diff --git a/advisories/unreviewed/2022/05/GHSA-44fv-7jv8-5cpp/GHSA-44fv-7jv8-5cpp.json b/advisories/unreviewed/2022/05/GHSA-44fv-7jv8-5cpp/GHSA-44fv-7jv8-5cpp.json index bddb0e65824..83cad7fea5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-44fv-7jv8-5cpp/GHSA-44fv-7jv8-5cpp.json +++ b/advisories/unreviewed/2022/05/GHSA-44fv-7jv8-5cpp/GHSA-44fv-7jv8-5cpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44fv-7jv8-5cpp", - "modified": "2024-07-24T18:31:10Z", + "modified": "2025-05-29T15:31:02Z", "published": "2022-05-14T02:32:18Z", "aliases": [ "CVE-2014-1776" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://technet.microsoft.com/library/security/2963983" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2014-1776-use-after-free-vulnerability-in-microsoft-internet-explorer-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2014-1776-use-after-free-vulnerability-in-microsoft-internet-explorer-mitigation-scripts" + }, { "type": "WEB", "url": "http://blogs.technet.com/b/srd/archive/2014/04/30/protection-strategies-for-the-security-advisory-2963983-ie-0day.aspx" diff --git a/advisories/unreviewed/2022/09/GHSA-3fp9-5j6q-rjrv/GHSA-3fp9-5j6q-rjrv.json b/advisories/unreviewed/2022/09/GHSA-3fp9-5j6q-rjrv/GHSA-3fp9-5j6q-rjrv.json index 1cd1dff5b93..23d7b60ab3f 100644 --- a/advisories/unreviewed/2022/09/GHSA-3fp9-5j6q-rjrv/GHSA-3fp9-5j6q-rjrv.json +++ b/advisories/unreviewed/2022/09/GHSA-3fp9-5j6q-rjrv/GHSA-3fp9-5j6q-rjrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fp9-5j6q-rjrv", - "modified": "2022-09-22T00:00:24Z", + "modified": "2025-05-29T15:31:02Z", "published": "2022-09-21T00:00:44Z", "aliases": [ "CVE-2022-35196" diff --git a/advisories/unreviewed/2022/09/GHSA-56cx-5f5p-v4rv/GHSA-56cx-5f5p-v4rv.json b/advisories/unreviewed/2022/09/GHSA-56cx-5f5p-v4rv/GHSA-56cx-5f5p-v4rv.json index fcd26b21b8d..541e11d262d 100644 --- a/advisories/unreviewed/2022/09/GHSA-56cx-5f5p-v4rv/GHSA-56cx-5f5p-v4rv.json +++ b/advisories/unreviewed/2022/09/GHSA-56cx-5f5p-v4rv/GHSA-56cx-5f5p-v4rv.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5mp3-vqfj-w7mq/GHSA-5mp3-vqfj-w7mq.json b/advisories/unreviewed/2022/09/GHSA-5mp3-vqfj-w7mq/GHSA-5mp3-vqfj-w7mq.json index 99906675160..54821d8d70a 100644 --- a/advisories/unreviewed/2022/09/GHSA-5mp3-vqfj-w7mq/GHSA-5mp3-vqfj-w7mq.json +++ b/advisories/unreviewed/2022/09/GHSA-5mp3-vqfj-w7mq/GHSA-5mp3-vqfj-w7mq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-377" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-63qp-xj7q-6fq4/GHSA-63qp-xj7q-6fq4.json b/advisories/unreviewed/2022/09/GHSA-63qp-xj7q-6fq4/GHSA-63qp-xj7q-6fq4.json index 3826ac3a569..346383b2c07 100644 --- a/advisories/unreviewed/2022/09/GHSA-63qp-xj7q-6fq4/GHSA-63qp-xj7q-6fq4.json +++ b/advisories/unreviewed/2022/09/GHSA-63qp-xj7q-6fq4/GHSA-63qp-xj7q-6fq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63qp-xj7q-6fq4", - "modified": "2022-09-23T00:00:34Z", + "modified": "2025-05-29T15:31:03Z", "published": "2022-09-21T00:00:33Z", "aliases": [ "CVE-2022-32911" @@ -47,13 +47,23 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT213488" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Oct/28" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Oct/39" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Oct/41" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-6h2q-3hc7-cvj3/GHSA-6h2q-3hc7-cvj3.json b/advisories/unreviewed/2022/09/GHSA-6h2q-3hc7-cvj3/GHSA-6h2q-3hc7-cvj3.json index abaed076409..6c169560b05 100644 --- a/advisories/unreviewed/2022/09/GHSA-6h2q-3hc7-cvj3/GHSA-6h2q-3hc7-cvj3.json +++ b/advisories/unreviewed/2022/09/GHSA-6h2q-3hc7-cvj3/GHSA-6h2q-3hc7-cvj3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-8356-ccjq-rwhv/GHSA-8356-ccjq-rwhv.json b/advisories/unreviewed/2022/09/GHSA-8356-ccjq-rwhv/GHSA-8356-ccjq-rwhv.json index d1cd845aec8..077e2ce3cbc 100644 --- a/advisories/unreviewed/2022/09/GHSA-8356-ccjq-rwhv/GHSA-8356-ccjq-rwhv.json +++ b/advisories/unreviewed/2022/09/GHSA-8356-ccjq-rwhv/GHSA-8356-ccjq-rwhv.json @@ -74,6 +74,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-8hvh-7pr8-r6wh/GHSA-8hvh-7pr8-r6wh.json b/advisories/unreviewed/2022/09/GHSA-8hvh-7pr8-r6wh/GHSA-8hvh-7pr8-r6wh.json index 86e270c6c3b..d2661dc800e 100644 --- a/advisories/unreviewed/2022/09/GHSA-8hvh-7pr8-r6wh/GHSA-8hvh-7pr8-r6wh.json +++ b/advisories/unreviewed/2022/09/GHSA-8hvh-7pr8-r6wh/GHSA-8hvh-7pr8-r6wh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-8qrg-f3r4-2pv6/GHSA-8qrg-f3r4-2pv6.json b/advisories/unreviewed/2022/09/GHSA-8qrg-f3r4-2pv6/GHSA-8qrg-f3r4-2pv6.json index 3788261ba0d..55cf8145ad4 100644 --- a/advisories/unreviewed/2022/09/GHSA-8qrg-f3r4-2pv6/GHSA-8qrg-f3r4-2pv6.json +++ b/advisories/unreviewed/2022/09/GHSA-8qrg-f3r4-2pv6/GHSA-8qrg-f3r4-2pv6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-f888-gr94-8gvj/GHSA-f888-gr94-8gvj.json b/advisories/unreviewed/2022/09/GHSA-f888-gr94-8gvj/GHSA-f888-gr94-8gvj.json index 06d40cf9de7..92c36ef2d10 100644 --- a/advisories/unreviewed/2022/09/GHSA-f888-gr94-8gvj/GHSA-f888-gr94-8gvj.json +++ b/advisories/unreviewed/2022/09/GHSA-f888-gr94-8gvj/GHSA-f888-gr94-8gvj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-hjx6-46xp-4mxh/GHSA-hjx6-46xp-4mxh.json b/advisories/unreviewed/2022/09/GHSA-hjx6-46xp-4mxh/GHSA-hjx6-46xp-4mxh.json index 9d4e0e9d91f..0d59389f844 100644 --- a/advisories/unreviewed/2022/09/GHSA-hjx6-46xp-4mxh/GHSA-hjx6-46xp-4mxh.json +++ b/advisories/unreviewed/2022/09/GHSA-hjx6-46xp-4mxh/GHSA-hjx6-46xp-4mxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjx6-46xp-4mxh", - "modified": "2022-09-23T00:00:34Z", + "modified": "2025-05-29T15:31:03Z", "published": "2022-09-21T00:00:33Z", "aliases": [ "CVE-2022-32908" @@ -51,6 +51,10 @@ "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Oct/28" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Oct/39" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Oct/41" diff --git a/advisories/unreviewed/2022/09/GHSA-hvhp-3r57-wcr8/GHSA-hvhp-3r57-wcr8.json b/advisories/unreviewed/2022/09/GHSA-hvhp-3r57-wcr8/GHSA-hvhp-3r57-wcr8.json index 5079dac957e..e8b1e3c0aec 100644 --- a/advisories/unreviewed/2022/09/GHSA-hvhp-3r57-wcr8/GHSA-hvhp-3r57-wcr8.json +++ b/advisories/unreviewed/2022/09/GHSA-hvhp-3r57-wcr8/GHSA-hvhp-3r57-wcr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hvhp-3r57-wcr8", - "modified": "2022-09-23T00:00:41Z", + "modified": "2025-05-29T15:31:02Z", "published": "2022-09-21T00:00:32Z", "aliases": [ "CVE-2022-38340" diff --git a/advisories/unreviewed/2022/09/GHSA-m649-qfq3-hfqm/GHSA-m649-qfq3-hfqm.json b/advisories/unreviewed/2022/09/GHSA-m649-qfq3-hfqm/GHSA-m649-qfq3-hfqm.json index 0c7a56a6a9e..864fc9bca70 100644 --- a/advisories/unreviewed/2022/09/GHSA-m649-qfq3-hfqm/GHSA-m649-qfq3-hfqm.json +++ b/advisories/unreviewed/2022/09/GHSA-m649-qfq3-hfqm/GHSA-m649-qfq3-hfqm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json b/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json index 7173e4dc0bc..54ba47bc9d0 100644 --- a/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json +++ b/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rm7v-mc66-6r49", - "modified": "2022-09-23T00:00:35Z", + "modified": "2025-05-29T15:31:03Z", "published": "2022-09-21T00:00:33Z", "aliases": [ "CVE-2022-32886" diff --git a/advisories/unreviewed/2022/09/GHSA-wrp8-cmmv-vq5c/GHSA-wrp8-cmmv-vq5c.json b/advisories/unreviewed/2022/09/GHSA-wrp8-cmmv-vq5c/GHSA-wrp8-cmmv-vq5c.json index 5bc6413e5f9..a28fd920502 100644 --- a/advisories/unreviewed/2022/09/GHSA-wrp8-cmmv-vq5c/GHSA-wrp8-cmmv-vq5c.json +++ b/advisories/unreviewed/2022/09/GHSA-wrp8-cmmv-vq5c/GHSA-wrp8-cmmv-vq5c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-79g5-39qj-ggvg/GHSA-79g5-39qj-ggvg.json b/advisories/unreviewed/2023/12/GHSA-79g5-39qj-ggvg/GHSA-79g5-39qj-ggvg.json index 58fb47c63d5..157d1248d3d 100644 --- a/advisories/unreviewed/2023/12/GHSA-79g5-39qj-ggvg/GHSA-79g5-39qj-ggvg.json +++ b/advisories/unreviewed/2023/12/GHSA-79g5-39qj-ggvg/GHSA-79g5-39qj-ggvg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json b/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json index efd9ccd1b10..5afc8181141 100644 --- a/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json +++ b/advisories/unreviewed/2023/12/GHSA-jqgq-x29j-jv5r/GHSA-jqgq-x29j-jv5r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-2xh7-8hvj-mrr7/GHSA-2xh7-8hvj-mrr7.json b/advisories/unreviewed/2024/01/GHSA-2xh7-8hvj-mrr7/GHSA-2xh7-8hvj-mrr7.json index 4551141414f..4a06f38a273 100644 --- a/advisories/unreviewed/2024/01/GHSA-2xh7-8hvj-mrr7/GHSA-2xh7-8hvj-mrr7.json +++ b/advisories/unreviewed/2024/01/GHSA-2xh7-8hvj-mrr7/GHSA-2xh7-8hvj-mrr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xh7-8hvj-mrr7", - "modified": "2024-02-03T00:31:33Z", + "modified": "2025-05-29T15:31:03Z", "published": "2024-01-30T03:30:30Z", "aliases": [ "CVE-2024-22938" diff --git a/advisories/unreviewed/2024/01/GHSA-7cm4-cx64-v496/GHSA-7cm4-cx64-v496.json b/advisories/unreviewed/2024/01/GHSA-7cm4-cx64-v496/GHSA-7cm4-cx64-v496.json index fc49e4e8098..dff8d39d4d9 100644 --- a/advisories/unreviewed/2024/01/GHSA-7cm4-cx64-v496/GHSA-7cm4-cx64-v496.json +++ b/advisories/unreviewed/2024/01/GHSA-7cm4-cx64-v496/GHSA-7cm4-cx64-v496.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cm4-cx64-v496", - "modified": "2024-02-03T03:30:27Z", + "modified": "2025-05-29T15:31:03Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-6165" diff --git a/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json b/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json index 6014afe93d7..c4d77fcbd36 100644 --- a/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json +++ b/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhq6-2w37-vh8q", - "modified": "2024-02-05T21:30:31Z", + "modified": "2025-05-29T15:31:04Z", "published": "2024-01-31T00:30:18Z", "aliases": [ "CVE-2024-1060" diff --git a/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json index 2efebf3031e..c001b30dcee 100644 --- a/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json +++ b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j3rg-72x7-gm5r", - "modified": "2024-01-30T18:30:20Z", + "modified": "2025-05-29T15:31:04Z", "published": "2024-01-30T18:30:20Z", "aliases": [ "CVE-2023-37518" ], - "details": "HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.