Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-06 21:32:54 +00:00
parent b936b3e95a
commit 53708f237d
34 changed files with 842 additions and 24 deletions
@@ -37,7 +37,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-177"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vm8m-8vm4-x33v",
"modified": "2023-03-13T15:30:17Z",
"modified": "2025-03-06T21:31:19Z",
"published": "2023-03-06T21:30:18Z",
"aliases": [
"CVE-2023-0093"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fjhg-vc4c-336q",
"modified": "2024-04-04T05:06:51Z",
"modified": "2025-03-06T21:31:20Z",
"published": "2023-06-23T15:30:44Z",
"aliases": [
"CVE-2023-36274"
@@ -22,6 +22,14 @@
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/issues/677#BUG2"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/commit/8651fa27dd2de731e706e2ba09f0d28e4e0dce33"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/blob/0.11/src/out_dxf.c#L1792"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fx57-4pvv-5x6q",
"modified": "2024-04-04T05:06:46Z",
"modified": "2025-03-06T21:31:20Z",
"published": "2023-06-23T15:30:44Z",
"aliases": [
"CVE-2023-36271"
@@ -22,6 +22,14 @@
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/issues/681#BUG2"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/commit/c1ed1d91e28a6ddc7a9b5479d4795d58fb6be0ca"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/blob/0.10/src/bits.c#L1677C11-L1683C17"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7hc-4p56-pcfx",
"modified": "2024-04-04T05:06:47Z",
"modified": "2025-03-06T21:31:20Z",
"published": "2023-06-23T15:30:44Z",
"aliases": [
"CVE-2023-36272"
@@ -22,6 +22,14 @@
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/issues/681#BUG1"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/commit/c1ed1d91e28a6ddc7a9b5479d4795d58fb6be0ca"
},
{
"type": "WEB",
"url": "https://github.com/LibreDWG/libredwg/blob/0.10/src/bits.c#L1677C11-L1683C17"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp49-g67r-vh5q",
"modified": "2024-12-10T18:31:07Z",
"modified": "2025-03-06T21:31:22Z",
"published": "2024-12-10T18:31:07Z",
"aliases": [
"CVE-2024-53245"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pcx-8wcv-8m4v",
"modified": "2025-01-08T09:30:38Z",
"modified": "2025-03-06T21:31:23Z",
"published": "2025-01-08T09:30:38Z",
"aliases": [
"CVE-2024-12584"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-35"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g8h-33rh-hp24",
"modified": "2025-02-28T06:30:48Z",
"modified": "2025-03-06T21:31:25Z",
"published": "2025-02-28T06:30:48Z",
"aliases": [
"CVE-2024-13796"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44w2-c6gq-2xxx",
"modified": "2025-02-22T21:30:52Z",
"modified": "2025-03-06T21:31:25Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2024-38316"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46vg-h2w6-gh78",
"modified": "2025-02-28T15:31:04Z",
"modified": "2025-03-06T21:31:26Z",
"published": "2025-02-28T15:31:04Z",
"aliases": [
"CVE-2025-26326"
],
"details": "A vulnerability in the remote connection complements of the NVDA (Nonvisual Desktop Access) 2024.4.1 and 2024.4.2 was identified, which allows an attacker to obtain total control of the remote system when guessing a weak password. The problem occurs because the complements accept any password typed by the user and do not have an additional authentication or checking mechanism by the computer that will be accessed. Tests indicate that over 1,000 systems use easy to guess passwords, many with less than 4 to 6 characters, including common sequences. This enables brute strength or attempt and error attacks on the part of malicious invaders. Vulnerability can be explored by a remote striker who knows or can guess the password used in the connection. As a result, the invader gets complete access to the affected system and can run commands, modify files and compromise user security.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-287"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T15:15:13Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79wv-5cfm-5wm8",
"modified": "2025-02-28T18:31:04Z",
"modified": "2025-03-06T21:31:26Z",
"published": "2025-02-28T18:31:04Z",
"aliases": [
"CVE-2024-44754"
],
"details": "Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-522"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T16:15:37Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ffm-4mfx-v85f",
"modified": "2025-02-28T06:30:48Z",
"modified": "2025-03-06T21:31:25Z",
"published": "2025-02-28T06:30:48Z",
"aliases": [
"CVE-2025-1757"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gvrr-q7f9-rx5j",
"modified": "2025-02-06T06:31:26Z",
"modified": "2025-03-06T21:31:25Z",
"published": "2025-02-06T06:31:26Z",
"aliases": [
"CVE-2024-56473"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-116",
"CWE-117"
],
"severity": "MODERATE",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmcm-9g64-4qhv",
"modified": "2025-02-28T18:31:04Z",
"modified": "2025-03-06T21:31:26Z",
"published": "2025-02-28T18:31:04Z",
"aliases": [
"CVE-2025-26047"
],
"details": "Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T16:15:40Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jvp-r7m9-xhpr",
"modified": "2025-03-06T21:31:27Z",
"published": "2025-03-06T21:31:27Z",
"aliases": [
"CVE-2025-25497"
],
"details": "An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the \"Account Owner\" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25497"
},
{
"type": "WEB",
"url": "https://helpdesk.netsweeper.com/docs/8_2_Docs/8_2_Netsweeper_Docs/Content/Release_Notes/Netsweeper_Release_Notes/8_2_Release_Notes/8_2_7_Release_and_Downloads.htm"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/188626"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-06T20:15:38Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cgj-hhfq-rgx4",
"modified": "2025-03-06T21:31:26Z",
"published": "2025-03-06T21:31:26Z",
"aliases": [
"CVE-2024-50600"
],
"details": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access. An attacker can send a malformed message to the target through the Wi-Fi driver.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50600"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-06T19:15:26Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gpw-rmhm-r2vm",
"modified": "2025-03-06T21:31:25Z",
"published": "2025-03-06T21:31:25Z",
"aliases": [
"CVE-2025-25825"
],
"details": "A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25825"
},
{
"type": "WEB",
"url": "https://github.com/Ka7arotto/emlog/blob/main/xss-4.md"
},
{
"type": "WEB",
"url": "https://www.emlog.net"
},
{
"type": "WEB",
"url": "http://emlogpro.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T15:15:28Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2xx-646h-c4q2",
"modified": "2025-03-06T21:31:27Z",
"published": "2025-03-06T21:31:27Z",
"aliases": [
"CVE-2025-2036"
],
"details": "A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2036"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.298779"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.298779"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.512405"
},
{
"type": "WEB",
"url": "https://www.websecurityinsights.my.id/2025/03/e-commerce-10-detailsphpproid-sql.html?m=1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-06T19:15:28Z"
}
}

Some files were not shown because too many files have changed in this diff Show More