From 5a53f6f40c434b565e394d4d2a76f58bb8e40ebe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Jan 2025 18:32:09 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-vjvx-2q28-pjv2.json | 9 ++++- .../GHSA-fjww-grc5-6wh6.json | 4 +- .../GHSA-j827-v44f-fw4p.json | 1 + .../GHSA-qf97-3r3x-x56v.json | 6 ++- .../GHSA-xh7f-2c8g-37p4.json | 3 +- .../GHSA-j5r7-6rm3-99mm.json | 1 + .../GHSA-q392-qg7v-xvc4.json | 5 ++- .../GHSA-vxc9-8m8h-9cp6.json | 6 ++- .../GHSA-2697-3jf6-rpjg.json | 13 ++++-- .../GHSA-4f6h-9vp6-5p6r.json | 3 +- .../GHSA-58ff-49fr-3jwf.json | 2 +- .../GHSA-676h-wcx2-4w5q.json | 4 +- .../GHSA-76v6-7m6g-p6v4.json | 9 ++++- .../GHSA-7c5f-gfr7-vw4v.json | 13 ++++-- .../GHSA-9pf5-f78q-q36r.json | 3 +- .../GHSA-9w75-994h-2j26.json | 1 + .../GHSA-c857-frv5-v87x.json | 13 ++++-- .../GHSA-cpfm-2p8w-wrxc.json | 3 +- .../GHSA-f3wv-rx3x-v6fh.json | 9 ++++- .../GHSA-fg7h-q67h-82rg.json | 9 ++++- .../GHSA-h4mr-p94x-gf79.json | 2 +- .../GHSA-m4g6-h6xh-8xr8.json | 9 ++++- .../GHSA-p8m9-gxw7-g5pf.json | 13 ++++-- .../GHSA-pcwp-p8jm-7xc7.json | 9 ++++- .../GHSA-px27-325w-m34c.json | 9 ++++- .../GHSA-q4f3-pjpv-9q5x.json | 3 +- .../GHSA-qhhm-rhwq-mpvm.json | 12 ++++-- .../GHSA-r647-89qj-xwmp.json | 13 ++++-- .../GHSA-rg6m-2r9v-c5fj.json | 9 ++++- .../GHSA-rqpw-v3g2-qccx.json | 1 + .../GHSA-rv43-fj24-7hpc.json | 13 ++++-- .../GHSA-w46j-w72r-9x98.json | 9 ++++- .../GHSA-x3vf-fcq8-6cpg.json | 2 + .../GHSA-x45r-8w3c-gwgc.json | 12 ++++-- .../GHSA-9g5r-3vrr-xfcm.json | 1 + .../GHSA-qjpw-c5xf-g33j.json | 10 ++++- .../GHSA-vcm2-j8f4-m7fj.json | 3 +- .../GHSA-g9w6-c3gx-pmr3.json | 5 ++- .../GHSA-53wx-2f9c-xxxr.json | 2 +- .../GHSA-3j54-7gqc-xjwp.json | 3 +- .../GHSA-3r49-g977-5jhx.json | 4 +- .../GHSA-5h8h-fq9x-xjw5.json | 4 +- .../GHSA-5q43-fxm7-9fhw.json | 1 + .../GHSA-8pwc-q3g2-whvm.json | 4 +- .../GHSA-c39g-g6jh-qhq6.json | 3 +- .../GHSA-f8mp-7x2x-6r8p.json | 4 +- .../GHSA-p73q-78q5-cwpp.json | 3 +- .../GHSA-p8v4-cwrw-r86g.json | 3 +- .../GHSA-q6xq-fwhh-m47h.json | 4 +- .../GHSA-r9r7-cx8h-pf3v.json | 4 +- .../GHSA-8qxv-m5ch-w93h.json | 6 ++- .../GHSA-9229-97hp-fx4j.json | 2 +- .../GHSA-98m5-rjgx-wv8j.json | 2 +- .../GHSA-vm8j-5gj2-mf44.json | 2 +- .../GHSA-g4p6-wj2c-46f6.json | 6 ++- .../GHSA-hw3g-x69p-f6rq.json | 6 ++- .../GHSA-wfc2-g4f8-v6c3.json | 6 ++- .../GHSA-qvmh-c8p3-rp3h.json | 15 +++++-- .../GHSA-3vc6-vvp3-rw5p.json | 6 ++- .../GHSA-3xp5-3hvv-rw8c.json | 4 +- .../GHSA-483w-q33g-j5qq.json | 4 +- .../GHSA-4947-94mr-v96v.json | 4 +- .../GHSA-m3vh-wcgv-mqx6.json | 6 ++- .../GHSA-prm3-v4r8-g2mv.json | 4 +- .../GHSA-pwvr-q337-w45r.json | 4 +- .../GHSA-r52v-m5f6-5gjm.json | 6 ++- .../GHSA-44xh-w98h-vq6q.json | 2 +- .../GHSA-4r3v-6hh6-vhf4.json | 2 +- .../GHSA-8vv9-x4pw-wwf3.json | 1 + .../GHSA-cmmr-cc39-65m3.json | 2 +- .../GHSA-7cv4-mxxr-4vxg.json | 6 ++- .../GHSA-h5x9-4j34-4q7p.json | 6 ++- .../GHSA-m785-2mqm-9r6g.json | 6 ++- .../GHSA-q9cq-m6qx-6497.json | 6 ++- .../GHSA-vrv4-mmpj-7phv.json | 6 ++- .../GHSA-wq4q-895p-v538.json | 6 ++- .../GHSA-cm54-mprw-5279.json | 3 +- .../GHSA-67wj-vrrp-x2fv.json | 6 ++- .../GHSA-6ghv-cm9w-9m65.json | 6 ++- .../GHSA-6rh6-g778-wcww.json | 6 ++- .../GHSA-9w23-rv5f-3ch2.json | 6 ++- .../GHSA-f5q3-r2wq-xch4.json | 6 ++- .../GHSA-fgg7-f8f3-3g3h.json | 6 ++- .../GHSA-g79x-gv43-8472.json | 6 ++- .../GHSA-gq79-6cpg-v72r.json | 6 ++- .../GHSA-hmwf-p83m-gr4q.json | 6 ++- .../GHSA-jgvv-pcgx-gv2f.json | 6 ++- .../GHSA-mmp3-h84f-cq76.json | 6 ++- .../GHSA-p92v-v2pv-248f.json | 6 ++- .../GHSA-pjwc-96x8-qh73.json | 6 ++- .../GHSA-qgwv-xwcw-8vxj.json | 6 ++- .../GHSA-3fr9-m4cp-5gr8.json | 15 +++++-- .../GHSA-4cfr-xp32-h9c9.json | 36 +++++++++++++++++ .../GHSA-9229-mw36-xgrg.json | 15 +++++-- .../GHSA-99gg-h722-7qw4.json | 15 +++++-- .../GHSA-9r3r-662w-7j3w.json | 40 +++++++++++++++++++ .../GHSA-h6q9-c4w9-v66r.json | 15 +++++-- .../GHSA-hhw5-j8rq-43wg.json | 36 +++++++++++++++++ .../GHSA-m3pc-rgm4-56jw.json | 15 +++++-- .../GHSA-qq5h-rjj9-q9qg.json | 15 +++++-- .../GHSA-rrmh-m2fw-63jp.json | 36 +++++++++++++++++ .../GHSA-vf25-w4jq-mhx2.json | 36 +++++++++++++++++ .../GHSA-xh6m-fr4r-mqj3.json | 15 +++++-- 103 files changed, 647 insertions(+), 146 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-4cfr-xp32-h9c9/GHSA-4cfr-xp32-h9c9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9r3r-662w-7j3w/GHSA-9r3r-662w-7j3w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hhw5-j8rq-43wg/GHSA-hhw5-j8rq-43wg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rrmh-m2fw-63jp/GHSA-rrmh-m2fw-63jp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vf25-w4jq-mhx2/GHSA-vf25-w4jq-mhx2.json diff --git a/advisories/unreviewed/2022/02/GHSA-vjvx-2q28-pjv2/GHSA-vjvx-2q28-pjv2.json b/advisories/unreviewed/2022/02/GHSA-vjvx-2q28-pjv2/GHSA-vjvx-2q28-pjv2.json index 247c4e4c62f..511ecb4356e 100644 --- a/advisories/unreviewed/2022/02/GHSA-vjvx-2q28-pjv2/GHSA-vjvx-2q28-pjv2.json +++ b/advisories/unreviewed/2022/02/GHSA-vjvx-2q28-pjv2/GHSA-vjvx-2q28-pjv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vjvx-2q28-pjv2", - "modified": "2022-02-16T00:02:00Z", + "modified": "2025-01-29T18:31:02Z", "published": "2022-02-13T00:00:25Z", "aliases": [ "CVE-2021-4102" ], "details": "Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json b/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json index 01702d5d9a8..911f73e8f71 100644 --- a/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json +++ b/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-j827-v44f-fw4p/GHSA-j827-v44f-fw4p.json b/advisories/unreviewed/2022/03/GHSA-j827-v44f-fw4p/GHSA-j827-v44f-fw4p.json index 6df6a28544c..841ce4d66b9 100644 --- a/advisories/unreviewed/2022/03/GHSA-j827-v44f-fw4p/GHSA-j827-v44f-fw4p.json +++ b/advisories/unreviewed/2022/03/GHSA-j827-v44f-fw4p/GHSA-j827-v44f-fw4p.