\n", + "details": "HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json b/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json index 29f3e188a93..0c711bb34b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json +++ b/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mp4-h7q5-2rgq", - "modified": "2024-02-15T06:31:35Z", + "modified": "2025-05-29T15:31:05Z", "published": "2024-02-13T18:38:24Z", "aliases": [ "CVE-2024-21413" @@ -26,6 +26,14 @@ { "type": "WEB", "url": "https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-21413-critical-monikerlink-vulnerability-affecting-microsoft-outlook-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-21413-critical-monikerlink-vulnerability-affecting-microsoft-outlook-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-5p67-c598-q5xx/GHSA-5p67-c598-q5xx.json b/advisories/unreviewed/2024/05/GHSA-5p67-c598-q5xx/GHSA-5p67-c598-q5xx.json index 05118aea5f5..497a10c23c7 100644 --- a/advisories/unreviewed/2024/05/GHSA-5p67-c598-q5xx/GHSA-5p67-c598-q5xx.json +++ b/advisories/unreviewed/2024/05/GHSA-5p67-c598-q5xx/GHSA-5p67-c598-q5xx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p67-c598-q5xx", - "modified": "2024-05-02T18:30:52Z", + "modified": "2025-05-29T15:31:05Z", "published": "2024-05-02T18:30:52Z", "aliases": [ "CVE-2024-1396" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c2gr-3cmq-v4w3/GHSA-c2gr-3cmq-v4w3.json b/advisories/unreviewed/2024/05/GHSA-c2gr-3cmq-v4w3/GHSA-c2gr-3cmq-v4w3.json index 5e0b4eef915..ff31c7d100f 100644 --- a/advisories/unreviewed/2024/05/GHSA-c2gr-3cmq-v4w3/GHSA-c2gr-3cmq-v4w3.json +++ b/advisories/unreviewed/2024/05/GHSA-c2gr-3cmq-v4w3/GHSA-c2gr-3cmq-v4w3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c8m8-rxhp-2qqc/GHSA-c8m8-rxhp-2qqc.json b/advisories/unreviewed/2024/05/GHSA-c8m8-rxhp-2qqc/GHSA-c8m8-rxhp-2qqc.json index 056ee7741e5..c1eec052435 100644 --- a/advisories/unreviewed/2024/05/GHSA-c8m8-rxhp-2qqc/GHSA-c8m8-rxhp-2qqc.json +++ b/advisories/unreviewed/2024/05/GHSA-c8m8-rxhp-2qqc/GHSA-c8m8-rxhp-2qqc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q33m-xm72-7q7v/GHSA-q33m-xm72-7q7v.json b/advisories/unreviewed/2024/05/GHSA-q33m-xm72-7q7v/GHSA-q33m-xm72-7q7v.json index 96fe53f866b..d88e96c5e63 100644 --- a/advisories/unreviewed/2024/05/GHSA-q33m-xm72-7q7v/GHSA-q33m-xm72-7q7v.json +++ b/advisories/unreviewed/2024/05/GHSA-q33m-xm72-7q7v/GHSA-q33m-xm72-7q7v.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w82v-44gq-6487/GHSA-w82v-44gq-6487.json b/advisories/unreviewed/2024/05/GHSA-w82v-44gq-6487/GHSA-w82v-44gq-6487.json index cdab8aa7c03..15b58e5ff0b 100644 --- a/advisories/unreviewed/2024/05/GHSA-w82v-44gq-6487/GHSA-w82v-44gq-6487.json +++ b/advisories/unreviewed/2024/05/GHSA-w82v-44gq-6487/GHSA-w82v-44gq-6487.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json b/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json index 2fbb8acb74d..75e751cd41b 100644 --- a/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json +++ b/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4f3-8wwc-j9x2", - "modified": "2025-01-14T18:32:02Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-01-14T18:32:02Z", "aliases": [ "CVE-2025-21224" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21224" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21224-remote-code-execution-vulnerability-in-windows-line-printer-daemon-service-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21224-remote-code-execution-vulnerability-in-windows-line-printer-daemon-service-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-6v67-599p-fprc/GHSA-6v67-599p-fprc.json b/advisories/unreviewed/2025/03/GHSA-6v67-599p-fprc/GHSA-6v67-599p-fprc.json index c3afc63d870..dc8a03d9e99 100644 --- a/advisories/unreviewed/2025/03/GHSA-6v67-599p-fprc/GHSA-6v67-599p-fprc.json +++ b/advisories/unreviewed/2025/03/GHSA-6v67-599p-fprc/GHSA-6v67-599p-fprc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v67-599p-fprc", - "modified": "2025-04-27T09:30:34Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-03-11T18:32:17Z", "aliases": [ "CVE-2025-24054" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24054" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-mitigation-script" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2025/Apr/28" diff --git a/advisories/unreviewed/2025/03/GHSA-vf6f-gpmv-93m4/GHSA-vf6f-gpmv-93m4.json b/advisories/unreviewed/2025/03/GHSA-vf6f-gpmv-93m4/GHSA-vf6f-gpmv-93m4.json index 50a3d6b324b..4f768d4ad95 100644 --- a/advisories/unreviewed/2025/03/GHSA-vf6f-gpmv-93m4/GHSA-vf6f-gpmv-93m4.json +++ b/advisories/unreviewed/2025/03/GHSA-vf6f-gpmv-93m4/GHSA-vf6f-gpmv-93m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vf6f-gpmv-93m4", - "modified": "2025-03-11T18:32:18Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-03-11T18:32:18Z", "aliases": [ "CVE-2025-24985" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24985" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-driver-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-driver-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json b/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json index 1ad9f013454..47ab96e0122 100644 --- a/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json +++ b/advisories/unreviewed/2025/04/GHSA-429q-ccqc-32wq/GHSA-429q-ccqc-32wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-429q-ccqc-32wq", - "modified": "2025-04-08T18:34:44Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-04-08T18:34:44Z", "aliases": [ "CVE-2025-21204" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21204-privilege-elevation-vulnerability-in-microsoft-windows-update-stack-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21204-privilege-elevation-vulnerability-in-microsoft-windows-update-stack-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-9g47-36rw-gjh2/GHSA-9g47-36rw-gjh2.json b/advisories/unreviewed/2025/04/GHSA-9g47-36rw-gjh2/GHSA-9g47-36rw-gjh2.json index 1af4c8c9388..d9175a9f4ae 100644 --- a/advisories/unreviewed/2025/04/GHSA-9g47-36rw-gjh2/GHSA-9g47-36rw-gjh2.json +++ b/advisories/unreviewed/2025/04/GHSA-9g47-36rw-gjh2/GHSA-9g47-36rw-gjh2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9g47-36rw-gjh2", - "modified": "2025-04-19T21:30:28Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-04-19T21:30:27Z", "aliases": [ "CVE-2025-3818" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3818" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00041.html" + }, { "type": "WEB", "url": "https://noppgwz8if.feishu.cn/docx/TxjpddUpTokyBwxibSgcTRr7nUf" diff --git a/advisories/unreviewed/2025/05/GHSA-245w-hx5r-x6jq/GHSA-245w-hx5r-x6jq.json b/advisories/unreviewed/2025/05/GHSA-245w-hx5r-x6jq/GHSA-245w-hx5r-x6jq.json new file mode 100644 index 00000000000..50dc798ab6e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-245w-hx5r-x6jq/GHSA-245w-hx5r-x6jq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-245w-hx5r-x6jq", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2024-22654" + ], + "details": "tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22654" + }, + { + "type": "WEB", + "url": "https://github.com/appneta/tcpreplay/issues/827" + }, + { + "type": "WEB", + "url": "https://gist.github.com/TimChan2001/4f25915b9952e8e3453db5cf72185b88" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2m9m-fgg6-qcx9/GHSA-2m9m-fgg6-qcx9.json b/advisories/unreviewed/2025/05/GHSA-2m9m-fgg6-qcx9/GHSA-2m9m-fgg6-qcx9.json new file mode 100644 index 00000000000..0e04eb812b8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2m9m-fgg6-qcx9/GHSA-2m9m-fgg6-qcx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m9m-fgg6-qcx9", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-46078" + ], + "details": "HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46078" + }, + { + "type": "WEB", + "url": "https://github.com/yggcwhat/CVE-2025-46078" + }, + { + "type": "WEB", + "url": "https://github.com/yggcwhat/test/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json index d7427f8ad41..90a28a33a54 100644 --- a/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json +++ b/advisories/unreviewed/2025/05/GHSA-2mx4-jrqf-62cp/GHSA-2mx4-jrqf-62cp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2mx4-jrqf-62cp", - "modified": "2025-05-23T18:32:12Z", + "modified": "2025-05-29T15:31:07Z", "published": "2025-05-23T18:32:12Z", "aliases": [ "CVE-2024-51099" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-23T16:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5pqc-8wc5-jxj6/GHSA-5pqc-8wc5-jxj6.json b/advisories/unreviewed/2025/05/GHSA-5pqc-8wc5-jxj6/GHSA-5pqc-8wc5-jxj6.json new file mode 100644 index 00000000000..762e849e29d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5pqc-8wc5-jxj6/GHSA-5pqc-8wc5-jxj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pqc-8wc5-jxj6", + "modified": "2025-05-29T15:31:08Z", + "published": "2025-05-29T15:31:08Z", + "aliases": [ + "CVE-2025-48045" + ], + "details": "An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48045" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2025/05/29/cve-2025-48045-cve-2025-48046-cve-2025-48047-mici-netfax-server-product-vulnerabilities-not-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json b/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json index c1682cecd6f..ac9b8ee6987 100644 --- a/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json +++ b/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-288" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7qr6-vjfq-429r/GHSA-7qr6-vjfq-429r.json b/advisories/unreviewed/2025/05/GHSA-7qr6-vjfq-429r/GHSA-7qr6-vjfq-429r.json new file mode 100644 index 00000000000..f1ffe7f32ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7qr6-vjfq-429r/GHSA-7qr6-vjfq-429r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qr6-vjfq-429r", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37999" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/erofs/fileio: call erofs_onlinefolio_split() after bio_add_folio()\n\nIf bio_add_folio() fails (because it is full),\nerofs_fileio_scan_folio() needs to submit the I/O request via\nerofs_fileio_rq_submit() and allocate a new I/O request with an empty\n`struct bio`. Then it retries the bio_add_folio() call.