-8v2f-pqrx/GHSA-8xr4-8v2f-pqrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xr4-8v2f-pqrx", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-2242" + ], + "details": "An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2242" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/516271" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-957j-8wc9-pfwx/GHSA-957j-8wc9-pfwx.json b/advisories/unreviewed/2025/03/GHSA-957j-8wc9-pfwx/GHSA-957j-8wc9-pfwx.json new file mode 100644 index 00000000000..2f01d6664d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-957j-8wc9-pfwx/GHSA-957j-8wc9-pfwx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-957j-8wc9-pfwx", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21883" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix deinitializing VF in error path\n\nIf ice_ena_vfs() fails after calling ice_create_vf_entries(), it frees\nall VFs without removing them from snapshot PF-VF mailbox list, leading\nto list corruption.\n\nReproducer:\n devlink dev eswitch set $PF1_PCI mode switchdev\n ip l s $PF1 up\n ip l s $PF1 promisc on\n sleep 1\n echo 1 > /sys/class/net/$PF1/device/sriov_numvfs\n sleep 1\n echo 1 > /sys/class/net/$PF1/device/sriov_numvfs\n\nTrace (minimized):\n list_add corruption. next->prev should be prev (ffff8882e241c6f0), but was 0000000000000000. (next=ffff888455da1330).\n kernel BUG at lib/list_debug.c:29!\n RIP: 0010:__list_add_valid_or_report+0xa6/0x100\n ice_mbx_init_vf_info+0xa7/0x180 [ice]\n ice_initialize_vf_entry+0x1fa/0x250 [ice]\n ice_sriov_configure+0x8d7/0x1520 [ice]\n ? __percpu_ref_switch_mode+0x1b1/0x5d0\n ? __pfx_ice_sriov_configure+0x10/0x10 [ice]\n\nSometimes a KASAN report can be seen instead with a similar stack trace:\n BUG: KASAN: use-after-free in __list_add_valid_or_report+0xf1/0x100\n\nVFs are added to this list in ice_mbx_init_vf_info(), but only removed\nin ice_free_vfs(). Move the removing to ice_free_vf_entries(), which is\nalso being called in other places where VFs are being removed (including\nice_free_vfs() itself).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34393fd78d7183a007eaf0090966ebedcc29bd57" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c01102bec9592928e6b155da41cfcd5d25a2066" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79990cf5e7aded76d0c092c9f5ed31eb1c75e02c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4880583f88deba63504ce1c8287a70d39c01378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9g28-r45p-qwp3/GHSA-9g28-r45p-qwp3.json b/advisories/unreviewed/2025/03/GHSA-9g28-r45p-qwp3/GHSA-9g28-r45p-qwp3.json new file mode 100644 index 00000000000..513e47f9d60 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9g28-r45p-qwp3/GHSA-9g28-r45p-qwp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g28-r45p-qwp3", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22652" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment Forms for Paystack allows SQL Injection.This issue affects Payment Forms for Paystack: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/payment-forms-for-paystack/vulnerability/wordpress-payment-forms-for-paystack-plugin-4-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9pcq-fqff-43qc/GHSA-9pcq-fqff-43qc.json b/advisories/unreviewed/2025/03/GHSA-9pcq-fqff-43qc/GHSA-9pcq-fqff-43qc.json new file mode 100644 index 00000000000..23e38a3d2c5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9pcq-fqff-43qc/GHSA-9pcq-fqff-43qc.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pcq-fqff-43qc", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-21872" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: Don't map the entire mokvar table to determine its size\n\nCurrently, when validating the mokvar table, we (re)map the entire table\non each iteration of the loop, adding space as we discover new entries.\nIf the table grows over a certain size, this fails due to limitations of\nearly_memmap(), and we get a failure and traceback:\n\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 0 at mm/early_ioremap.c:139 __early_ioremap+0xef/0x220\n ...\n Call Trace:\n \n ? __early_ioremap+0xef/0x220\n ? __warn.cold+0x93/0xfa\n ? __early_ioremap+0xef/0x220\n ? report_bug+0xff/0x140\n ? early_fixup_exception+0x5d/0xb0\n ? early_idt_handler_common+0x2f/0x3a\n ? __early_ioremap+0xef/0x220\n ? efi_mokvar_table_init+0xce/0x1d0\n ? setup_arch+0x864/0xc10\n ? start_kernel+0x6b/0xa10\n ? x86_64_start_reservations+0x24/0x30\n ? x86_64_start_kernel+0xed/0xf0\n ? common_startup_64+0x13e/0x141\n \n ---[ end trace 0000000000000000 ]---\n mokvar: Failed to map EFI MOKvar config table pa=0x7c4c3000, size=265187.\n\nMapping the entire structure isn't actually necessary, as we don't ever\nneed more than one entry header mapped at once.\n\nChanges efi_mokvar_table_init() to only map each entry header, not the\nentire table, when determining the table size. Since we're not mapping\nany data past the variable name, it also changes the code to enforce\nthat each variable name is NUL terminated, rather than attempting to\nverify it in place.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21872" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b90e7ace79774a3540ce569e000388f8d22c9e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46c0454ffb78ce9d3355a3cccac86383ea8ddd55" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65f4aebb8127708ba668dd938e83b8558abfc5cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97bd560b6cc4c26386a53b4881bf03e96f9ba03a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea3f0b362dfe4ef885ef812bfaf4088176422c91" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9pqg-5frc-r6c9/GHSA-9pqg-5frc-r6c9.json b/advisories/unreviewed/2025/03/GHSA-9pqg-5frc-r6c9/GHSA-9pqg-5frc-r6c9.json new file mode 100644 index 00000000000..3dcbcc05710 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9pqg-5frc-r6c9/GHSA-9pqg-5frc-r6c9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pqg-5frc-r6c9", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-2255" + ], + "details": "An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2255" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2994150" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/524635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vgr-3j5w-9g36/GHSA-9vgr-3j5w-9g36.json b/advisories/unreviewed/2025/03/GHSA-9vgr-3j5w-9g36/GHSA-9vgr-3j5w-9g36.json new file mode 100644 index 00000000000..60bc1eeb3d9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vgr-3j5w-9g36/GHSA-9vgr-3j5w-9g36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vgr-3j5w-9g36", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26731" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARPrice allows Stored XSS.This issue affects ARPrice: from n/a through 4.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c2rm-4wxp-4832/GHSA-c2rm-4wxp-4832.json b/advisories/unreviewed/2025/03/GHSA-c2rm-4wxp-4832/GHSA-c2rm-4wxp-4832.json new file mode 100644 index 00000000000..a48543bf558 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c2rm-4wxp-4832/GHSA-c2rm-4wxp-4832.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2rm-4wxp-4832", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26734" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peregrinethemes Hester allows Stored XSS.This issue affects Hester: from n/a through 1.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26734" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hester/vulnerability/wordpress-hester-plugin-1-1-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c77w-wgvp-cx35/GHSA-c77w-wgvp-cx35.json b/advisories/unreviewed/2025/03/GHSA-c77w-wgvp-cx35/GHSA-c77w-wgvp-cx35.json index 738082519fc..bbeadb0d212 100644 --- a/advisories/unreviewed/2025/03/GHSA-c77w-wgvp-cx35/GHSA-c77w-wgvp-cx35.json +++ b/advisories/unreviewed/2025/03/GHSA-c77w-wgvp-cx35/GHSA-c77w-wgvp-cx35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c77w-wgvp-cx35", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:07Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2024-55965" ], "details": "An issue was discovered in Appsmith before 1.51. Users invited as \"App Viewer\" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T21:15:23Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c78c-hvp4-g9pm/GHSA-c78c-hvp4-g9pm.json b/advisories/unreviewed/2025/03/GHSA-c78c-hvp4-g9pm/GHSA-c78c-hvp4-g9pm.json new file mode 100644 index 00000000000..046ad935317 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c78c-hvp4-g9pm/GHSA-c78c-hvp4-g9pm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c78c-hvp4-g9pm", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-2852" + ], + "details": "A vulnerability has been found in SourceCodester Food Ordering Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menus/view_menu.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2852" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@gnol719/rJqOPiInye" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522402" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cchg-5m9c-jwh9/GHSA-cchg-5m9c-jwh9.json b/advisories/unreviewed/2025/03/GHSA-cchg-5m9c-jwh9/GHSA-cchg-5m9c-jwh9.json new file mode 100644 index 00000000000..5b264f8a551 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cchg-5m9c-jwh9/GHSA-cchg-5m9c-jwh9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cchg-5m9c-jwh9", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2024-58091" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/fbdev-dma: Add shadow buffering for deferred I/O\n\nDMA areas are not necessarily backed by struct page, so we cannot\nrely on it for deferred I/O. Allocate a shadow buffer for drivers\nthat require deferred I/O and use it as framebuffer memory.\n\nFixes driver errors about being \"Unable to handle kernel NULL pointer\ndereference at virtual address\" or \"Unable to handle kernel paging\nrequest at virtual address\".\n\nThe patch splits drm_fbdev_dma_driver_fbdev_probe() in an initial\nallocation, which creates the DMA-backed buffer object, and a tail\nthat sets up the fbdev data structures. There is a tail function for\ndirect memory mappings and a tail function for deferred I/O with\nthe shadow buffer.\n\nIt is no longer possible to use deferred I/O without shadow buffer.\nIt can be re-added if there exists a reliably test for usable struct\npage in the allocated DMA-backed buffer object.