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-434" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json b/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json index ab1c30b3d1d..b17ae447d67 100644 --- a/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json +++ b/advisories/unreviewed/2022/03/GHSA-qf97-3r3x-x56v/GHSA-qf97-3r3x-x56v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf97-3r3x-x56v", - "modified": "2022-04-05T00:00:58Z", + "modified": "2025-01-29T18:31:03Z", "published": "2022-03-29T00:01:17Z", "aliases": [ "CVE-2022-26258" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json b/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json index b4516b08bd9..afc7f891219 100644 --- a/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json +++ b/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh7f-2c8g-37p4", - "modified": "2022-03-19T00:01:29Z", + "modified": "2025-01-29T18:31:03Z", "published": "2022-03-11T00:02:03Z", "aliases": [ "CVE-2022-26143" @@ -50,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/04/GHSA-j5r7-6rm3-99mm/GHSA-j5r7-6rm3-99mm.json b/advisories/unreviewed/2022/04/GHSA-j5r7-6rm3-99mm/GHSA-j5r7-6rm3-99mm.json index 15ab9ab19ea..a5e30d336d7 100644 --- a/advisories/unreviewed/2022/04/GHSA-j5r7-6rm3-99mm/GHSA-j5r7-6rm3-99mm.json +++ b/advisories/unreviewed/2022/04/GHSA-j5r7-6rm3-99mm/GHSA-j5r7-6rm3-99mm.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-434" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-q392-qg7v-xvc4/GHSA-q392-qg7v-xvc4.json b/advisories/unreviewed/2022/04/GHSA-q392-qg7v-xvc4/GHSA-q392-qg7v-xvc4.json index 139771fb098..7e168c9ea80 100644 --- a/advisories/unreviewed/2022/04/GHSA-q392-qg7v-xvc4/GHSA-q392-qg7v-xvc4.json +++ b/advisories/unreviewed/2022/04/GHSA-q392-qg7v-xvc4/GHSA-q392-qg7v-xvc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q392-qg7v-xvc4", - "modified": "2022-04-27T00:00:28Z", + "modified": "2025-01-29T18:31:04Z", "published": "2022-04-19T00:00:57Z", "aliases": [ "CVE-2022-28810" @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-78" + "CWE-78", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-vxc9-8m8h-9cp6/GHSA-vxc9-8m8h-9cp6.json b/advisories/unreviewed/2022/04/GHSA-vxc9-8m8h-9cp6/GHSA-vxc9-8m8h-9cp6.json index a8d82c0352b..defb03873e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxc9-8m8h-9cp6/GHSA-vxc9-8m8h-9cp6.json +++ b/advisories/unreviewed/2022/04/GHSA-vxc9-8m8h-9cp6/GHSA-vxc9-8m8h-9cp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxc9-8m8h-9cp6", - "modified": "2022-05-07T00:01:15Z", + "modified": "2025-01-29T18:31:05Z", "published": "2022-04-27T00:00:21Z", "aliases": [ "CVE-2022-24706" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/w24wo0h8nlctfps65txvk0oc5hdcnv00" }, + { + "type": "WEB", + "url": "https://medium.com/%40_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd" + }, { "type": "WEB", "url": "https://medium.com/@_sadshade/couchdb-erlang-and-cookies-rce-on-default-settings-b1e9173a4bcd" diff --git a/advisories/unreviewed/2022/05/GHSA-2697-3jf6-rpjg/GHSA-2697-3jf6-rpjg.json b/advisories/unreviewed/2022/05/GHSA-2697-3jf6-rpjg/GHSA-2697-3jf6-rpjg.json index 5823b57dc87..7e6f92e34cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2697-3jf6-rpjg/GHSA-2697-3jf6-rpjg.json +++ b/advisories/unreviewed/2022/05/GHSA-2697-3jf6-rpjg/GHSA-2697-3jf6-rpjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2697-3jf6-rpjg", - "modified": "2024-12-19T21:31:07Z", + "modified": "2025-01-29T18:30:52Z", "published": "2022-05-17T04:07:23Z", "aliases": [ "CVE-2015-1130" ], "details": "The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-59" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f6h-9vp6-5p6r/GHSA-4f6h-9vp6-5p6r.json b/advisories/unreviewed/2022/05/GHSA-4f6h-9vp6-5p6r/GHSA-4f6h-9vp6-5p6r.json index f0aeb94dc21..096b28cb097 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f6h-9vp6-5p6r/GHSA-4f6h-9vp6-5p6r.json +++ b/advisories/unreviewed/2022/05/GHSA-4f6h-9vp6-5p6r/GHSA-4f6h-9vp6-5p6r.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-494" + "CWE-494", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-58ff-49fr-3jwf/GHSA-58ff-49fr-3jwf.json b/advisories/unreviewed/2022/05/GHSA-58ff-49fr-3jwf/GHSA-58ff-49fr-3jwf.json index 45d753b50e2..5fe67ff5025 100644 --- a/advisories/unreviewed/2022/05/GHSA-58ff-49fr-3jwf/GHSA-58ff-49fr-3jwf.json +++ b/advisories/unreviewed/2022/05/GHSA-58ff-49fr-3jwf/GHSA-58ff-49fr-3jwf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58ff-49fr-3jwf", - "modified": "2022-06-16T00:00:30Z", + "modified": "2025-01-29T18:30:57Z", "published": "2022-05-24T17:31:50Z", "aliases": [ "CVE-2020-3992" diff --git a/advisories/unreviewed/2022/05/GHSA-676h-wcx2-4w5q/GHSA-676h-wcx2-4w5q.json b/advisories/unreviewed/2022/05/GHSA-676h-wcx2-4w5q/GHSA-676h-wcx2-4w5q.json index 63680316f24..d23819346da 100644 --- a/advisories/unreviewed/2022/05/GHSA-676h-wcx2-4w5q/GHSA-676h-wcx2-4w5q.json +++ b/advisories/unreviewed/2022/05/GHSA-676h-wcx2-4w5q/GHSA-676h-wcx2-4w5q.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76v6-7m6g-p6v4/GHSA-76v6-7m6g-p6v4.json b/advisories/unreviewed/2022/05/GHSA-76v6-7m6g-p6v4/GHSA-76v6-7m6g-p6v4.json index 0daf7307157..f8267c00ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-76v6-7m6g-p6v4/GHSA-76v6-7m6g-p6v4.json +++ b/advisories/unreviewed/2022/05/GHSA-76v6-7m6g-p6v4/GHSA-76v6-7m6g-p6v4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76v6-7m6g-p6v4", - "modified": "2022-05-24T17:35:43Z", + "modified": "2025-01-29T18:30:57Z", "published": "2022-05-24T17:35:43Z", "aliases": [ "CVE-2020-27950" ], "details": "A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-7c5f-gfr7-vw4v/GHSA-7c5f-gfr7-vw4v.json b/advisories/unreviewed/2022/05/GHSA-7c5f-gfr7-vw4v/GHSA-7c5f-gfr7-vw4v.json index b766ac57f54..132d7a60b4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c5f-gfr7-vw4v/GHSA-7c5f-gfr7-vw4v.json +++ b/advisories/unreviewed/2022/05/GHSA-7c5f-gfr7-vw4v/GHSA-7c5f-gfr7-vw4v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7c5f-gfr7-vw4v", - "modified": "2022-05-24T17:04:07Z", + "modified": "2025-01-29T18:30:53Z", "published": "2022-05-24T17:04:07Z", "aliases": [ "CVE-2019-7286" ], "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pf5-f78q-q36r/GHSA-9pf5-f78q-q36r.json b/advisories/unreviewed/2022/05/GHSA-9pf5-f78q-q36r/GHSA-9pf5-f78q-q36r.json index fe3047a2e99..9cbb4236358 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pf5-f78q-q36r/GHSA-9pf5-f78q-q36r.json +++ b/advisories/unreviewed/2022/05/GHSA-9pf5-f78q-q36r/GHSA-9pf5-f78q-q36r.