\n\nHowever, at this point, erofs_onlinefolio_split() has already been\ncalled which increments `folio->private`; the retry will call\nerofs_onlinefolio_split() again, but there will never be a matching\nerofs_onlinefolio_end() call. This leaves the folio locked forever\nand all waiters will be stuck in folio_wait_bit_common().\n\nThis bug has been added by commit ce63cb62d794 (\"erofs: support\nunencoded inodes for fileio\"), but was practically unreachable because\nthere was room for 256 folios in the `struct bio` - until commit\n9f74ae8c9ac9 (\"erofs: shorten bvecs[] for file-backed mounts\") which\nreduced the array capacity to 16 folios.\n\nIt was now trivial to trigger the bug by manually invoking readahead\nfrom userspace, e.g.:\n\n posix_fadvise(fd, 0, st.st_size, POSIX_FADV_WILLNEED);\n\nThis should be fixed by invoking erofs_onlinefolio_split() only after\nbio_add_folio() has succeeded. This is safe: asynchronous completions\ninvoking erofs_onlinefolio_end() will not unlock the folio because\nerofs_fileio_scan_folio() is still holding a reference to be released\nby erofs_onlinefolio_end() at the end.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61e0fc3312309867e5a3495329dad0286d2a5703" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbfe756dc3062c1e934f06e5ba39c239aa953b92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c26076197df348c84cc23e5962d61902e072a0f5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8jh2-3h65-3cwh/GHSA-8jh2-3h65-3cwh.json b/advisories/unreviewed/2025/05/GHSA-8jh2-3h65-3cwh/GHSA-8jh2-3h65-3cwh.json new file mode 100644 index 00000000000..b8e59cff152 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8jh2-3h65-3cwh/GHSA-8jh2-3h65-3cwh.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jh2-3h65-3cwh", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37998" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: Fix unsafe attribute parsing in output_userspace()\n\nThis patch replaces the manual Netlink attribute iteration in\noutput_userspace() with nla_for_each_nested(), which ensures that only\nwell-formed attributes are processed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37998" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0236742bd959332181c1fcc41a05b7b709180501" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47f7f00cf2fa3137d5c0416ef1a71bdf77901395" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4fa672cbce9c86c3efb8621df1ae580d47813430" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6beb6835c1fbb3f676aebb51a5fee6b77fed9308" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bca8df998cce1fead8cbc69144862eadc2e34c87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec334aaab74705cc515205e1da3cb369fdfd93cd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8q5q-7mvv-w97x/GHSA-8q5q-7mvv-w97x.json b/advisories/unreviewed/2025/05/GHSA-8q5q-7mvv-w97x/GHSA-8q5q-7mvv-w97x.json new file mode 100644 index 00000000000..bb588955ca8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8q5q-7mvv-w97x/GHSA-8q5q-7mvv-w97x.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q5q-7mvv-w97x", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37995" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmodule: ensure that kobject_put() is safe for module type kobjects\n\nIn 'lookup_or_create_module_kobject()', an internal kobject is created\nusing 'module_ktype'. So call to 'kobject_put()' on error handling\npath causes an attempt to use an uninitialized completion pointer in\n'module_kobject_release()'. In this scenario, we just want to release\nkobject without an extra synchronization required for a regular module\nunloading process, so adding an extra check whether 'complete()' is\nactually required makes 'kobject_put()' safe.