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3603996432997f7c88da37a97062a46cda01ac9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdc581169942de3b9e2648cfbd98c5ff9111c2c8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cjp9-h6x7-98p3/GHSA-cjp9-h6x7-98p3.json b/advisories/unreviewed/2025/03/GHSA-cjp9-h6x7-98p3/GHSA-cjp9-h6x7-98p3.json index 6fd25c37e83..ad89cfec1af 100644 --- a/advisories/unreviewed/2025/03/GHSA-cjp9-h6x7-98p3/GHSA-cjp9-h6x7-98p3.json +++ b/advisories/unreviewed/2025/03/GHSA-cjp9-h6x7-98p3/GHSA-cjp9-h6x7-98p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjp9-h6x7-98p3", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-30073" ], "details": "An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions with the same reference are completed, depending on timing. This can be used to transfer more money onto employee cards than is paid.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-488" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json b/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json new file mode 100644 index 00000000000..5c1ece12e75 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq9f-xr5j-3g97", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29490" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29490" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz8.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cvv7-5999-m892/GHSA-cvv7-5999-m892.json b/advisories/unreviewed/2025/03/GHSA-cvv7-5999-m892/GHSA-cvv7-5999-m892.json new file mode 100644 index 00000000000..73a5af0c5b3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cvv7-5999-m892/GHSA-cvv7-5999-m892.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvv7-5999-m892", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-2516" + ], + "details": "The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components.\n\nAs older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2516" + }, + { + "type": "WEB", + "url": "https://www.welivesecurity.com/en/eset-research/nspx30-sophisticated-aitm-enabled-implant-evolving-since-2005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cx5q-5hjq-7mpm/GHSA-cx5q-5hjq-7mpm.json b/advisories/unreviewed/2025/03/GHSA-cx5q-5hjq-7mpm/GHSA-cx5q-5hjq-7mpm.json index 8f86bc46396..4257bdc479c 100644 --- a/advisories/unreviewed/2025/03/GHSA-cx5q-5hjq-7mpm/GHSA-cx5q-5hjq-7mpm.json +++ b/advisories/unreviewed/2025/03/GHSA-cx5q-5hjq-7mpm/GHSA-cx5q-5hjq-7mpm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5q-5hjq-7mpm", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:05Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26005" ], "details": "Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cxqh-7ch8-jx2g/GHSA-cxqh-7ch8-jx2g.json b/advisories/unreviewed/2025/03/GHSA-cxqh-7ch8-jx2g/GHSA-cxqh-7ch8-jx2g.json new file mode 100644 index 00000000000..87fb009f8a9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cxqh-7ch8-jx2g/GHSA-cxqh-7ch8-jx2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxqh-7ch8-jx2g", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-2867" + ], + "details": "An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2867" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/512509" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f4wj-m43r-79jr/GHSA-f4wj-m43r-79jr.json b/advisories/unreviewed/2025/03/GHSA-f4wj-m43r-79jr/GHSA-f4wj-m43r-79jr.json new file mode 100644 index 00000000000..512612fc343 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f4wj-m43r-79jr/GHSA-f4wj-m43r-79jr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4wj-m43r-79jr", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21884" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: better track kernel sockets lifetime\n\nWhile kernel sockets are dismantled during pernet_operations->exit(),\ntheir freeing can be delayed by any tx packets still held in qdisc\nor device queues, due to skb_set_owner_w() prior calls.\n\nThis then trigger the following warning from ref_tracker_dir_exit() [1]\n\nTo fix this, make sure that kernel sockets own a reference on net->passive.\n\nAdd sk_net_refcnt_upgrade() helper, used whenever a kernel socket\nis converted to a refcounted one.\n\n[1]\n\n[ 136.263918][ T35] ref_tracker: net notrefcnt@ffff8880638f01e0 has 1/2 users at\n[ 136.263918][ T35] sk_alloc+0x2b3/0x370\n[ 136.263918][ T35] inet6_create+0x6ce/0x10f0\n[ 136.263918][ T35] __sock_create+0x4c0/0xa30\n[ 136.263918][ T35] inet_ctl_sock_create+0xc2/0x250\n[ 136.263918][ T35] igmp6_net_init+0x39/0x390\n[ 136.263918][ T35] ops_init+0x31e/0x590\n[ 136.263918][ T35] setup_net+0x287/0x9e0\n[ 136.263918][ T35] copy_net_ns+0x33f/0x570\n[ 136.263918][ T35] create_new_namespaces+0x425/0x7b0\n[ 136.263918][ T35] unshare_nsproxy_namespaces+0x124/0x180\n[ 136.263918][ T35] ksys_unshare+0x57d/0xa70\n[ 136.263918][ T35] __x64_sys_unshare+0x38/0x40\n[ 136.263918][ T35] do_syscall_64+0xf3/0x230\n[ 136.263918][ T35] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 136.263918][ T35]\n[ 136.343488][ T35] ref_tracker: net notrefcnt@ffff8880638f01e0 has 1/2 users at\n[ 136.343488][ T35] sk_alloc+0x2b3/0x370\n[ 136.343488][ T35] inet6_create+0x6ce/0x10f0\n[ 136.343488][ T35] __sock_create+0x4c0/0xa30\n[ 136.343488][ T35] inet_ctl_sock_create+0xc2/0x250\n[ 136.343488][ T35] ndisc_net_init+0xa7/0x2b0\n[ 136.343488][ T35] ops_init+0x31e/0x590\n[ 136.343488][ T35] setup_net+0x287/0x9e0\n[ 136.343488][ T35] copy_net_ns+0x33f/0x570\n[ 136.343488][ T35] create_new_namespaces+0x425/0x7b0\n[ 136.343488][ T35] unshare_nsproxy_namespaces+0x124/0x180\n[ 136.343488][ T35] ksys_unshare+0x57d/0xa70\n[ 136.343488][ T35] __x64_sys_unshare+0x38/0x40\n[ 136.343488][ T35] do_syscall_64+0xf3/0x230\n[ 136.343488][ T35] entry_SYSCALL_64_after_hwframe+0x77/0x7f", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c70eb5c593d64d93b178905da215a9fd288a4b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c31a732fac46b00b95b78fcc9c37cb48dd6f2e0c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fccp-q48g-r5f8/GHSA-fccp-q48g-r5f8.json b/advisories/unreviewed/2025/03/GHSA-fccp-q48g-r5f8/GHSA-fccp-q48g-r5f8.json new file mode 100644 index 00000000000..ec25e8cc25a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fccp-q48g-r5f8/GHSA-fccp-q48g-r5f8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fccp-q48g-r5f8", + "modified": "2025-03-27T15:31:15Z", + "published": "2025-03-27T15:31:15Z", + "aliases": [ + "CVE-2025-31181" + ], + "details": "A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31181" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31181" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fcmx-wvw9-587f/GHSA-fcmx-wvw9-587f.json b/advisories/unreviewed/2025/03/GHSA-fcmx-wvw9-587f/GHSA-fcmx-wvw9-587f.json new file mode 100644 index 00000000000..ed145e0585c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fcmx-wvw9-587f/GHSA-fcmx-wvw9-587f.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcmx-wvw9-587f", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21891" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: ensure network headers are in skb linear part\n\nsyzbot found that ipvlan_process_v6_outbound() was assuming\nthe IPv6 network header isis present in skb->head [1]\n\nAdd the needed pskb_network_may_pull() calls for both\nIPv4 and IPv6 handlers.\n\n[1]\nBUG: KMSAN: uninit-value in __ipv6_addr_type+0xa2/0x490 net/ipv6/addrconf_core.c:47\n __ipv6_addr_type+0xa2/0x490 net/ipv6/addrconf_core.c:47\n ipv6_addr_type include/net/ipv6.h:555 [inline]\n ip6_route_output_flags_noref net/ipv6/route.c:2616 [inline]\n ip6_route_output_flags+0x51/0x720 net/ipv6/route.c:2651\n ip6_route_output include/net/ip6_route.h:93 [inline]\n ipvlan_route_v6_outbound+0x24e/0x520 drivers/net/ipvlan/ipvlan_core.c:476\n ipvlan_process_v6_outbound drivers/net/ipvlan/ipvlan_core.c:491 [inline]\n ipvlan_process_outbound drivers/net/ipvlan/ipvlan_core.c:541 [inline]\n ipvlan_xmit_mode_l3 drivers/net/ipvlan/ipvlan_core.c:605 [inline]\n ipvlan_queue_xmit+0xd72/0x1780 drivers/net/ipvlan/ipvlan_core.c:671\n ipvlan_start_xmit+0x5b/0x210 drivers/net/ipvlan/ipvlan_main.c:223\n __netdev_start_xmit include/linux/netdevice.h:5150 [inline]\n netdev_start_xmit include/linux/netdevice.h:5159 [inline]\n xmit_one net/core/dev.c:3735 [inline]\n dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3751\n sch_direct_xmit+0x399/0xd40 net/sched/sch_generic.c:343\n qdisc_restart net/sched/sch_generic.c:408 [inline]\n __qdisc_run+0x14da/0x35d0 net/sched/sch_generic.c:416\n qdisc_run+0x141/0x4d0 include/net/pkt_sched.h:127\n net_tx_action+0x78b/0x940 net/core/dev.c:5484\n handle_softirqs+0x1a0/0x7c0 kernel/softirq.c:561\n __do_softirq+0x14/0x1a kernel/softirq.c:595\n do_softirq+0x9a/0x100 kernel/softirq.c:462\n __local_bh_enable_ip+0x9f/0xb0 kernel/softirq.c:389\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline]\n __dev_queue_xmit+0x2758/0x57d0 net/core/dev.c:4611\n dev_queue_xmit include/linux/netdevice.h:3311 [inline]\n packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3132 [inline]\n packet_sendmsg+0x93e0/0xa7e0 net/packet/af_packet.c:3164\n sock_sendmsg_nosec net/socket.c:718 [inline]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21891" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27843ce6ba3d3122b65066550fe33fb8839f8aef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ec48f812804f370f622e0874e6dd8fcc58241cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5353fd89663c48f56bdff975c562cfe78b1a2e4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b8dea8d1612dc7151d2457d7d2e6a69820309bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2a4f76a2d8a44816ecd25bcbdb47b786d621974" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json b/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json new file mode 100644 index 00000000000..87f06585508 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fffw-r3h2-v6wq", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-2854" + ], + "details": "A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. The manipulation of the argument emp_type leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2854" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Fizz-L/CVE/blob/main/sql-fizz.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fj78-p3p7-vv2p/GHSA-fj78-p3p7-vv2p.json b/advisories/unreviewed/2025/03/GHSA-fj78-p3p7-vv2p/GHSA-fj78-p3p7-vv2p.json new file mode 100644 index 00000000000..377421c98f1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fj78-p3p7-vv2p/GHSA-fj78-p3p7-vv2p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj78-p3p7-vv2p", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21890" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix checksums set in idpf_rx_rsc()\n\nidpf_rx_rsc() uses skb_transport_offset(skb) while the transport header\nis not set yet.