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json b/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json index a381ed81dce..464ba9bf7d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json +++ b/advisories/unreviewed/2022/05/GHSA-9w75-994h-2j26/GHSA-9w75-994h-2j26.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-434" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-c857-frv5-v87x/GHSA-c857-frv5-v87x.json b/advisories/unreviewed/2022/05/GHSA-c857-frv5-v87x/GHSA-c857-frv5-v87x.json index abea7bb7c9f..a58781be22e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c857-frv5-v87x/GHSA-c857-frv5-v87x.json +++ b/advisories/unreviewed/2022/05/GHSA-c857-frv5-v87x/GHSA-c857-frv5-v87x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c857-frv5-v87x", - "modified": "2022-05-24T17:04:07Z", + "modified": "2025-01-29T18:30:54Z", "published": "2022-05-24T17:04:07Z", "aliases": [ "CVE-2019-7287" ], "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpfm-2p8w-wrxc/GHSA-cpfm-2p8w-wrxc.json b/advisories/unreviewed/2022/05/GHSA-cpfm-2p8w-wrxc/GHSA-cpfm-2p8w-wrxc.json index e936514efc7..e469c6b07a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpfm-2p8w-wrxc/GHSA-cpfm-2p8w-wrxc.json +++ b/advisories/unreviewed/2022/05/GHSA-cpfm-2p8w-wrxc/GHSA-cpfm-2p8w-wrxc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-f3wv-rx3x-v6fh/GHSA-f3wv-rx3x-v6fh.json b/advisories/unreviewed/2022/05/GHSA-f3wv-rx3x-v6fh/GHSA-f3wv-rx3x-v6fh.json index f0ca890da16..af0caa59bf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3wv-rx3x-v6fh/GHSA-f3wv-rx3x-v6fh.json +++ b/advisories/unreviewed/2022/05/GHSA-f3wv-rx3x-v6fh/GHSA-f3wv-rx3x-v6fh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f3wv-rx3x-v6fh", - "modified": "2022-05-24T17:35:44Z", + "modified": "2025-01-29T18:30:57Z", "published": "2022-05-24T17:35:44Z", "aliases": [ "CVE-2020-27932" ], "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-fg7h-q67h-82rg/GHSA-fg7h-q67h-82rg.json b/advisories/unreviewed/2022/05/GHSA-fg7h-q67h-82rg/GHSA-fg7h-q67h-82rg.json index a308df1c529..0c67dfbe957 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg7h-q67h-82rg/GHSA-fg7h-q67h-82rg.json +++ b/advisories/unreviewed/2022/05/GHSA-fg7h-q67h-82rg/GHSA-fg7h-q67h-82rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg7h-q67h-82rg", - "modified": "2022-05-24T17:04:09Z", + "modified": "2025-01-29T18:30:54Z", "published": "2022-05-24T17:04:09Z", "aliases": [ "CVE-2019-8506" ], "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-h4mr-p94x-gf79/GHSA-h4mr-p94x-gf79.json b/advisories/unreviewed/2022/05/GHSA-h4mr-p94x-gf79/GHSA-h4mr-p94x-gf79.json index c4adf100031..a274e046015 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4mr-p94x-gf79/GHSA-h4mr-p94x-gf79.json +++ b/advisories/unreviewed/2022/05/GHSA-h4mr-p94x-gf79/GHSA-h4mr-p94x-gf79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4mr-p94x-gf79", - "modified": "2022-05-18T00:00:35Z", + "modified": "2025-01-29T18:31:05Z", "published": "2022-05-10T00:00:21Z", "aliases": [ "CVE-2022-30333" diff --git a/advisories/unreviewed/2022/05/GHSA-m4g6-h6xh-8xr8/GHSA-m4g6-h6xh-8xr8.json b/advisories/unreviewed/2022/05/GHSA-m4g6-h6xh-8xr8/GHSA-m4g6-h6xh-8xr8.json index c0a9eaccf08..d0a6dba39ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4g6-h6xh-8xr8/GHSA-m4g6-h6xh-8xr8.json +++ b/advisories/unreviewed/2022/05/GHSA-m4g6-h6xh-8xr8/GHSA-m4g6-h6xh-8xr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4g6-h6xh-8xr8", - "modified": "2022-05-24T19:09:47Z", + "modified": "2025-01-29T18:30:59Z", "published": "2022-05-24T19:09:47Z", "aliases": [ "CVE-2021-30563" ], "details": "Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-p8m9-gxw7-g5pf/GHSA-p8m9-gxw7-g5pf.json b/advisories/unreviewed/2022/05/GHSA-p8m9-gxw7-g5pf/GHSA-p8m9-gxw7-g5pf.json index 30d3eb88519..afa4dbe2d4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8m9-gxw7-g5pf/GHSA-p8m9-gxw7-g5pf.json +++ b/advisories/unreviewed/2022/05/GHSA-p8m9-gxw7-g5pf/GHSA-p8m9-gxw7-g5pf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p8m9-gxw7-g5pf", - "modified": "2022-05-24T17:04:10Z", + "modified": "2025-01-29T18:30:54Z", "published": "2022-05-24T17:04:10Z", "aliases": [ "CVE-2019-8526" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pcwp-p8jm-7xc7/GHSA-pcwp-p8jm-7xc7.json b/advisories/unreviewed/2022/05/GHSA-pcwp-p8jm-7xc7/GHSA-pcwp-p8jm-7xc7.json index dad24fb6c06..3f166591e00 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcwp-p8jm-7xc7/GHSA-pcwp-p8jm-7xc7.json +++ b/advisories/unreviewed/2022/05/GHSA-pcwp-p8jm-7xc7/GHSA-pcwp-p8jm-7xc7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcwp-p8jm-7xc7", - "modified": "2022-05-24T17:35:42Z", + "modified": "2025-01-29T18:30:58Z", "published": "2022-05-24T17:35:42Z", "aliases": [ "CVE-2020-27930" ], "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-px27-325w-m34c/GHSA-px27-325w-m34c.json b/advisories/unreviewed/2022/05/GHSA-px27-325w-m34c/GHSA-px27-325w-m34c.json index 05518dd933c..a3b5c31ce2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-px27-325w-m34c/GHSA-px27-325w-m34c.json +++ b/advisories/unreviewed/2022/05/GHSA-px27-325w-m34c/GHSA-px27-325w-m34c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px27-325w-m34c", - "modified": "2022-05-24T17:45:56Z", + "modified": "2025-01-29T18:30:58Z", "published": "2022-05-24T17:45:56Z", "aliases": [ "CVE-2021-21975" ], "details": "Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-q4f3-pjpv-9q5x/GHSA-q4f3-pjpv-9q5x.json