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37995" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31d8df3f303c3ae9115230820977ef8c35c88808" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e7b49ce4f9d0cb5b6e87db9e07a2fb9e754b0dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6aeb739974ec73e5217c75a7c008a688d3d5cf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d63851049f412cdfadaeef7a7eaef5031d11c1e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1c71b4bd721a4ea21da408806964b10468623f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/faa9059631d3491d699c69ecf512de9e1a3d6649" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cc89-xr3w-vpvf/GHSA-cc89-xr3w-vpvf.json b/advisories/unreviewed/2025/05/GHSA-cc89-xr3w-vpvf/GHSA-cc89-xr3w-vpvf.json new file mode 100644 index 00000000000..d9adc1deaee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cc89-xr3w-vpvf/GHSA-cc89-xr3w-vpvf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc89-xr3w-vpvf", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37993" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe\n\nThe spin lock tx_handling_spinlock in struct m_can_classdev is not\nbeing initialized. This leads the following spinlock bad magic\ncomplaint from the kernel, eg. when trying to send CAN frames with\ncansend from can-utils:\n\n| BUG: spinlock bad magic on CPU#0, cansend/95\n| lock: 0xff60000002ec1010, .magic: 00000000, .owner: /-1, .owner_cpu: 0\n| CPU: 0 UID: 0 PID: 95 Comm: cansend Not tainted 6.15.0-rc3-00032-ga79be02bba5c #5 NONE\n| Hardware name: MachineWare SIM-V (DT)\n| Call Trace:\n| [] dump_backtrace+0x1c/0x24\n| [] show_stack+0x28/0x34\n| [] dump_stack_lvl+0x4a/0x68\n| [] dump_stack+0x14/0x1c\n| [] spin_dump+0x62/0x6e\n| [] do_raw_spin_lock+0xd0/0x142\n| [] _raw_spin_lock_irqsave+0x20/0x2c\n| [] m_can_start_xmit+0x90/0x34a\n| [] dev_hard_start_xmit+0xa6/0xee\n| [] sch_direct_xmit+0x114/0x292\n| [] __dev_queue_xmit+0x3b0/0xaa8\n| [] can_send+0xc6/0x242\n| [] raw_sendmsg+0x1a8/0x36c\n| [] sock_write_iter+0x9a/0xee\n| [] vfs_write+0x184/0x3a6\n| [] ksys_write+0xa0/0xc0\n| [] __riscv_sys_write+0x14/0x1c\n| [] do_trap_ecall_u+0x168/0x212\n| [] handle_exception+0x146/0x152\n\nInitializing the spin lock in m_can_class_allocate_dev solves that\nproblem.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37993" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ecce25ea296f328d79070ee36229a15aeeb7aca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d5379cfecfdd665e4206bc4f19824656388779f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcaeeb8ae84c5506ebc574732838264f3887738c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json index d75c81566be..14a2d212177 100644 --- a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json +++ b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch64-4x3c-w3jq", - "modified": "2025-05-28T03:30:33Z", + "modified": "2025-05-29T15:31:07Z", "published": "2025-05-27T21:32:17Z", "aliases": [ "CVE-2025-5278" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/27/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/29/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json b/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json new file mode 100644 index 00000000000..2246ba4be02 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fhv3-95jg-vjrh/GHSA-fhv3-95jg-vjrh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhv3-95jg-vjrh", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-48748" + ], + "details": "Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48748" + }, + { + "type": "WEB", + "url": "https://community.netwrix.com/t/adv-2025-013-hard-coded-password-in-netwrix-directory-manager-formerly-imanami-groupid-v10-and-earlier/13945" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g265-w27f-7cfm/GHSA-g265-w27f-7cfm.json b/advisories/unreviewed/2025/05/GHSA-g265-w27f-7cfm/GHSA-g265-w27f-7cfm.json new file mode 100644 index 00000000000..3b8be650a9c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g265-w27f-7cfm/GHSA-g265-w27f-7cfm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g265-w27f-7cfm", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-4081" + ], + "details": "Use of entitlement \"com.apple.security.cs.disable-library-validation\" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency, Consent, and Control (TCC). Acquired resource access is limited to previously granted permissions by the user. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission.\n\nThis issue affects DaVinci Resolve on macOS in all versions.\nLast tested version: 19.1.3", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4081" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/tcc-bypass" + }, + { + "type": "WEB", + "url": "https://www.blackmagicdesign.com/products/davinciresolve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp5h-f9c5-8355/GHSA-gp5h-f9c5-8355.json b/advisories/unreviewed/2025/05/GHSA-gp5h-f9c5-8355/GHSA-gp5h-f9c5-8355.json new file mode 100644 index 00000000000..a7b8501b122 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gp5h-f9c5-8355/GHSA-gp5h-f9c5-8355.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp5h-f9c5-8355", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-5321" + ], + "details": "A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of the argument Query leads to sandbox issue. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5321" + }, + { + "type": "WEB", + "url": "https://gist.github.com/superboy-zjc/1fc4747a0ac77a1edc8c32e1d4edc54c" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580253" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hfcm-596p-c7f7/GHSA-hfcm-596p-c7f7.json b/advisories/unreviewed/2025/05/GHSA-hfcm-596p-c7f7/GHSA-hfcm-596p-c7f7.json new file mode 100644 index 00000000000..536ff4abcbf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hfcm-596p-c7f7/GHSA-hfcm-596p-c7f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfcm-596p-c7f7", + "modified": "2025-05-29T15:31:08Z", + "published": "2025-05-29T15:31:08Z", + "aliases": [ + "CVE-2025-48046" + ], + "details": "An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48046" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2025/05/29/cve-2025-48045-cve-2025-48046-cve-2025-48047-mici-netfax-server-product-vulnerabilities-not-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-260" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hq4x-qvjp-878v/GHSA-hq4x-qvjp-878v.json b/advisories/unreviewed/2025/05/GHSA-hq4x-qvjp-878v/GHSA-hq4x-qvjp-878v.json new file mode 100644 index 00000000000..7d39f290976 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hq4x-qvjp-878v/GHSA-hq4x-qvjp-878v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq4x-qvjp-878v", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-46080" + ], + "details": "HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46080" + }, + { + "type": "WEB", + "url": "https://github.com/yggcwhat/CVE-2025-46080" + }, + { + "type": "WEB", + "url": "https://github.com/yggcwhat/test2/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgxp-fpw7-p364/GHSA-jgxp-fpw7-p364.json b/advisories/unreviewed/2025/05/GHSA-jgxp-fpw7-p364/GHSA-jgxp-fpw7-p364.json new file mode 100644 index 00000000000..17c5942d27e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgxp-fpw7-p364/GHSA-jgxp-fpw7-p364.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgxp-fpw7-p364", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37997" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix region locking in hash types\n\nRegion locking introduced in v5.6-rc4 contained three macros to handle\nthe region locks: ahash_bucket_start(), ahash_bucket_end() which gave\nback the start and end hash bucket values belonging to a given region\nlock and ahash_region() which should give back the region lock belonging\nto a given hash bucket. The latter was incorrect which can lead to a\nrace condition between the garbage collector and adding new elements\nwhen a hash type of set is defined with timeouts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37997" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e002ecc1c8cfdfc866b9104ab7888da54613e59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82c1eb32693bc48251d92532975e19160987e5b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8478a729c0462273188263136880480729e9efca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3dfec485401943e315c394c29afe2db8f9481d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa77294b0f73bb8265987591460cd25b8722c3df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2ab67672b2288521a6146034a971f9a82ffc5c5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p49g-r9vw-4fm8/GHSA-p49g-r9vw-4fm8.json b/advisories/unreviewed/2025/05/GHSA-p49g-r9vw-4fm8/GHSA-p49g-r9vw-4fm8.json new file mode 100644 index 00000000000..efc5c887e4c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p49g-r9vw-4fm8/GHSA-p49g-r9vw-4fm8.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p49g-r9vw-4fm8", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37994" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: displayport: Fix NULL pointer access\n\nThis patch ensures that the UCSI driver waits for all pending tasks in the\nucsi_displayport_work workqueue to finish executing before proceeding with\nthe partner removal.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37994" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/076ab0631ed4928905736f1701e25f1e722bc086" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14f298c52188c34acde9760bf5abc669c5c36fdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/312d79669e71283d05c05cc49a1a31e59e3d9e0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ad298d6d4aebe1229adba6427e417e89a5208d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7804c4d63edfdd5105926cc291e806e8f4ce01b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9b63faf5c97deb43fc39a52edbc39d626cc14bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q358-6958-pqcv/GHSA-q358-6958-pqcv.json b/advisories/unreviewed/2025/05/GHSA-q358-6958-pqcv/GHSA-q358-6958-pqcv.json new file mode 100644 index 00000000000..ad65b2d29f0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q358-6958-pqcv/GHSA-q358-6958-pqcv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q358-6958-pqcv", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-33043" + ], + "details": "APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33043" + }, + { + "type": "WEB", + "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025005.