\n\nThis triggers the following warning for CONFIG_DEBUG_NET=y builds.\n\nDEBUG_NET_WARN_ON_ONCE(!skb_transport_header_was_set(skb))\n\n[ 69.261620] WARNING: CPU: 7 PID: 0 at ./include/linux/skbuff.h:3020 idpf_vport_splitq_napi_poll (include/linux/skbuff.h:3020) idpf\n[ 69.261629] Modules linked in: vfat fat dummy bridge intel_uncore_frequency_tpmi intel_uncore_frequency_common intel_vsec_tpmi idpf intel_vsec cdc_ncm cdc_eem cdc_ether usbnet mii xhci_pci xhci_hcd ehci_pci ehci_hcd libeth\n[ 69.261644] CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Tainted: G S W 6.14.0-smp-DEV #1697\n[ 69.261648] Tainted: [S]=CPU_OUT_OF_SPEC, [W]=WARN\n[ 69.261650] RIP: 0010:idpf_vport_splitq_napi_poll (include/linux/skbuff.h:3020) idpf\n[ 69.261677] ? __warn (kernel/panic.c:242 kernel/panic.c:748)\n[ 69.261682] ? idpf_vport_splitq_napi_poll (include/linux/skbuff.h:3020) idpf\n[ 69.261687] ? report_bug (lib/bug.c:?)\n[ 69.261690] ? handle_bug (arch/x86/kernel/traps.c:285)\n[ 69.261694] ? exc_invalid_op (arch/x86/kernel/traps.c:309)\n[ 69.261697] ? asm_exc_invalid_op (arch/x86/include/asm/idtentry.h:621)\n[ 69.261700] ? __pfx_idpf_vport_splitq_napi_poll (drivers/net/ethernet/intel/idpf/idpf_txrx.c:4011) idpf\n[ 69.261704] ? idpf_vport_splitq_napi_poll (include/linux/skbuff.h:3020) idpf\n[ 69.261708] ? idpf_vport_splitq_napi_poll (drivers/net/ethernet/intel/idpf/idpf_txrx.c:3072) idpf\n[ 69.261712] __napi_poll (net/core/dev.c:7194)\n[ 69.261716] net_rx_action (net/core/dev.c:7265)\n[ 69.261718] ? __qdisc_run (net/sched/sch_generic.c:293)\n[ 69.261721] ? sched_clock (arch/x86/include/asm/preempt.h:84 arch/x86/kernel/tsc.c:288)\n[ 69.261726] handle_softirqs (kernel/softirq.c:561)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21890" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4279bbebe00ffdbfd1a77567961886e35465cbdc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57e68f256911f3ab4b997141975561646ccbbb8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/674fcb4f4a7e3e277417a01788cc6daae47c3804" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fm7j-w4wp-g93x/GHSA-fm7j-w4wp-g93x.json b/advisories/unreviewed/2025/03/GHSA-fm7j-w4wp-g93x/GHSA-fm7j-w4wp-g93x.json new file mode 100644 index 00000000000..5aad77a2a31 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fm7j-w4wp-g93x/GHSA-fm7j-w4wp-g93x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm7j-w4wp-g93x", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-25086" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Secret Meta allows Reflected XSS.This issue affects Secret Meta: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25086" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/facebook-secret-meta/vulnerability/wordpress-secret-meta-plugin-1-2-1-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fvjc-2g3g-9pm4/GHSA-fvjc-2g3g-9pm4.json b/advisories/unreviewed/2025/03/GHSA-fvjc-2g3g-9pm4/GHSA-fvjc-2g3g-9pm4.json new file mode 100644 index 00000000000..34cabf5686e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fvjc-2g3g-9pm4/GHSA-fvjc-2g3g-9pm4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvjc-2g3g-9pm4", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-21870" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers\n\nOther, non DAI copier widgets could have the same stream name (sname) as\nthe ALH copier and in that case the copier->data is NULL, no alh_data is\nattached, which could lead to NULL pointer dereference.\nWe could check for this NULL pointer in sof_ipc4_prepare_copier_module()\nand avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai()\nwill miscalculate the ALH device count, causing broken audio.\n\nThe correct fix is to harden the matching logic by making sure that the\n1. widget is a DAI widget - so dai = w->private is valid\n2. the dai (and thus the copier) is ALH copier", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21870" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6fd60136d256b3b948333ebdb3835f41a95ab7ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87c8768a96092ce75cd47fe076db5080db7ac515" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93c6c2e5801aab09ef1ef99f248f3cd323c3f152" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fw4x-j9wf-qmp2/GHSA-fw4x-j9wf-qmp2.json b/advisories/unreviewed/2025/03/GHSA-fw4x-j9wf-qmp2/GHSA-fw4x-j9wf-qmp2.json index 87ef68d5436..519a2512d1d 100644 --- a/advisories/unreviewed/2025/03/GHSA-fw4x-j9wf-qmp2/GHSA-fw4x-j9wf-qmp2.json +++ b/advisories/unreviewed/2025/03/GHSA-fw4x-j9wf-qmp2/GHSA-fw4x-j9wf-qmp2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-g53p-8p8h-vwv8/GHSA-g53p-8p8h-vwv8.json b/advisories/unreviewed/2025/03/GHSA-g53p-8p8h-vwv8/GHSA-g53p-8p8h-vwv8.json new file mode 100644 index 00000000000..c6127ce5e40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g53p-8p8h-vwv8/GHSA-g53p-8p8h-vwv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g53p-8p8h-vwv8", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-22644" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce allows Stored XSS.This issue affects Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vayu-blocks/vulnerability/wordpress-vayu-blocks-gutenberg-blocks-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g779-v36v-3w99/GHSA-g779-v36v-3w99.json b/advisories/unreviewed/2025/03/GHSA-g779-v36v-3w99/GHSA-g779-v36v-3w99.json new file mode 100644 index 00000000000..6efb3d42b61 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g779-v36v-3w99/GHSA-g779-v36v-3w99.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g779-v36v-3w99", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-21867" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()\n\nKMSAN reported a use-after-free issue in eth_skb_pkt_type()[1]. The\ncause of the issue was that eth_skb_pkt_type() accessed skb's data\nthat didn't contain an Ethernet header. This occurs when\nbpf_prog_test_run_xdp() passes an invalid value as the user_data\nargument to bpf_test_init().\n\nFix this by returning an error when user_data is less than ETH_HLEN in\nbpf_test_init(). Additionally, remove the check for \"if (user_size >\nsize)\" as it is unnecessary.\n\n[1]\nBUG: KMSAN: use-after-free in eth_skb_pkt_type include/linux/etherdevice.h:627 [inline]\nBUG: KMSAN: use-after-free in eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165\n eth_skb_pkt_type include/linux/etherdevice.h:627 [inline]\n eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165\n __xdp_build_skb_from_frame+0x5a8/0xa50 net/core/xdp.c:635\n xdp_recv_frames net/bpf/test_run.c:272 [inline]\n xdp_test_run_batch net/bpf/test_run.c:361 [inline]\n bpf_test_run_xdp_live+0x2954/0x3330 net/bpf/test_run.c:390\n bpf_prog_test_run_xdp+0x148e/0x1b10 net/bpf/test_run.c:1318\n bpf_prog_test_run+0x5b7/0xa30 kernel/bpf/syscall.c:4371\n __sys_bpf+0x6a6/0xe20 kernel/bpf/syscall.c:5777\n __do_sys_bpf kernel/bpf/syscall.c:5866 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5864 [inline]\n __x64_sys_bpf+0xa4/0xf0 kernel/bpf/syscall.c:5864\n x64_sys_call+0x2ea0/0x3d90 arch/x86/include/generated/asm/syscalls_64.h:322\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1d0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n free_pages_prepare mm/page_alloc.c:1056 [inline]\n free_unref_page+0x156/0x1320 mm/page_alloc.c:2657\n __free_pages+0xa3/0x1b0 mm/page_alloc.c:4838\n bpf_ringbuf_free kernel/bpf/ringbuf.c:226 [inline]\n ringbuf_map_free+0xff/0x1e0 kernel/bpf/ringbuf.c:235\n bpf_map_free kernel/bpf/syscall.c:838 [inline]\n bpf_map_free_deferred+0x17c/0x310 kernel/bpf/syscall.c:862\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa2b/0x1b60 kernel/workqueue.c:3310\n worker_thread+0xedf/0x1550 kernel/workqueue.c:3391\n kthread+0x535/0x6b0 kernel/kthread.c:389\n ret_from_fork+0x6e/0x90 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nCPU: 1 UID: 0 PID: 17276 Comm: syz.1.16450 Not tainted 6.12.0-05490-g9bb88c659673 #8\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21867" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a9e1284e87d59b1303b69d1808d310821d6e5f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b3d638ca897e099fa99bd6d02189d3176f80a47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/972bafed67ca73ad9a56448384281eb5fd5c0ba3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d56d8a23d95100b65f40438639dd82db2af81c11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f615fccfc689cb48977d275ac2e391297b52392b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g7j6-fpp2-cq73/GHSA-g7j6-fpp2-cq73.json b/advisories/unreviewed/2025/03/GHSA-g7j6-fpp2-cq73/GHSA-g7j6-fpp2-cq73.json index 144c8a1399c..ebb5a0ac702 100644 --- a/advisories/unreviewed/2025/03/GHSA-g7j6-fpp2-cq73/GHSA-g7j6-fpp2-cq73.json +++ b/advisories/unreviewed/2025/03/GHSA-g7j6-fpp2-cq73/GHSA-g7j6-fpp2-cq73.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7j6-fpp2-cq73", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:04Z", "published": "2025-03-26T21:31:06Z", "aliases": [ "CVE-2025-26001" ], "details": "Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gggq-j347-r3w6/GHSA-gggq-j347-r3w6.json b/advisories/unreviewed/2025/03/GHSA-gggq-j347-r3w6/GHSA-gggq-j347-r3w6.json new file mode 100644 index 00000000000..35bf1f7ec67 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gggq-j347-r3w6/GHSA-gggq-j347-r3w6.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggq-j347-r3w6", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-21871" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntee: optee: Fix supplicant wait loop\n\nOP-TEE supplicant is a user-space daemon and it's possible for it\nbe hung or crashed or killed in the middle of processing an OP-TEE\nRPC call. It becomes more complicated when there is incorrect shutdown\nordering of the supplicant process vs the OP-TEE client application which\ncan eventually lead to system hang-up waiting for the closure of the\nclient application.\n\nAllow the client process waiting in kernel for supplicant response to\nbe killed rather than indefinitely waiting in an unkillable state. Also,\na normal uninterruptible wait should not have resulted in the hung-task\nwatchdog getting triggered, but the endless loop would.\n\nThis fixes issues observed during system reboot/shutdown when supplicant\ngot hung for some reason or gets crashed/killed which lead to client\ngetting hung in an unkillable state. It in turn lead to system being in\nhung up state requiring hard power off/on to recover.