b/advisories/unreviewed/2022/05/GHSA-q4f3-pjpv-9q5x/GHSA-q4f3-pjpv-9q5x.json index d547ffbb541..9849dd63f9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4f3-pjpv-9q5x/GHSA-q4f3-pjpv-9q5x.json +++ b/advisories/unreviewed/2022/05/GHSA-q4f3-pjpv-9q5x/GHSA-q4f3-pjpv-9q5x.json @@ -62,7 +62,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-362" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qhhm-rhwq-mpvm/GHSA-qhhm-rhwq-mpvm.json b/advisories/unreviewed/2022/05/GHSA-qhhm-rhwq-mpvm/GHSA-qhhm-rhwq-mpvm.json index 108210ecd82..68e181af841 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhhm-rhwq-mpvm/GHSA-qhhm-rhwq-mpvm.json +++ b/advisories/unreviewed/2022/05/GHSA-qhhm-rhwq-mpvm/GHSA-qhhm-rhwq-mpvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhhm-rhwq-mpvm", - "modified": "2022-05-24T17:09:46Z", + "modified": "2025-01-29T18:30:54Z", "published": "2022-05-24T17:09:46Z", "aliases": [ "CVE-2020-3837" ], "details": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-r647-89qj-xwmp/GHSA-r647-89qj-xwmp.json b/advisories/unreviewed/2022/05/GHSA-r647-89qj-xwmp/GHSA-r647-89qj-xwmp.json index 809431d9a6d..32d0e8c6284 100644 --- a/advisories/unreviewed/2022/05/GHSA-r647-89qj-xwmp/GHSA-r647-89qj-xwmp.json +++ b/advisories/unreviewed/2022/05/GHSA-r647-89qj-xwmp/GHSA-r647-89qj-xwmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r647-89qj-xwmp", - "modified": "2022-05-24T17:19:43Z", + "modified": "2025-01-29T18:30:57Z", "published": "2022-05-24T17:19:43Z", "aliases": [ "CVE-2020-9818" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json b/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json index 4c19901aa65..b7524d8d2e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json +++ b/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg6m-2r9v-c5fj", - "modified": "2022-05-24T19:03:21Z", + "modified": "2025-01-29T18:30:59Z", "published": "2022-05-24T19:03:21Z", "aliases": [ "CVE-2021-21985" ], "details": "The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-rqpw-v3g2-qccx/GHSA-rqpw-v3g2-qccx.json b/advisories/unreviewed/2022/05/GHSA-rqpw-v3g2-qccx/GHSA-rqpw-v3g2-qccx.json index 8a409b0aa66..9360c2b3930 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqpw-v3g2-qccx/GHSA-rqpw-v3g2-qccx.json +++ b/advisories/unreviewed/2022/05/GHSA-rqpw-v3g2-qccx/GHSA-rqpw-v3g2-qccx.json @@ -31,6 +31,7 @@ "database_specific": { "cwe_ids": [ "CWE-287", + "CWE-306", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-rv43-fj24-7hpc/GHSA-rv43-fj24-7hpc.json b/advisories/unreviewed/2022/05/GHSA-rv43-fj24-7hpc/GHSA-rv43-fj24-7hpc.json index ee6ebe76ea6..bc5a196d086 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv43-fj24-7hpc/GHSA-rv43-fj24-7hpc.json +++ b/advisories/unreviewed/2022/05/GHSA-rv43-fj24-7hpc/GHSA-rv43-fj24-7hpc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rv43-fj24-7hpc", - "modified": "2022-05-24T17:04:19Z", + "modified": "2025-01-29T18:30:54Z", "published": "2022-05-24T17:04:19Z", "aliases": [ "CVE-2019-8605" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json b/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json index 60077cde553..0630bd88f8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json +++ b/advisories/unreviewed/2022/05/GHSA-w46j-w72r-9x98/GHSA-w46j-w72r-9x98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w46j-w72r-9x98", - "modified": "2022-05-24T19:15:35Z", + "modified": "2025-01-29T18:31:01Z", "published": "2022-05-24T19:15:35Z", "aliases": [ "CVE-2021-22017" ], "details": "Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json b/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json index e485e1894c1..f683ada360e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json +++ b/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json @@ -34,6 +34,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", + "CWE-862", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-x45r-8w3c-gwgc/GHSA-x45r-8w3c-gwgc.json b/advisories/unreviewed/2022/05/GHSA-x45r-8w3c-gwgc/GHSA-x45r-8w3c-gwgc.json index a23fb8f61e9..55b66065ae5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x45r-8w3c-gwgc/GHSA-x45r-8w3c-gwgc.json +++ b/advisories/unreviewed/2022/05/GHSA-x45r-8w3c-gwgc/GHSA-x45r-8w3c-gwgc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x45r-8w3c-gwgc", - "modified": "2022-05-24T17:19:43Z", + "modified": "2025-01-29T18:30:57Z", "published": "2022-05-24T17:19:43Z", "aliases": [ "CVE-2020-9819" ], "details": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -33,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-9g5r-3vrr-xfcm/GHSA-9g5r-3vrr-xfcm.json b/advisories/unreviewed/2022/08/GHSA-9g5r-3vrr-xfcm/GHSA-9g5r-3vrr-xfcm.json index 029d1700bcb..3c7c268d704 100644 --- a/advisories/unreviewed/2022/08/GHSA-9g5r-3vrr-xfcm/GHSA-9g5r-3vrr-xfcm.json +++ b/advisories/unreviewed/2022/08/GHSA-9g5r-3vrr-xfcm/GHSA-9g5r-3vrr-xfcm.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-287" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/08/GHSA-qjpw-c5xf-g33j/GHSA-qjpw-c5xf-g33j.json b/advisories/unreviewed/2022/08/GHSA-qjpw-c5xf-g33j/GHSA-qjpw-c5xf-g33j.json index fded807d736..2c775b9380c 100644 --- a/advisories/unreviewed/2022/08/GHSA-qjpw-c5xf-g33j/GHSA-qjpw-c5xf-g33j.json +++ b/advisories/unreviewed/2022/08/GHSA-qjpw-c5xf-g33j/GHSA-qjpw-c5xf-g33j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjpw-c5xf-g33j", - "modified": "2022-08-29T20:06:51Z", + "modified": "2025-01-29T18:31:06Z", "published": "2022-08-25T00:00:25Z", "aliases": [ "CVE-2022-32893" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/08/msg00019.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKJGV2EXVMYQW3OAJNI4WUTKKVMD2YYK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL" diff --git a/advisories/unreviewed/2022/08/GHSA-vcm2-j8f4-m7fj/GHSA-vcm2-j8f4-m7fj.json b/advisories/unreviewed/2022/08/GHSA-vcm2-j8f4-m7fj/GHSA-vcm2-j8f4-m7fj.json index 9852e0b13b5..b1f42123bba 100644 --- a/advisories/unreviewed/2022/08/GHSA-vcm2-j8f4-m7fj/GHSA-vcm2-j8f4-m7fj.json +++ b/advisories/unreviewed/2022/08/GHSA-vcm2-j8f4-m7fj/GHSA-vcm2-j8f4-m7fj.