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgwh-9j3v-m669/GHSA-qgwh-9j3v-m669.json b/advisories/unreviewed/2025/05/GHSA-qgwh-9j3v-m669/GHSA-qgwh-9j3v-m669.json new file mode 100644 index 00000000000..7bff23506d1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgwh-9j3v-m669/GHSA-qgwh-9j3v-m669.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgwh-9j3v-m669", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2024-22653" + ], + "details": "yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22653" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/247" + }, + { + "type": "WEB", + "url": "https://gist.github.com/TimChan2001/03e5792b15d0a34bfaad970e37c17660" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json b/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json index 4a8afb864ce..7d4930b8230 100644 --- a/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json +++ b/advisories/unreviewed/2025/05/GHSA-r7hj-5f27-q8xw/GHSA-r7hj-5f27-q8xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7hj-5f27-q8xw", - "modified": "2025-05-13T18:30:57Z", + "modified": "2025-05-29T15:31:06Z", "published": "2025-05-13T18:30:57Z", "aliases": [ "CVE-2025-30397" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30397" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-v8pp-m355-r6cw/GHSA-v8pp-m355-r6cw.json b/advisories/unreviewed/2025/05/GHSA-v8pp-m355-r6cw/GHSA-v8pp-m355-r6cw.json new file mode 100644 index 00000000000..5791884d7f8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8pp-m355-r6cw/GHSA-v8pp-m355-r6cw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8pp-m355-r6cw", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-37996" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix uninitialized memcache pointer in user_mem_abort()\n\nCommit fce886a60207 (\"KVM: arm64: Plumb the pKVM MMU in KVM\") made the\ninitialization of the local memcache variable in user_mem_abort()\nconditional, leaving a codepath where it is used uninitialized via\nkvm_pgtable_stage2_map().\n\nThis can fail on any path that requires a stage-2 allocation\nwithout transition via a permission fault or dirty logging.\n\nFix this by making sure that memcache is always valid.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37996" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/157dbc4a321f5bb6f8b6c724d12ba720a90f1a7c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a26d50f8a4a5049e956984797b5d0dedea4bbb18" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wg3r-h2gv-34fv/GHSA-wg3r-h2gv-34fv.json b/advisories/unreviewed/2025/05/GHSA-wg3r-h2gv-34fv/GHSA-wg3r-h2gv-34fv.json new file mode 100644 index 00000000000..13b7a4f918e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wg3r-h2gv-34fv/GHSA-wg3r-h2gv-34fv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg3r-h2gv-34fv", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-5334" + ], + "details": "Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager\nallows an authenticated user to gain unauthorized access to private personal information. \n\n\n\nUnder specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.\n\n\n\n\nThis issue affects the following versions :\n\n * Remote Desktop Manager Windows 2025.1.34.0 and earlier", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5334" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200", + "CWE-359" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmjh-cpqj-4v6x/GHSA-wmjh-cpqj-4v6x.json b/advisories/unreviewed/2025/05/GHSA-wmjh-cpqj-4v6x/GHSA-wmjh-cpqj-4v6x.json new file mode 100644 index 00000000000..0f1ed039b01 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmjh-cpqj-4v6x/GHSA-wmjh-cpqj-4v6x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmjh-cpqj-4v6x", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-5320" + ], + "details": "A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to origin validation error. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5320" + }, + { + "type": "WEB", + "url": "https://gist.github.com/superboy-zjc/aa3dfa161d7b19d8a53ab4605792f2fe" + }, + { + "type": "WEB", + "url": "https://gist.github.com/superboy-zjc/aa3dfa161d7b19d8a53ab4605792f2fe#proof-of-concept-poc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.580250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xhw7-r59x-5m6x/GHSA-xhw7-r59x-5m6x.json b/advisories/unreviewed/2025/05/GHSA-xhw7-r59x-5m6x/GHSA-xhw7-r59x-5m6x.json new file mode 100644 index 00000000000..bc909b10b89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xhw7-r59x-5m6x/GHSA-xhw7-r59x-5m6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhw7-r59x-5m6x", + "modified": "2025-05-29T15:31:09Z", + "published": "2025-05-29T15:31:09Z", + "aliases": [ + "CVE-2025-48047" + ], + "details": "An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48047" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2025/05/29/cve-2025-48045-cve-2025-48046-cve-2025-48047-mici-netfax-server-product-vulnerabilities-not-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T13:15:25Z" + } +} \ No newline at end of file