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0180cf0373f84fff61b16f8c062553a13dd7cfca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21234efe2a8474a6d2d01ea9573319de7858ce44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3eb4911364c764572e9db4ab900a57689a54e8ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70b0d6b0a199c5a3ee6c72f5e61681ed6f759612" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0a9a948159153be145f9471435695373904ee6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d61cc1a435e6894bfb0dd3370c6f765d2d12825d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec18520f5edc20a00c34a8c9fdd6507c355e880f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd9d2d6124c293e40797a080adf8a9c237efd8b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gm34-2m74-w3v9/GHSA-gm34-2m74-w3v9.json b/advisories/unreviewed/2025/03/GHSA-gm34-2m74-w3v9/GHSA-gm34-2m74-w3v9.json new file mode 100644 index 00000000000..3895b7fe97a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gm34-2m74-w3v9/GHSA-gm34-2m74-w3v9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm34-2m74-w3v9", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-25100" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in victoracano Cazamba allows Reflected XSS.This issue affects Cazamba: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25100" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cazamba/vulnerability/wordpress-cazamba-plugin-1-2-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gpfm-whf9-59qj/GHSA-gpfm-whf9-59qj.json b/advisories/unreviewed/2025/03/GHSA-gpfm-whf9-59qj/GHSA-gpfm-whf9-59qj.json new file mode 100644 index 00000000000..f47727774f5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gpfm-whf9-59qj/GHSA-gpfm-whf9-59qj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpfm-whf9-59qj", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26737" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes City Store allows DOM-Based XSS.This issue affects City Store: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26737" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/city-store/vulnerability/wordpress-city-store-theme-1-4-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json b/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json new file mode 100644 index 00000000000..9b1403146e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr89-4g8m-9f9g", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29488" + ], + "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29488" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz5.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h6jm-5pc8-f32c/GHSA-h6jm-5pc8-f32c.json b/advisories/unreviewed/2025/03/GHSA-h6jm-5pc8-f32c/GHSA-h6jm-5pc8-f32c.json index 178578e8dd7..4668e99ac32 100644 --- a/advisories/unreviewed/2025/03/GHSA-h6jm-5pc8-f32c/GHSA-h6jm-5pc8-f32c.json +++ b/advisories/unreviewed/2025/03/GHSA-h6jm-5pc8-f32c/GHSA-h6jm-5pc8-f32c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6jm-5pc8-f32c", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26008" ], "details": "In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json b/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json new file mode 100644 index 00000000000..051552aae40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8g5-2596-xjh9", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-2857" + ], + "details": "Following the sandbox escape in CVE-2025-2783, various Firefox developers identified a similar pattern in our IPC code. Attackers were able to confuse the parent process into leaking handles to unprivileged child processes leading to a sandbox escape. \nThe original vulnerability was being exploited in the wild. \n*This only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 136.0.4, Firefox ESR < 128.8.1, and Firefox ESR < 115.21.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2857" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1956398" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/405143032" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-19" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hm4c-83cp-q77m/GHSA-hm4c-83cp-q77m.json b/advisories/unreviewed/2025/03/GHSA-hm4c-83cp-q77m/GHSA-hm4c-83cp-q77m.json new file mode 100644 index 00000000000..f90bcf949b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hm4c-83cp-q77m/GHSA-hm4c-83cp-q77m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm4c-83cp-q77m", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-31179" + ], + "details": "A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31179" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31179" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hp5r-frgx-32v8/GHSA-hp5r-frgx-32v8.json b/advisories/unreviewed/2025/03/GHSA-hp5r-frgx-32v8/GHSA-hp5r-frgx-32v8.json new file mode 100644 index 00000000000..efe8040696d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hp5r-frgx-32v8/GHSA-hp5r-frgx-32v8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp5r-frgx-32v8", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-31176" + ], + "details": "A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31176" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31176" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json b/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json new file mode 100644 index 00000000000..c052d6bb703 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqf3-3h38-frmh", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29489" + ], + "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29489" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz7.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hqhm-v784-c624/GHSA-hqhm-v784-c624.json b/advisories/unreviewed/2025/03/GHSA-hqhm-v784-c624/GHSA-hqhm-v784-c624.json new file mode 100644 index 00000000000..4c46b683d53 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hqhm-v784-c624/GHSA-hqhm-v784-c624.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqhm-v784-c624", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22669" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through 2.7.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-event-booking/vulnerability/wordpress-awesome-event-booking-plugin-2-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hqxp-37pv-997r/GHSA-hqxp-37pv-997r.json b/advisories/unreviewed/2025/03/GHSA-hqxp-37pv-997r/GHSA-hqxp-37pv-997r.json new file mode 100644 index 00000000000..fbb9660f7dd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hqxp-37pv-997r/GHSA-hqxp-37pv-997r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqxp-37pv-997r", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-26736" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in viktoras MorningTime Lite allows Stored XSS.This issue affects MorningTime Lite: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26736" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/morningtime-lite/vulnerability/wordpress-morningtime-lite-theme-1-3-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmj6-q2wq-2jq8/GHSA-jmj6-q2wq-2jq8.json b/advisories/unreviewed/2025/03/GHSA-jmj6-q2wq-2jq8/GHSA-jmj6-q2wq-2jq8.json new file mode 100644 index 00000000000..ac1e6b8f197 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmj6-q2wq-2jq8/GHSA-jmj6-q2wq-2jq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmj6-q2wq-2jq8", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22670" + ], + "details": "Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vikbooking/vulnerability/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-7-2-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json b/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json new file mode 100644 index 00000000000..57f95c860c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrx7-5cr9-c5v4", + "modified": "2025-03-27T15:31:09Z", + "published": "2025-03-27T15:31:09Z", + "aliases": [ + "CVE-2025-2849" + ], + "details": "A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2849" + }, + { + "type": "WEB", + "url": "https://github.com/upx/upx/issues/898" + }, + { + "type": "WEB", + "url": "https://github.com/upx/upx/issues/898#issuecomment-2734082143" + }, + { + "type": "WEB", + "url": "https://github.com/upx/upx/commit/e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/19307868/input.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jvfr-jf2p-rc53/GHSA-jvfr-jf2p-rc53.json b/advisories/unreviewed/2025/03/GHSA-jvfr-jf2p-rc53/GHSA-jvfr-jf2p-rc53.json index 2711716fbf1..0909d51f89c 100644 --- a/advisories/unreviewed/2025/03/GHSA-jvfr-jf2p-rc53/GHSA-jvfr-jf2p-rc53.json +++ b/advisories/unreviewed/2025/03/GHSA-jvfr-jf2p-rc53/GHSA-jvfr-jf2p-rc53.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-208" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-jx9q-3qfh-34g2/GHSA-jx9q-3qfh-34g2.json b/advisories/unreviewed/2025/03/GHSA-jx9q-3qfh-34g2/GHSA-jx9q-3qfh-34g2.json new file mode 100644 index 00000000000..4caf70cfc09 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jx9q-3qfh-34g2/GHSA-jx9q-3qfh-34g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx9q-3qfh-34g2", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22671" + ], + "details": "Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/disable-elementor-editor-translation/vulnerability/wordpress-disable-elementor-editor-translation-plugin-1-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m87m-4m85-px6p/GHSA-m87m-4m85-px6p.json b/advisories/unreviewed/2025/03/GHSA-m87m-4m85-px6p/GHSA-m87m-4m85-px6p.json new file mode 100644 index 00000000000..c8af9b25c9f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m87m-4m85-px6p/GHSA-m87m-4m85-px6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87m-4m85-px6p", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22659" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle allows Stored XSS.This issue affects Orbit Fox by ThemeIsle: from n/a through 2.10.44.