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-g9w6-c3gx-pmr3/GHSA-g9w6-c3gx-pmr3.json b/advisories/unreviewed/2023/01/GHSA-g9w6-c3gx-pmr3/GHSA-g9w6-c3gx-pmr3.json index 560b1ac3d81..ed963ba6d98 100644 --- a/advisories/unreviewed/2023/01/GHSA-g9w6-c3gx-pmr3/GHSA-g9w6-c3gx-pmr3.json +++ b/advisories/unreviewed/2023/01/GHSA-g9w6-c3gx-pmr3/GHSA-g9w6-c3gx-pmr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9w6-c3gx-pmr3", - "modified": "2023-01-19T00:30:31Z", + "modified": "2025-01-29T18:31:07Z", "published": "2023-01-11T09:30:29Z", "aliases": [ "CVE-2023-22952" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-53wx-2f9c-xxxr/GHSA-53wx-2f9c-xxxr.json b/advisories/unreviewed/2023/02/GHSA-53wx-2f9c-xxxr/GHSA-53wx-2f9c-xxxr.json index c79260253a1..d8ba0a5ec60 100644 --- a/advisories/unreviewed/2023/02/GHSA-53wx-2f9c-xxxr/GHSA-53wx-2f9c-xxxr.json +++ b/advisories/unreviewed/2023/02/GHSA-53wx-2f9c-xxxr/GHSA-53wx-2f9c-xxxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53wx-2f9c-xxxr", - "modified": "2023-02-23T18:31:06Z", + "modified": "2025-01-29T18:31:07Z", "published": "2023-02-13T21:31:04Z", "aliases": [ "CVE-2023-25717" diff --git a/advisories/unreviewed/2023/05/GHSA-3j54-7gqc-xjwp/GHSA-3j54-7gqc-xjwp.json b/advisories/unreviewed/2023/05/GHSA-3j54-7gqc-xjwp/GHSA-3j54-7gqc-xjwp.json index 8fb92506add..548cdbfa04c 100644 --- a/advisories/unreviewed/2023/05/GHSA-3j54-7gqc-xjwp/GHSA-3j54-7gqc-xjwp.json +++ b/advisories/unreviewed/2023/05/GHSA-3j54-7gqc-xjwp/GHSA-3j54-7gqc-xjwp.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-319" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-3r49-g977-5jhx/GHSA-3r49-g977-5jhx.json b/advisories/unreviewed/2023/05/GHSA-3r49-g977-5jhx/GHSA-3r49-g977-5jhx.json index c8b12ec95f7..3977a3d4b3f 100644 --- a/advisories/unreviewed/2023/05/GHSA-3r49-g977-5jhx/GHSA-3r49-g977-5jhx.json +++ b/advisories/unreviewed/2023/05/GHSA-3r49-g977-5jhx/GHSA-3r49-g977-5jhx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json b/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json index 5cf08feb970..d883e9083f0 100644 --- a/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json +++ b/advisories/unreviewed/2023/05/GHSA-5h8h-fq9x-xjw5/GHSA-5h8h-fq9x-xjw5.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json b/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json index d60d1633708..092199db6c3 100644 --- a/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json +++ b/advisories/unreviewed/2023/05/GHSA-5q43-fxm7-9fhw/GHSA-5q43-fxm7-9fhw.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/05/GHSA-8pwc-q3g2-whvm/GHSA-8pwc-q3g2-whvm.json b/advisories/unreviewed/2023/05/GHSA-8pwc-q3g2-whvm/GHSA-8pwc-q3g2-whvm.json index 8b543088ede..f6683bccfd1 100644 --- a/advisories/unreviewed/2023/05/GHSA-8pwc-q3g2-whvm/GHSA-8pwc-q3g2-whvm.json +++ b/advisories/unreviewed/2023/05/GHSA-8pwc-q3g2-whvm/GHSA-8pwc-q3g2-whvm.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-c39g-g6jh-qhq6/GHSA-c39g-g6jh-qhq6.json b/advisories/unreviewed/2023/05/GHSA-c39g-g6jh-qhq6/GHSA-c39g-g6jh-qhq6.json index 715371d36a3..91d10d48303 100644 --- a/advisories/unreviewed/2023/05/GHSA-c39g-g6jh-qhq6/GHSA-c39g-g6jh-qhq6.json +++ b/advisories/unreviewed/2023/05/GHSA-c39g-g6jh-qhq6/GHSA-c39g-g6jh-qhq6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-f8mp-7x2x-6r8p/GHSA-f8mp-7x2x-6r8p.json b/advisories/unreviewed/2023/05/GHSA-f8mp-7x2x-6r8p/GHSA-f8mp-7x2x-6r8p.json index e1406f6f31e..7447fd0c892 100644 --- a/advisories/unreviewed/2023/05/GHSA-f8mp-7x2x-6r8p/GHSA-f8mp-7x2x-6r8p.json +++ b/advisories/unreviewed/2023/05/GHSA-f8mp-7x2x-6r8p/GHSA-f8mp-7x2x-6r8p.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json b/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json index 49a1d30470c..2a51909b34c 100644 --- a/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json +++ b/advisories/unreviewed/2023/05/GHSA-p73q-78q5-cwpp/GHSA-p73q-78q5-cwpp.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-78" + "CWE-78", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-p8v4-cwrw-r86g/GHSA-p8v4-cwrw-r86g.json b/advisories/unreviewed/2023/05/GHSA-p8v4-cwrw-r86g/GHSA-p8v4-cwrw-r86g.json index 8f5f90aa352..76e21a5d880 100644 --- a/advisories/unreviewed/2023/05/GHSA-p8v4-cwrw-r86g/GHSA-p8v4-cwrw-r86g.json +++ b/advisories/unreviewed/2023/05/GHSA-p8v4-cwrw-r86g/GHSA-p8v4-cwrw-r86g.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-q6xq-fwhh-m47h/GHSA-q6xq-fwhh-m47h.json b/advisories/unreviewed/2023/05/GHSA-q6xq-fwhh-m47h/GHSA-q6xq-fwhh-m47h.json index 0fab209a201..d3b2260cc0b 100644 --- a/advisories/unreviewed/2023/05/GHSA-q6xq-fwhh-m47h/GHSA-q6xq-fwhh-m47h.json +++ b/advisories/unreviewed/2023/05/GHSA-q6xq-fwhh-m47h/GHSA-q6xq-fwhh-m47h.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-r9r7-cx8h-pf3v/GHSA-r9r7-cx8h-pf3v.json b/advisories/unreviewed/2023/05/GHSA-r9r7-cx8h-pf3v/GHSA-r9r7-cx8h-pf3v.json index c35bf858520..2c862b4eae4 100644 --- a/advisories/unreviewed/2023/05/GHSA-r9r7-cx8h-pf3v/GHSA-r9r7-cx8h-pf3v.json +++ b/advisories/unreviewed/2023/05/GHSA-r9r7-cx8h-pf3v/GHSA-r9r7-cx8h-pf3v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-8qxv-m5ch-w93h/GHSA-8qxv-m5ch-w93h.json b/advisories/unreviewed/2023/07/GHSA-8qxv-m5ch-w93h/GHSA-8qxv-m5ch-w93h.json index 5605f93f5c0..7f2b4d69bed 100644 --- a/advisories/unreviewed/2023/07/GHSA-8qxv-m5ch-w93h/GHSA-8qxv-m5ch-w93h.json +++ b/advisories/unreviewed/2023/07/GHSA-8qxv-m5ch-w93h/GHSA-8qxv-m5ch-w93h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qxv-m5ch-w93h", - "modified": "2024-04-04T05:40:38Z", + "modified": "2025-01-29T18:31:13Z", "published": "2023-07-06T21:14:54Z", "aliases": [ "CVE-2023-23541" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-9229-97hp-fx4j/GHSA-9229-97hp-fx4j.json