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22659" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themeisle-companion/vulnerability/wordpress-orbit-fox-by-themeisle-plugin-2-10-44-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mcf6-fpvv-xxr4/GHSA-mcf6-fpvv-xxr4.json b/advisories/unreviewed/2025/03/GHSA-mcf6-fpvv-xxr4/GHSA-mcf6-fpvv-xxr4.json new file mode 100644 index 00000000000..e7de10e61aa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mcf6-fpvv-xxr4/GHSA-mcf6-fpvv-xxr4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcf6-fpvv-xxr4", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21889" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Add RCU read lock protection to perf_iterate_ctx()\n\nThe perf_iterate_ctx() function performs RCU list traversal but\ncurrently lacks RCU read lock protection. This causes lockdep warnings\nwhen running perf probe with unshare(1) under CONFIG_PROVE_RCU_LIST=y:\n\n\tWARNING: suspicious RCU usage\n\tkernel/events/core.c:8168 RCU-list traversed in non-reader section!!\n\n\t Call Trace:\n\t lockdep_rcu_suspicious\n\t ? perf_event_addr_filters_apply\n\t perf_iterate_ctx\n\t perf_event_exec\n\t begin_new_exec\n\t ? load_elf_phdrs\n\t load_elf_binary\n\t ? lock_acquire\n\t ? find_held_lock\n\t ? bprm_execve\n\t bprm_execve\n\t do_execveat_common.isra.0\n\t __x64_sys_execve\n\t do_syscall_64\n\t entry_SYSCALL_64_after_hwframe\n\nThis protection was previously present but was removed in commit\nbd2756811766 (\"perf: Rewrite core context handling\"). Add back the\nnecessary rcu_read_lock()/rcu_read_unlock() pair around\nperf_iterate_ctx() call in perf_event_exec().\n\n[ mingo: Use scoped_guard() as suggested by Peter ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fe8813baf4b2e865d3b2c735ce1a15b86002c74" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2475ccad6120546ea45dbcd6cd1f74dc565ef6b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd536566dda9a551fc2a2acfab5313a5bb13ed02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f390c2eea571945f357a2d3b9fcb1c015767132e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mrwq-3cq2-5j36/GHSA-mrwq-3cq2-5j36.json b/advisories/unreviewed/2025/03/GHSA-mrwq-3cq2-5j36/GHSA-mrwq-3cq2-5j36.json new file mode 100644 index 00000000000..c18eda65020 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mrwq-3cq2-5j36/GHSA-mrwq-3cq2-5j36.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrwq-3cq2-5j36", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21882" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix vport QoS cleanup on error\n\nWhen enabling vport QoS fails, the scheduling node was never freed,\ncausing a leak.\n\nAdd the missing free and reset the vport scheduling node pointer to\nNULL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21882" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f3528f7d2f98b70e19a6bb7b130fc82c079ac54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fead368502bce0e10bea7c0d2895b2fa0c6c10aa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mwmh-5wxj-6hjh/GHSA-mwmh-5wxj-6hjh.json b/advisories/unreviewed/2025/03/GHSA-mwmh-5wxj-6hjh/GHSA-mwmh-5wxj-6hjh.json new file mode 100644 index 00000000000..eb5114a9d87 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mwmh-5wxj-6hjh/GHSA-mwmh-5wxj-6hjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwmh-5wxj-6hjh", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-22649" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through 2.6.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wedevs-project-manager/vulnerability/wordpress-wp-project-manager-plugin-2-6-17-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mwpv-367w-4cpc/GHSA-mwpv-367w-4cpc.json b/advisories/unreviewed/2025/03/GHSA-mwpv-367w-4cpc/GHSA-mwpv-367w-4cpc.json index e46bb610514..a88684d3814 100644 --- a/advisories/unreviewed/2025/03/GHSA-mwpv-367w-4cpc/GHSA-mwpv-367w-4cpc.json +++ b/advisories/unreviewed/2025/03/GHSA-mwpv-367w-4cpc/GHSA-mwpv-367w-4cpc.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/03/GHSA-p2jr-9qm5-gxfq/GHSA-p2jr-9qm5-gxfq.json b/advisories/unreviewed/2025/03/GHSA-p2jr-9qm5-gxfq/GHSA-p2jr-9qm5-gxfq.json new file mode 100644 index 00000000000..fe57366878d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2jr-9qm5-gxfq/GHSA-p2jr-9qm5-gxfq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2jr-9qm5-gxfq", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-29493" + ], + "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29493" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz11.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p4m8-c64v-m3v8/GHSA-p4m8-c64v-m3v8.json b/advisories/unreviewed/2025/03/GHSA-p4m8-c64v-m3v8/GHSA-p4m8-c64v-m3v8.json new file mode 100644 index 00000000000..97e40ac118f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p4m8-c64v-m3v8/GHSA-p4m8-c64v-m3v8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4m8-c64v-m3v8", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-21869" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/code-patching: Disable KASAN report during patching via temporary mm\n\nErhard reports the following KASAN hit on Talos II (power9) with kernel 6.13:\n\n[ 12.028126] ==================================================================\n[ 12.028198] BUG: KASAN: user-memory-access in copy_to_kernel_nofault+0x8c/0x1a0\n[ 12.028260] Write of size 8 at addr 0000187e458f2000 by task systemd/1\n\n[ 12.028346] CPU: 87 UID: 0 PID: 1 Comm: systemd Tainted: G T 6.13.0-P9-dirty #3\n[ 12.028408] Tainted: [T]=RANDSTRUCT\n[ 12.028446] Hardware name: T2P9D01 REV 1.01 POWER9 0x4e1202 opal:skiboot-bc106a0 PowerNV\n[ 12.028500] Call Trace:\n[ 12.028536] [c000000008dbf3b0] [c000000001656a48] dump_stack_lvl+0xbc/0x110 (unreliable)\n[ 12.028609] [c000000008dbf3f0] [c0000000006e2fc8] print_report+0x6b0/0x708\n[ 12.028666] [c000000008dbf4e0] [c0000000006e2454] kasan_report+0x164/0x300\n[ 12.028725] [c000000008dbf600] [c0000000006e54d4] kasan_check_range+0x314/0x370\n[ 12.028784] [c000000008dbf640] [c0000000006e6310] __kasan_check_write+0x20/0x40\n[ 12.028842] [c000000008dbf660] [c000000000578e8c] copy_to_kernel_nofault+0x8c/0x1a0\n[ 12.028902] [c000000008dbf6a0] [c0000000000acfe4] __patch_instructions+0x194/0x210\n[ 12.028965] [c000000008dbf6e0] [c0000000000ade80] patch_instructions+0x150/0x590\n[ 12.029026] [c000000008dbf7c0] [c0000000001159bc] bpf_arch_text_copy+0x6c/0xe0\n[ 12.029085] [c000000008dbf800] [c000000000424250] bpf_jit_binary_pack_finalize+0x40/0xc0\n[ 12.029147] [c000000008dbf830] [c000000000115dec] bpf_int_jit_compile+0x3bc/0x930\n[ 12.029206] [c000000008dbf990] [c000000000423720] bpf_prog_select_runtime+0x1f0/0x280\n[ 12.029266] [c000000008dbfa00] [c000000000434b18] bpf_prog_load+0xbb8/0x1370\n[ 12.029324] [c000000008dbfb70] [c000000000436ebc] __sys_bpf+0x5ac/0x2e00\n[ 12.029379] [c000000008dbfd00] [c00000000043a228] sys_bpf+0x28/0x40\n[ 12.029435] [c000000008dbfd20] [c000000000038eb4] system_call_exception+0x334/0x610\n[ 12.029497] [c000000008dbfe50] [c00000000000c270] system_call_vectored_common+0xf0/0x280\n[ 12.029561] --- interrupt: 3000 at 0x3fff82f5cfa8\n[ 12.029608] NIP: 00003fff82f5cfa8 LR: 00003fff82f5cfa8 CTR: 0000000000000000\n[ 12.029660] REGS: c000000008dbfe80 TRAP: 3000 Tainted: G T (6.13.0-P9-dirty)\n[ 12.029735] MSR: 900000000280f032 CR: 42004848 XER: 00000000\n[ 12.029855] IRQMASK: 0\n GPR00: 0000000000000169 00003fffdcf789a0 00003fff83067100 0000000000000005\n GPR04: 00003fffdcf78a98 0000000000000090 0000000000000000 0000000000000008\n GPR08: 0000000000000000 0000000000000000 0000000000000000 0000000000000000\n GPR12: 0000000000000000 00003fff836ff7e0 c000000000010678 0000000000000000\n GPR16: 0000000000000000 0000000000000000 00003fffdcf78f28 00003fffdcf78f90\n GPR20: 0000000000000000 0000000000000000 0000000000000000 00003fffdcf78f80\n GPR24: 00003fffdcf78f70 00003fffdcf78d10 00003fff835c7239 00003fffdcf78bd8\n GPR28: 00003fffdcf78a98 0000000000000000 0000000000000000 000000011f547580\n[ 12.030316] NIP [00003fff82f5cfa8] 0x3fff82f5cfa8\n[ 12.030361] LR [00003fff82f5cfa8] 0x3fff82f5cfa8\n[ 12.030405] --- interrupt: 3000\n[ 12.030444] ==================================================================\n\nCommit c28c15b6d28a (\"powerpc/code-patching: Use temporary mm for\nRadix MMU\") is inspired from x86 but unlike x86 is doesn't disable\nKASAN reports during patching. This wasn't a problem at the begining\nbecause __patch_mem() is not instrumented.\n\nCommit 465cabc97b42 (\"powerpc/code-patching: introduce\npatch_instructions()\") use copy_to_kernel_nofault() to copy several\ninstructions at once. But when using temporary mm the destination is\nnot regular kernel memory but a kind of kernel-like memory located\nin user address space. \n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21869" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5980d4456dd66d1b6505d5ec15048bd87e8775e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc9c5166c3cb044f8a001e397195242fd6796eee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea291447a4031f3dac5c23d55bc83fe833820d84" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pcxc-wr93-928c/GHSA-pcxc-wr93-928c.json b/advisories/unreviewed/2025/03/GHSA-pcxc-wr93-928c/GHSA-pcxc-wr93-928c.json index 86673cef8b5..176abe91bce 100644 --- a/advisories/unreviewed/2025/03/GHSA-pcxc-wr93-928c/GHSA-pcxc-wr93-928c.json +++ b/advisories/unreviewed/2025/03/GHSA-pcxc-wr93-928c/GHSA-pcxc-wr93-928c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcxc-wr93-928c", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26007" ], "details": "Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-phqr-mm9h-9x4v/GHSA-phqr-mm9h-9x4v.json b/advisories/unreviewed/2025/03/GHSA-phqr-mm9h-9x4v/GHSA-phqr-mm9h-9x4v.json new file mode 100644 index 00000000000..505e29bde0e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-phqr-mm9h-9x4v/GHSA-phqr-mm9h-9x4v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phqr-mm9h-9x4v", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29484" + ], + "details": "An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29484" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pj4h-hg6q-3xgv/GHSA-pj4h-hg6q-3xgv.json b/advisories/unreviewed/2025/03/GHSA-pj4h-hg6q-3xgv/GHSA-pj4h-hg6q-3xgv.json new file mode 100644 index 00000000000..88c0017990e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj4h-hg6q-3xgv/GHSA-pj4h-hg6q-3xgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj4h-hg6q-3xgv", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22667" + ], + "details": "Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets.This issue affects Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets: from n/a through 1.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22667" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsyncsheets-woocommerce/vulnerability/wordpress-export-order-product-customer-coupon-for-woocommerce-to-google-sheets-plugin-1-8-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pwxf-vp8f-f327/GHSA-pwxf-vp8f-f327.json b/advisories/unreviewed/2025/03/GHSA-pwxf-vp8f-f327/GHSA-pwxf-vp8f-f327.json new file mode 100644 index 00000000000..b0849cecf9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pwxf-vp8f-f327/GHSA-pwxf-vp8f-f327.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwxf-vp8f-f327", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21879" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on inode when scanning root during em shrinking\n\nAt btrfs_scan_root() we are accessing the inode's root (and fs_info) in a\ncall to btrfs_fs_closing() after we have scheduled the inode for a delayed\niput, and that can result in a use-after-free on the inode in case the\ncleaner kthread does the iput before we dereference the inode in the call\nto btrfs_fs_closing().\n\nFix this by using the fs_info stored already in a local variable instead\nof doing inode->root->fs_info.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21879" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59f37036bb7ab3d554c24abc856aabca01126414" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e79d26014f9386387575b9ed60d342057cee49b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qc34-7p9f-9q4v/GHSA-qc34-7p9f-9q4v.json b/advisories/unreviewed/2025/03/GHSA-qc34-7p9f-9q4v/GHSA-qc34-7p9f-9q4v.json new file mode 100644 index 00000000000..feb424ec888 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qc34-7p9f-9q4v/GHSA-qc34-7p9f-9q4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc34-7p9f-9q4v", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22668" + ], + "details": "Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-event-booking/vulnerability/wordpress-awesome-event-booking-plugin-2-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvvw-3v9r-73ph/GHSA-qvvw-3v9r-73ph.json b/advisories/unreviewed/2025/03/GHSA-qvvw-3v9r-73ph/GHSA-qvvw-3v9r-73ph.json new file mode 100644 index 00000000000..c0c86a59222 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvvw-3v9r-73ph/GHSA-qvvw-3v9r-73ph.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvvw-3v9r-73ph", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-0811" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0811" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2961854" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/515566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rg83-2j3j-4hmc/GHSA-rg83-2j3j-4hmc.json b/advisories/unreviewed/2025/03/GHSA-rg83-2j3j-4hmc/GHSA-rg83-2j3j-4hmc.json new file mode 100644 index 00000000000..3cbec970877 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rg83-2j3j-4hmc/GHSA-rg83-2j3j-4hmc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg83-2j3j-4hmc", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21888" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix a WARN during dereg_mr for DM type\n\nMemory regions (MR) of type DM (device memory) do not have an associated\numem.\n\nIn the __mlx5_ib_dereg_mr() -> mlx5_free_priv_descs() flow, the code\nincorrectly takes the wrong branch, attempting to call\ndma_unmap_single() on a DMA address that is not mapped.\n\nThis results in a WARN [1], as shown below.\n\nThe issue is resolved by properly accounting for the DM type and\nensuring the correct branch is selected in mlx5_free_priv_descs().\n\n[1]\nWARNING: CPU: 12 PID: 1346 at drivers/iommu/dma-iommu.c:1230 iommu_dma_unmap_page+0x79/0x90\nModules linked in: ip6table_mangle ip6table_nat ip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry ovelay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core\nCPU: 12 UID: 0 PID: 1346 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1631\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:iommu_dma_unmap_page+0x79/0x90\nCode: 2b 49 3b 29 72 26 49 3b 69 08 73 20 4d 89 f0 44 89 e9 4c 89 e2 48 89 ee 48 89 df 5b 5d 41 5c 41 5d 41 5e 41 5f e9 07 b8 88 ff <0f> 0b 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 66 0f 1f 44 00\nRSP: 0018:ffffc90001913a10 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff88810194b0a8 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001\nRBP: ffff88810194b0a8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000\nR13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f537abdd740(0000) GS:ffff88885fb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f537aeb8000 CR3: 000000010c248001 CR4: 0000000000372eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\n? __warn+0x84/0x190\n? iommu_dma_unmap_page+0x79/0x90\n? report_bug+0xf8/0x1c0\n? handle_bug+0x55/0x90\n? exc_invalid_op+0x13/0x60\n? asm_exc_invalid_op+0x16/0x20\n? iommu_dma_unmap_page+0x79/0x90\ndma_unmap_page_attrs+0xe6/0x290\nmlx5_free_priv_descs+0xb0/0xe0 [mlx5_ib]\n__mlx5_ib_dereg_mr+0x37e/0x520 [mlx5_ib]\n? _raw_spin_unlock_irq+0x24/0x40\n? wait_for_completion+0xfe/0x130\n? rdma_restrack_put+0x63/0xe0 [ib_core]\nib_dereg_mr_user+0x5f/0x120 [ib_core]\n? lock_release+0xc6/0x280\ndestroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs]\nuverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs]\nuobj_destroy+0x3f/0x70 [ib_uverbs]\nib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs]\n? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs]\n? lock_acquire+0xc1/0x2f0\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0x116/0x170 [ib_uverbs]\n? lock_release+0xc6/0x280\nib_uverbs_ioctl+0xe7/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n__x64_sys_ioctl+0x1b0/0xa70\ndo_syscall_64+0x6b/0x140\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f537adaf17b\nCode: 0f 1e fa 48 8b 05 1d ad 0c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ed ac 0c 00 f7 d8 64 89 01 48\nRSP: 002b:00007ffff218f0b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffff218f1d8 RCX: 00007f537adaf17b\nRDX: 00007ffff218f1c0 RSI: 00000000c0181b01 RDI: 0000000000000003\nRBP: 00007ffff218f1a0 R08: 00007f537aa8d010 R09: 0000561ee2e4f270\nR10: 00007f537aace3a8 R11: 0000000000000246 R12: 00007ffff218f190\nR13: 000000000000001c R14: 0000561ee2e4d7c0 R15: 00007ffff218f450\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21888" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bd34bdd468e93a779c403de3cf7d43ee633b3e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abc7b3f1f056d69a8f11d6dceecc0c9549ace770" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1298cad47ae29828c5c5be77e733ccfcaef6a7f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rgw3-j4q6-grfp/GHSA-rgw3-j4q6-grfp.json b/advisories/unreviewed/2025/03/GHSA-rgw3-j4q6-grfp/GHSA-rgw3-j4q6-grfp.json new file mode 100644 index 00000000000..c59a008c26d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rgw3-j4q6-grfp/GHSA-rgw3-j4q6-grfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgw3-j4q6-grfp", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-22658" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Appfolio allows Stored XSS.This issue affects Listings for Appfolio: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listings-for-appfolio/vulnerability/wordpress-listings-for-appfolio-plugin-1-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v2hx-rxf2-p233/GHSA-v2hx-rxf2-p233.json b/advisories/unreviewed/2025/03/GHSA-v2hx-rxf2-p233/GHSA-v2hx-rxf2-p233.json new file mode 100644 index 00000000000..60e96719660 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v2hx-rxf2-p233/GHSA-v2hx-rxf2-p233.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2hx-rxf2-p233", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21881" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes: Reject the shared zeropage in uprobe_write_opcode()\n\nWe triggered the following crash in syzkaller tests:\n\n BUG: Bad page state in process syz.7.38 pfn:1eff3\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1eff3\n flags: 0x3fffff00004004(referenced|reserved|node=0|zone=1|lastcpupid=0x1fffff)\n raw: 003fffff00004004 ffffe6c6c07bfcc8 ffffe6c6c07bfcc8 0000000000000000\n raw: 0000000000000000 0000000000000000 00000000fffffffe 0000000000000000\n page dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x32/0x50\n bad_page+0x69/0xf0\n free_unref_page_prepare+0x401/0x500\n free_unref_page+0x6d/0x1b0\n uprobe_write_opcode+0x460/0x8e0\n install_breakpoint.part.0+0x51/0x80\n register_for_each_vma+0x1d9/0x2b0\n __uprobe_register+0x245/0x300\n bpf_uprobe_multi_link_attach+0x29b/0x4f0\n link_create+0x1e2/0x280\n __sys_bpf+0x75f/0xac0\n __x64_sys_bpf+0x1a/0x30\n do_syscall_64+0x56/0x100\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\n\n BUG: Bad rss-counter state mm:00000000452453e0 type:MM_FILEPAGES val:-1\n\nThe following syzkaller test case can be used to reproduce:\n\n r2 = creat(&(0x7f0000000000)='./file0\\x00', 0x8)\n write$nbd(r2, &(0x7f0000000580)=ANY=[], 0x10)\n r4 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\\x00', 0x42, 0x0)\n mmap$IORING_OFF_SQ_RING(&(0x7f0000ffd000/0x3000)=nil, 0x3000, 0x0, 0x12, r4, 0x0)\n r5 = userfaultfd(0x80801)\n ioctl$UFFDIO_API(r5, 0xc018aa3f, &(0x7f0000000040)={0xaa, 0x20})\n r6 = userfaultfd(0x80801)\n ioctl$UFFDIO_API(r6, 0xc018aa3f, &(0x7f0000000140))\n ioctl$UFFDIO_REGISTER(r6, 0xc020aa00, &(0x7f0000000100)={{&(0x7f0000ffc000/0x4000)=nil, 0x4000}, 0x2})\n ioctl$UFFDIO_ZEROPAGE(r5, 0xc020aa04, &(0x7f0000000000)={{&(0x7f0000ffd000/0x1000)=nil, 0x1000}})\n r7 = bpf$PROG_LOAD(0x5, &(0x7f0000000140)={0x2, 0x3, &(0x7f0000000200)=ANY=[@ANYBLOB=\"1800000000120000000000000000000095\"], &(0x7f0000000000)='GPL\\x00', 0x7, 0x0, 0x0, 0x0, 0x0, '\\x00', 0x0, @fallback=0x30, 0xffffffffffffffff, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x10, 0x0, @void, @value}, 0x94)\n bpf$BPF_LINK_CREATE_XDP(0x1c, &(0x7f0000000040)={r7, 0x0, 0x30, 0x1e, @val=@uprobe_multi={&(0x7f0000000080)='./file0\\x00', &(0x7f0000000100)=[0x2], 0x0, 0x0, 0x1}}, 0x40)\n\nThe cause is that zero pfn is set to the PTE without increasing the RSS\ncount in mfill_atomic_pte_zeropage() and the refcount of zero folio does\nnot increase accordingly. Then, the operation on the same pfn is performed\nin uprobe_write_opcode()->__replace_page() to unconditional decrease the\nRSS count and old_folio's refcount.\n\nTherefore, two bugs are introduced:\n\n 1. The RSS count is incorrect, when process exit, the check_mm() report\n error \"Bad rss-count\".\n\n 2. The reserved folio (zero folio) is freed when folio->refcount is zero,\n then free_pages_prepare->free_page_is_bad() report error\n \"Bad page state\".\n\nThere is more, the following warning could also theoretically be triggered:\n\n __replace_page()\n -> ...\n -> folio_remove_rmap_pte()\n -> VM_WARN_ON_FOLIO(is_zero_folio(folio), folio)\n\nConsidering that uprobe hit on the zero folio is a very rare case, just\nreject zero old folio immediately after get_user_page_vma_remote().\n\n[ mingo: Cleaned up the changelog ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21881" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b6f19714588cf2366b0364234f97ba963688f63" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13cca2b73e2b0ec3ea6d6615d615395621d22752" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54011fc94422f094eaf47555284de70a4bc32bb9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bddf10d26e6e5114e7415a0e442ec6f51a559468" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4cb2bfa99513311886c1eb5c1c2ac26f3338a6e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json b/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json new file mode 100644 index 00000000000..36d3f171ceb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7cw-67xp-5685", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29486" + ], + "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29486" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz3.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json b/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json new file mode 100644 index 00000000000..d268869a1f0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc99-rg67-mm68", + "modified": "2025-03-27T15:31:13Z", + "published": "2025-03-27T15:31:13Z", + "aliases": [ + "CVE-2025-29487" + ], + "details": "An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29487" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/goodmow/PoC/blob/main/libming/libming-fuzz6.readme" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vhgj-j89f-cpmf/GHSA-vhgj-j89f-cpmf.json b/advisories/unreviewed/2025/03/GHSA-vhgj-j89f-cpmf/GHSA-vhgj-j89f-cpmf.json index d81093cb7a1..f575dc977cb 100644 --- a/advisories/unreviewed/2025/03/GHSA-vhgj-j89f-cpmf/GHSA-vhgj-j89f-cpmf.json +++ b/advisories/unreviewed/2025/03/GHSA-vhgj-j89f-cpmf/GHSA-vhgj-j89f-cpmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhgj-j89f-cpmf", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-03-27T15:31:06Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-26010" ], "details": "Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vhqh-g62v-gqxx/GHSA-vhqh-g62v-gqxx.json b/advisories/unreviewed/2025/03/GHSA-vhqh-g62v-gqxx/GHSA-vhqh-g62v-gqxx.json new file mode 100644 index 00000000000..622ceee62a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhqh-g62v-gqxx/GHSA-vhqh-g62v-gqxx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhqh-g62v-gqxx", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21874" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: Avoid divide by zero in table status in Inline mode\n\nIn Inline mode, the journal is unused, and journal_sectors is zero.\n\nCalculating the journal watermark requires dividing by journal_sectors,\nwhich should be done only if the journal is configured.\n\nOtherwise, a simple table query (dmsetup table) can cause OOPS.\n\nThis bug did not show on some systems, perhaps only due to\ncompiler optimization.\n\nOn my 32-bit testing machine, this reliably crashes with the following:\n\n : Oops: divide error: 0000 [#1] PREEMPT SMP\n : CPU: 0 UID: 0 PID: 2450 Comm: dmsetup Not tainted 6.14.0-rc2+ #959\n : EIP: dm_integrity_status+0x2f8/0xab0 [dm_integrity]\n ...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21874" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06d9895f265282e939a8933bb18de82eba2b4dda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22c6f577b3cb184857b440ae5e5916f6c9e7021d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7fb39882b20c98a9a393c244c86b56ef6933cff8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vhv3-gpj3-fqm8/GHSA-vhv3-gpj3-fqm8.json b/advisories/unreviewed/2025/03/GHSA-vhv3-gpj3-fqm8/GHSA-vhv3-gpj3-fqm8.json new file mode 100644 index 00000000000..012e73cf516 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhv3-gpj3-fqm8/GHSA-vhv3-gpj3-fqm8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhv3-gpj3-fqm8", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-2846" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2846" + }, + { + "type": "WEB", + "url": "https://github.com/jeajeaa/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522326" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json b/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json new file mode 100644 index 00000000000..5d173e9337b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjwm-w9rc-f4cc", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21887" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up\n\nThe issue was caused by dput(upper) being called before\novl_dentry_update_reval(), while upper->d_flags was still\naccessed in ovl_dentry_remote().\n\nMove dput(upper) after its last use to prevent use-after-free.\n\nBUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]\nBUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167\n\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n ovl_dentry_remote fs/overlayfs/util.c:162 [inline]\n ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167\n ovl_link_up fs/overlayfs/copy_up.c:610 [inline]\n ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170\n ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223\n ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136\n vfs_rename+0xf84/0x20a0 fs/namei.c:4893\n...\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21887" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3594aad97e7be2557ca9fa9c931b206b604028c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b49d939b5a79117f939b77cc67efae2694d9799" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60b4b5c1277fc491da9e1e7abab307bfa39c2db7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64455c8051c3aedc71abb7ec8d47c80301f99f00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7c41830ffcd17b2177a95a9b99b270302090c35" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c84e125fff2615b4d9c259e762596134eddd2f27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vqff-54hc-2xch/GHSA-vqff-54hc-2xch.json b/advisories/unreviewed/2025/03/GHSA-vqff-54hc-2xch/GHSA-vqff-54hc-2xch.json index f30af9dd600..cad25ce4571 100644 --- a/advisories/unreviewed/2025/03/GHSA-vqff-54hc-2xch/GHSA-vqff-54hc-2xch.json +++ b/advisories/unreviewed/2025/03/GHSA-vqff-54hc-2xch/GHSA-vqff-54hc-2xch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vqff-54hc-2xch", - "modified": "2025-03-26T21:31:06Z", + "modified": "2025-03-27T15:31:04Z", "published": "2025-03-26T21:31:06Z", "aliases": [ "CVE-2025-25535" ], "details": "HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w6h4-wh4q-cwfj/GHSA-w6h4-wh4q-cwfj.json b/advisories/unreviewed/2025/03/GHSA-w6h4-wh4q-cwfj/GHSA-w6h4-wh4q-cwfj.json new file mode 100644 index 00000000000..bc8d38e47d4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6h4-wh4q-cwfj/GHSA-w6h4-wh4q-cwfj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6h4-wh4q-cwfj", + "modified": "2025-03-27T15:31:08Z", + "published": "2025-03-27T15:31:08Z", + "aliases": [ + "CVE-2025-2847" + ], + "details": "A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522330" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/baimatangseng-iyusa/qwwm81/zbefafzyl0of6g56?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wvfh-rj9m-fpc6/GHSA-wvfh-rj9m-fpc6.json b/advisories/unreviewed/2025/03/GHSA-wvfh-rj9m-fpc6/GHSA-wvfh-rj9m-fpc6.json new file mode 100644 index 00000000000..ab06898f5c4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wvfh-rj9m-fpc6/GHSA-wvfh-rj9m-fpc6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvfh-rj9m-fpc6", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2025-1998" + ], + "details": "IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 \n\nstores potentially sensitive authentication token information in log files that could be read by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1998" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wxjg-w4jc-v7mf/GHSA-wxjg-w4jc-v7mf.json b/advisories/unreviewed/2025/03/GHSA-wxjg-w4jc-v7mf/GHSA-wxjg-w4jc-v7mf.json new file mode 100644 index 00000000000..801273dfcc3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wxjg-w4jc-v7mf/GHSA-wxjg-w4jc-v7mf.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxjg-w4jc-v7mf", + "modified": "2025-03-27T15:31:10Z", + "published": "2025-03-27T15:31:10Z", + "aliases": [ + "CVE-2024-58090" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/core: Prevent rescheduling when interrupts are disabled\n\nDavid reported a warning observed while loop testing kexec jump:\n\n Interrupts enabled after irqrouter_resume+0x0/0x50\n WARNING: CPU: 0 PID: 560 at drivers/base/syscore.c:103 syscore_resume+0x18a/0x220\n kernel_kexec+0xf6/0x180\n __do_sys_reboot+0x206/0x250\n do_syscall_64+0x95/0x180\n\nThe corresponding interrupt flag trace:\n\n hardirqs last enabled at (15573): [] __up_console_sem+0x7e/0x90\n hardirqs last disabled at (15580): [] __up_console_sem+0x63/0x90\n\nThat means __up_console_sem() was invoked with interrupts enabled. Further\ninstrumentation revealed that in the interrupt disabled section of kexec\njump one of the syscore_suspend() callbacks woke up a task, which set the\nNEED_RESCHED flag. A later callback in the resume path invoked\ncond_resched() which in turn led to the invocation of the scheduler:\n\n __cond_resched+0x21/0x60\n down_timeout+0x18/0x60\n acpi_os_wait_semaphore+0x4c/0x80\n acpi_ut_acquire_mutex+0x3d/0x100\n acpi_ns_get_node+0x27/0x60\n acpi_ns_evaluate+0x1cb/0x2d0\n acpi_rs_set_srs_method_data+0x156/0x190\n acpi_pci_link_set+0x11c/0x290\n irqrouter_resume+0x54/0x60\n syscore_resume+0x6a/0x200\n kernel_kexec+0x145/0x1c0\n __do_sys_reboot+0xeb/0x240\n do_syscall_64+0x95/0x180\n\nThis is a long standing problem, which probably got more visible with\nthe recent printk changes. Something does a task wakeup and the\nscheduler sets the NEED_RESCHED flag. cond_resched() sees it set and\ninvokes schedule() from a completely bogus context. The scheduler\nenables interrupts after context switching, which causes the above\nwarning at the end.\n\nQuite some of the code paths in syscore_suspend()/resume() can result in\ntriggering a wakeup with the exactly same consequences. They might not\nhave done so yet, but as they share a lot of code with normal operations\nit's just a question of time.\n\nThe problem only affects the PREEMPT_NONE and PREEMPT_VOLUNTARY scheduling\nmodels. Full preemption is not affected as cond_resched() is disabled and\nthe preemption check preemptible() takes the interrupt disabled flag into\naccount.\n\nCure the problem by adding a corresponding check into cond_resched().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58090" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0362847c520747b44b574d363705d8af0621727a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1651f5731b378616565534eb9cda30e258cebebc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/288fdb8dcb71ec77b76ab8b8a06bc10f595ea504" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/321794b75ac968f0bb6b9c913581949452a8d992" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68786ab0935ccd5721283b7eb7f4d2f2942c7a52" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82c387ef7568c0d96a918a5a78d9cad6256cfa15" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84586322e010164eedddfcd0a0894206ae7d9317" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b927c8539f692fb1f9c2f42e6c8ea2d94956f921" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x237-489c-52j2/GHSA-x237-489c-52j2.json b/advisories/unreviewed/2025/03/GHSA-x237-489c-52j2/GHSA-x237-489c-52j2.json index 69029bfca64..4bb7af40c48 100644 --- a/advisories/unreviewed/2025/03/GHSA-x237-489c-52j2/GHSA-x237-489c-52j2.json +++ b/advisories/unreviewed/2025/03/GHSA-x237-489c-52j2/GHSA-x237-489c-52j2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-x4h3-99vh-7946/GHSA-x4h3-99vh-7946.json b/advisories/unreviewed/2025/03/GHSA-x4h3-99vh-7946/GHSA-x4h3-99vh-7946.json new file mode 100644 index 00000000000..455bd7a059c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x4h3-99vh-7946/GHSA-x4h3-99vh-7946.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4h3-99vh-7946", + "modified": "2025-03-27T15:31:12Z", + "published": "2025-03-27T15:31:12Z", + "aliases": [ + "CVE-2025-21892" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix the recovery flow of the UMR QP\n\nThis patch addresses an issue in the recovery flow of the UMR QP,\nensuring tasks do not get stuck, as highlighted by the call trace [1].\n\nDuring recovery, before transitioning the QP to the RESET state, the\nsoftware must wait for all outstanding WRs to complete.\n\nFailing to do so can cause the firmware to skip sending some flushed\nCQEs with errors and simply discard them upon the RESET, as per the IB\nspecification.\n\nThis race condition can result in lost CQEs and tasks becoming stuck.\n\nTo resolve this, the patch sends a final WR which serves only as a\nbarrier before moving the QP state to RESET.\n\nOnce a CQE is received for that final WR, it guarantees that no\noutstanding WRs remain, making it safe to transition the QP to RESET and\nsubsequently back to RTS, restoring proper functionality.\n\nNote:\nFor the barrier WR, we simply reuse the failed and ready WR.\nSince the QP is in an error state, it will only receive\nIB_WC_WR_FLUSH_ERR. However, as it serves only as a barrier we don't\ncare about its status.\n\n[1]\nINFO: task rdma_resource_l:1922 blocked for more than 120 seconds.\nTainted: G W 6.12.0-rc7+ #1626\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:rdma_resource_l state:D stack:0 pid:1922 tgid:1922 ppid:1369\n flags:0x00004004\nCall Trace:\n\n__schedule+0x420/0xd30\nschedule+0x47/0x130\nschedule_timeout+0x280/0x300\n? mark_held_locks+0x48/0x80\n? lockdep_hardirqs_on_prepare+0xe5/0x1a0\nwait_for_completion+0x75/0x130\nmlx5r_umr_post_send_wait+0x3c2/0x5b0 [mlx5_ib]\n? __pfx_mlx5r_umr_done+0x10/0x10 [mlx5_ib]\nmlx5r_umr_revoke_mr+0x93/0xc0 [mlx5_ib]\n__mlx5_ib_dereg_mr+0x299/0x520 [mlx5_ib]\n? _raw_spin_unlock_irq+0x24/0x40\n? wait_for_completion+0xfe/0x130\n? rdma_restrack_put+0x63/0xe0 [ib_core]\nib_dereg_mr_user+0x5f/0x120 [ib_core]\n? lock_release+0xc6/0x280\ndestroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs]\nuverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs]\nuobj_destroy+0x3f/0x70 [ib_uverbs]\nib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs]\n? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs]\n? __lock_acquire+0x64e/0x2080\n? mark_held_locks+0x48/0x80\n? find_held_lock+0x2d/0xa0\n? lock_acquire+0xc1/0x2f0\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n? __fget_files+0xc3/0x1b0\nib_uverbs_ioctl+0xe7/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n__x64_sys_ioctl+0x1b0/0xa70\ndo_syscall_64+0x6b/0x140\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f99c918b17b\nRSP: 002b:00007ffc766d0468 EFLAGS: 00000246 ORIG_RAX:\n 0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffc766d0578 RCX:\n 00007f99c918b17b\nRDX: 00007ffc766d0560 RSI: 00000000c0181b01 RDI:\n 0000000000000003\nRBP: 00007ffc766d0540 R08: 00007f99c8f99010 R09:\n 000000000000bd7e\nR10: 00007f99c94c1c70 R11: 0000000000000246 R12:\n 00007ffc766d0530\nR13: 000000000000001c R14: 0000000040246a80 R15:\n 0000000000000000\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21892" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d2b84d8d054313deed2b2fcafe1168bbcb9e99f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e3bf255992cc02404e9d209b127c1c9944239cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d97505baea64d93538b16baf14ce7b8c1fbad746" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x566-29g2-c4g8/GHSA-x566-29g2-c4g8.json b/advisories/unreviewed/2025/03/GHSA-x566-29g2-c4g8/GHSA-x566-29g2-c4g8.json new file mode 100644 index 00000000000..bbac250d4e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x566-29g2-c4g8/GHSA-x566-29g2-c4g8.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x566-29g2-c4g8", + "modified": "2025-03-27T15:31:11Z", + "published": "2025-03-27T15:31:11Z", + "aliases": [ + "CVE-2025-21877" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: gl620a: fix endpoint checking in genelink_bind()\n\nSyzbot reports [1] a warning in usb_submit_urb() triggered by\ninconsistencies between expected and actually present endpoints\nin gl620a driver. Since genelink_bind() does not properly\nverify whether specified eps are in fact provided by the device,\nin this case, an artificially manufactured one, one may get a\nmismatch.\n\nFix the issue by resorting to a usbnet utility function\nusbnet_get_endpoints(), usually reserved for this very problem.\nCheck for endpoints and return early before proceeding further if\nany are missing.\n\n[1] Syzbot report:\nusb 5-1: Manufacturer: syz\nusb 5-1: SerialNumber: syz\nusb 5-1: config 0 descriptor??\ngl620a 5-1:0.23 usb0: register 'gl620a' at usb-dummy_hcd.0-1, ...\n------------[ cut here ]------------\nusb 5-1: BOGUS urb xfer, pipe 3 != type 1\nWARNING: CPU: 2 PID: 1841 at drivers/usb/core/urb.c:503 usb_submit_urb+0xe4b/0x1730 drivers/usb/core/urb.c:503\nModules linked in:\nCPU: 2 UID: 0 PID: 1841 Comm: kworker/2:2 Not tainted 6.12.0-syzkaller-07834-g06afb0f36106 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nWorkqueue: mld mld_ifc_work\nRIP: 0010:usb_submit_urb+0xe4b/0x1730 drivers/usb/core/urb.c:503\n...\nCall Trace:\n \n usbnet_start_xmit+0x6be/0x2780 drivers/net/usb/usbnet.c:1467\n __netdev_start_xmit include/linux/netdevice.h:5002 [inline]\n netdev_start_xmit include/linux/netdevice.h:5011 [inline]\n xmit_one net/core/dev.c:3590 [inline]\n dev_hard_start_xmit+0x9a/0x7b0 net/core/dev.c:3606\n sch_direct_xmit+0x1ae/0xc30 net/sched/sch_generic.c:343\n __dev_xmit_skb net/core/dev.c:3827 [inline]\n __dev_queue_xmit+0x13d4/0x43e0 net/core/dev.c:4400\n dev_queue_xmit include/linux/netdevice.h:3168 [inline]\n neigh_resolve_output net/core/neighbour.c:1514 [inline]\n neigh_resolve_output+0x5bc/0x950 net/core/neighbour.c:1494\n neigh_output include/net/neighbour.h:539 [inline]\n ip6_finish_output2+0xb1b/0x2070 net/ipv6/ip6_output.c:141\n __ip6_finish_output net/ipv6/ip6_output.c:215 [inline]\n ip6_finish_output+0x3f9/0x1360 net/ipv6/ip6_output.c:226\n NF_HOOK_COND include/linux/netfilter.h:303 [inline]\n ip6_output+0x1f8/0x540 net/ipv6/ip6_output.c:247\n dst_output include/net/dst.h:450 [inline]\n NF_HOOK include/linux/netfilter.h:314 [inline]\n NF_HOOK include/linux/netfilter.h:308 [inline]\n mld_sendpack+0x9f0/0x11d0 net/ipv6/mcast.c:1819\n mld_send_cr net/ipv6/mcast.c:2120 [inline]\n mld_ifc_work+0x740/0xca0 net/ipv6/mcast.c:2651\n process_one_work+0x9c5/0x1ba0 kernel/workqueue.c:3229\n process_scheduled_works kernel/workqueue.c:3310 [inline]\n worker_thread+0x6c8/0xf00 kernel/workqueue.c:3391\n kthread+0x2c1/0x3a0 kernel/kthread.c:389\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21877" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1cf9631d836b289bd5490776551961c883ae8a4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24dd971104057c8828d420a48e0a5af6e6f30d3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e8b8d43373bf837be159366f0192502f97ec7a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f2dbabbce04b1ffcd6d8d07564adb94db577536" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67ebc3391c8377738e97a43374054d9718fdb6e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9bcb8cbc3e5d67eb223bfb7e2291a270dbb699dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2ee5e55b50a97d13617c8653482c0ad4decff8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ded25730c96949cb8b048b29c557e38569124943" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xqc2-xvq9-7x34/GHSA-xqc2-xvq9-7x34.json b/advisories/unreviewed/2025/03/GHSA-xqc2-xvq9-7x34/GHSA-xqc2-xvq9-7x34.json new file mode 100644 index 00000000000..44c66e8556a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xqc2-xvq9-7x34/GHSA-xqc2-xvq9-7x34.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqc2-xvq9-7x34", + "modified": "2025-03-27T15:31:14Z", + "published": "2025-03-27T15:31:14Z", + "aliases": [ + "CVE-2025-31178" + ], + "details": "A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31178" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-31178" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xxhc-h629-rhgx/GHSA-xxhc-h629-rhgx.json b/advisories/unreviewed/2025/03/GHSA-xxhc-h629-rhgx/GHSA-xxhc-h629-rhgx.json index 3c4a63df2de..f01751283f0 100644 --- a/advisories/unreviewed/2025/03/GHSA-xxhc-h629-rhgx/GHSA-xxhc-h629-rhgx.json +++ b/advisories/unreviewed/2025/03/GHSA-xxhc-h629-rhgx/GHSA-xxhc-h629-rhgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxhc-h629-rhgx", - "modified": "2025-03-26T18:30:50Z", + "modified": "2025-03-27T15:31:04Z", "published": "2025-03-26T18:30:50Z", "aliases": [ "CVE-2024-41643" ], "details": "An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T18:15:24Z"