b/advisories/unreviewed/2023/07/GHSA-9229-97hp-fx4j/GHSA-9229-97hp-fx4j.json index b798501b42d..20fcd19728a 100644 --- a/advisories/unreviewed/2023/07/GHSA-9229-97hp-fx4j/GHSA-9229-97hp-fx4j.json +++ b/advisories/unreviewed/2023/07/GHSA-9229-97hp-fx4j/GHSA-9229-97hp-fx4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9229-97hp-fx4j", - "modified": "2024-04-04T05:40:39Z", + "modified": "2025-01-29T18:31:18Z", "published": "2023-07-06T21:14:54Z", "aliases": [ "CVE-2023-24507" diff --git a/advisories/unreviewed/2023/07/GHSA-98m5-rjgx-wv8j/GHSA-98m5-rjgx-wv8j.json b/advisories/unreviewed/2023/07/GHSA-98m5-rjgx-wv8j/GHSA-98m5-rjgx-wv8j.json index 7c4821cb49f..41ad1d62568 100644 --- a/advisories/unreviewed/2023/07/GHSA-98m5-rjgx-wv8j/GHSA-98m5-rjgx-wv8j.json +++ b/advisories/unreviewed/2023/07/GHSA-98m5-rjgx-wv8j/GHSA-98m5-rjgx-wv8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-98m5-rjgx-wv8j", - "modified": "2024-04-04T05:40:21Z", + "modified": "2025-01-29T18:31:12Z", "published": "2023-07-06T21:14:54Z", "aliases": [ "CVE-2023-22779" diff --git a/advisories/unreviewed/2023/07/GHSA-vm8j-5gj2-mf44/GHSA-vm8j-5gj2-mf44.json b/advisories/unreviewed/2023/07/GHSA-vm8j-5gj2-mf44/GHSA-vm8j-5gj2-mf44.json index 2d0d4dcebca..f14ae35168a 100644 --- a/advisories/unreviewed/2023/07/GHSA-vm8j-5gj2-mf44/GHSA-vm8j-5gj2-mf44.json +++ b/advisories/unreviewed/2023/07/GHSA-vm8j-5gj2-mf44/GHSA-vm8j-5gj2-mf44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vm8j-5gj2-mf44", - "modified": "2024-04-04T05:40:22Z", + "modified": "2025-01-29T18:31:12Z", "published": "2023-07-06T21:14:54Z", "aliases": [ "CVE-2023-22780" diff --git a/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json b/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json index d2c7d3443de..219ceac4c3c 100644 --- a/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json +++ b/advisories/unreviewed/2024/03/GHSA-g4p6-wj2c-46f6/GHSA-g4p6-wj2c-46f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4p6-wj2c-46f6", - "modified": "2024-03-21T03:36:45Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2024-1214" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json b/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json index 8aa9bfff8e4..66cd9222ea3 100644 --- a/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json +++ b/advisories/unreviewed/2024/03/GHSA-hw3g-x69p-f6rq/GHSA-hw3g-x69p-f6rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw3g-x69p-f6rq", - "modified": "2024-03-21T03:36:45Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2024-1278" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json b/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json index 2952e45503b..40cbc9aec1a 100644 --- a/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json +++ b/advisories/unreviewed/2024/03/GHSA-wfc2-g4f8-v6c3/GHSA-wfc2-g4f8-v6c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfc2-g4f8-v6c3", - "modified": "2024-03-21T03:36:45Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2024-1213" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qvmh-c8p3-rp3h/GHSA-qvmh-c8p3-rp3h.json b/advisories/unreviewed/2024/05/GHSA-qvmh-c8p3-rp3h/GHSA-qvmh-c8p3-rp3h.json index d8c0f3569b1..fc016ba8dbd 100644 --- a/advisories/unreviewed/2024/05/GHSA-qvmh-c8p3-rp3h/GHSA-qvmh-c8p3-rp3h.json +++ b/advisories/unreviewed/2024/05/GHSA-qvmh-c8p3-rp3h/GHSA-qvmh-c8p3-rp3h.json @@ -1,13 +1,22 @@ { "schema_version": "1.4.0", "id": "GHSA-qvmh-c8p3-rp3h", - "modified": "2024-05-15T21:31:26Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4976" ], "details": "Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], "affected": [], "references": [ { @@ -23,7 +32,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T21:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3vc6-vvp3-rw5p/GHSA-3vc6-vvp3-rw5p.json b/advisories/unreviewed/2024/06/GHSA-3vc6-vvp3-rw5p/GHSA-3vc6-vvp3-rw5p.json index e93dd289b8b..77d5af2f4a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vc6-vvp3-rw5p/GHSA-3vc6-vvp3-rw5p.json +++ b/advisories/unreviewed/2024/06/GHSA-3vc6-vvp3-rw5p/GHSA-3vc6-vvp3-rw5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vc6-vvp3-rw5p", - "modified": "2024-06-27T09:30:39Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-06-27T09:30:39Z", "aliases": [ "CVE-2024-4983" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3xp5-3hvv-rw8c/GHSA-3xp5-3hvv-rw8c.json b/advisories/unreviewed/2024/06/GHSA-3xp5-3hvv-rw8c/GHSA-3xp5-3hvv-rw8c.json index f3921303c06..12f1d62a134 100644 --- a/advisories/unreviewed/2024/06/GHSA-3xp5-3hvv-rw8c/GHSA-3xp5-3hvv-rw8c.json +++ b/advisories/unreviewed/2024/06/GHSA-3xp5-3hvv-rw8c/GHSA-3xp5-3hvv-rw8c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-483w-q33g-j5qq/GHSA-483w-q33g-j5qq.json b/advisories/unreviewed/2024/06/GHSA-483w-q33g-j5qq/GHSA-483w-q33g-j5qq.json index 7f16aa5ced6..69afb340cc5 100644 --- a/advisories/unreviewed/2024/06/GHSA-483w-q33g-j5qq/GHSA-483w-q33g-j5qq.json +++ b/advisories/unreviewed/2024/06/GHSA-483w-q33g-j5qq/GHSA-483w-q33g-j5qq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4947-94mr-v96v/GHSA-4947-94mr-v96v.json b/advisories/unreviewed/2024/06/GHSA-4947-94mr-v96v/GHSA-4947-94mr-v96v.json index 44d6874dc54..e63bbfe887f 100644 --- a/advisories/unreviewed/2024/06/GHSA-4947-94mr-v96v/GHSA-4947-94mr-v96v.json +++ b/advisories/unreviewed/2024/06/GHSA-4947-94mr-v96v/GHSA-4947-94mr-v96v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-m3vh-wcgv-mqx6/GHSA-m3vh-wcgv-mqx6.json b/advisories/unreviewed/2024/06/GHSA-m3vh-wcgv-mqx6/GHSA-m3vh-wcgv-mqx6.json index 1fc6b6797e6..72f4ed52ee9 100644 --- a/advisories/unreviewed/2024/06/GHSA-m3vh-wcgv-mqx6/GHSA-m3vh-wcgv-mqx6.json +++ b/advisories/unreviewed/2024/06/GHSA-m3vh-wcgv-mqx6/GHSA-m3vh-wcgv-mqx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3vh-wcgv-mqx6", - "modified": "2024-06-09T03:30:35Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-06-09T03:30:35Z", "aliases": [ "CVE-2024-5773" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/06/GHSA-prm3-v4r8-g2mv/GHSA-prm3-v4r8-g2mv.json b/advisories/unreviewed/2024/06/GHSA-prm3-v4r8-g2mv/GHSA-prm3-v4r8-g2mv.json index d0a1289c8a4..34e5a797acd 100644 --- a/advisories/unreviewed/2024/06/GHSA-prm3-v4r8-g2mv/GHSA-prm3-v4r8-g2mv.json +++ b/advisories/unreviewed/2024/06/GHSA-prm3-v4r8-g2mv/GHSA-prm3-v4r8-g2mv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-pwvr-q337-w45r/GHSA-pwvr-q337-w45r.json b/advisories/unreviewed/2024/06/GHSA-pwvr-q337-w45r/GHSA-pwvr-q337-w45r.json index 3e55e1093f7..4a03fd00e2e 100644 --- a/advisories/unreviewed/2024/06/GHSA-pwvr-q337-w45r/GHSA-pwvr-q337-w45r.json +++ b/advisories/unreviewed/2024/06/GHSA-pwvr-q337-w45r/GHSA-pwvr-q337-w45r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-r52v-m5f6-5gjm/GHSA-r52v-m5f6-5gjm.json b/advisories/unreviewed/2024/06/GHSA-r52v-m5f6-5gjm/GHSA-r52v-m5f6-5gjm.json index 592afa8b0ae..3113e77823f 100644 --- a/advisories/unreviewed/2024/06/GHSA-r52v-m5f6-5gjm/GHSA-r52v-m5f6-5gjm.json +++ b/advisories/unreviewed/2024/06/GHSA-r52v-m5f6-5gjm/GHSA-r52v-m5f6-5gjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r52v-m5f6-5gjm", - "modified": "2024-06-09T03:30:35Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-06-09T03:30:35Z", "aliases": [ "CVE-2024-5772" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/08/GHSA-44xh-w98h-vq6q/GHSA-44xh-w98h-vq6q.json b/advisories/unreviewed/2024/08/GHSA-44xh-w98h-vq6q/GHSA-44xh-w98h-vq6q.json index 81336bf44bd..2c229ed43f8 100644 --- a/advisories/unreviewed/2024/08/GHSA-44xh-w98h-vq6q/GHSA-44xh-w98h-vq6q.json +++ b/advisories/unreviewed/2024/08/GHSA-44xh-w98h-vq6q/GHSA-44xh-w98h-vq6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44xh-w98h-vq6q", - "modified": "2024-08-16T03:33:48Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-08-16T03:33:48Z", "aliases": [ "CVE-2024-7630" diff --git a/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json b/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json index 9c602954cbc..220e430d1be 100644 --- a/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json +++ b/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4r3v-6hh6-vhf4", - "modified": "2024-08-13T00:31:42Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-08-13T00:31:42Z", "aliases": [ "CVE-2024-43152" diff --git a/advisories/unreviewed/2024/08/GHSA-8vv9-x4pw-wwf3/GHSA-8vv9-x4pw-wwf3.json b/advisories/unreviewed/2024/08/GHSA-8vv9-x4pw-wwf3/GHSA-8vv9-x4pw-wwf3.json index 8fe63729d86..9d41917e0ae 100644 --- a/advisories/unreviewed/2024/08/GHSA-8vv9-x4pw-wwf3/GHSA-8vv9-x4pw-wwf3.json +++ b/advisories/unreviewed/2024/08/GHSA-8vv9-x4pw-wwf3/GHSA-8vv9-x4pw-wwf3.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json index 504a123c28d..2bd2cbad792 100644 --- a/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json +++ b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmmr-cc39-65m3", - "modified": "2024-08-02T12:31:43Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-4643" diff --git a/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json b/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json index f098689351a..488db2635fc 100644 --- a/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json +++ b/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cv4-mxxr-4vxg", - "modified": "2024-09-30T21:31:07Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:07Z", "aliases": [ "CVE-2024-7671" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json b/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json index 36e170052e4..dd0ab872ecc 100644 --- a/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json +++ b/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5x9-4j34-4q7p", - "modified": "2024-09-30T21:31:08Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:08Z", "aliases": [ "CVE-2024-7675" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json b/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json index 5758c48d683..9ac55b8b12b 100644 --- a/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json +++ b/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m785-2mqm-9r6g", - "modified": "2024-09-30T21:31:08Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:08Z", "aliases": [ "CVE-2024-7672" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json b/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json index e199a2f8674..8d42bffc88b 100644 --- a/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json +++ b/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9cq-m6qx-6497", - "modified": "2024-09-30T21:31:07Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:07Z", "aliases": [ "CVE-2024-7670" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json index 0da84f4f35a..00cd923704a 100644 --- a/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json +++ b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrv4-mmpj-7phv", - "modified": "2024-09-30T21:31:08Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:08Z", "aliases": [ "CVE-2024-7673" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json index 648a1232e1f..6311af3b24e 100644 --- a/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json +++ b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq4q-895p-v538", - "modified": "2024-09-30T21:31:08Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-09-30T21:31:08Z", "aliases": [ "CVE-2024-7674" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0015" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json index 2425e6c7a07..251193a769f 100644 --- a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json +++ b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json b/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json index 1e29d8fb8ab..de55340db87 100644 --- a/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json +++ b/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67wj-vrrp-x2fv", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12198" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json b/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json index a38c8e3a673..78723e68063 100644 --- a/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json +++ b/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6ghv-cm9w-9m65", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12192" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json index 1939c8faef4..0209ee909f9 100644 --- a/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json +++ b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rh6-g778-wcww", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12670" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json b/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json index c47b6adf3c3..4111741e6ef 100644 --- a/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json +++ b/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w23-rv5f-3ch2", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12191" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json b/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json index bdf797d319b..c7b7ee39d24 100644 --- a/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json +++ b/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5q3-r2wq-xch4", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12199" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json b/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json index 53f5a11a4a5..16687218484 100644 --- a/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json +++ b/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgg7-f8f3-3g3h", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-11422" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json b/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json index 3721d8c2c1a..e1255fbd3b4 100644 --- a/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json +++ b/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g79x-gv43-8472", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12179" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json b/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json index 4bc6434457e..1cd65aff7f5 100644 --- a/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json +++ b/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gq79-6cpg-v72r", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12194" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json index 7d5adf69462..a95ae1b2552 100644 --- a/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json +++ b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hmwf-p83m-gr4q", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12669" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json b/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json index a8e298cc580..47dbdd013cb 100644 --- a/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json +++ b/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jgvv-pcgx-gv2f", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12200" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json b/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json index 9b356d5316b..0105b822118 100644 --- a/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json +++ b/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmp3-h84f-cq76", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12671" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json b/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json index e29dc403e4a..3e62ac1665f 100644 --- a/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json +++ b/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p92v-v2pv-248f", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:19Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12178" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json b/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json index b41bcd59461..7578641033b 100644 --- a/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json +++ b/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjwc-96x8-qh73", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12197" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json b/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json index 818f8d751e8..5881f9bec3e 100644 --- a/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json +++ b/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgwv-xwcw-8vxj", - "modified": "2024-12-17T18:33:49Z", + "modified": "2025-01-29T18:31:20Z", "published": "2024-12-17T18:33:49Z", "aliases": [ "CVE-2024-12193" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json b/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json index 3229c0ec968..6e372015367 100644 --- a/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json +++ b/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3fr9-m4cp-5gr8", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-29T18:31:21Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24101" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4cfr-xp32-h9c9/GHSA-4cfr-xp32-h9c9.json b/advisories/unreviewed/2025/01/GHSA-4cfr-xp32-h9c9/GHSA-4cfr-xp32-h9c9.json new file mode 100644 index 00000000000..ebbe27b12d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cfr-xp32-h9c9/GHSA-4cfr-xp32-h9c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cfr-xp32-h9c9", + "modified": "2025-01-29T18:31:22Z", + "published": "2025-01-29T18:31:22Z", + "aliases": [ + "CVE-2023-35907" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35907" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7181814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9229-mw36-xgrg/GHSA-9229-mw36-xgrg.json b/advisories/unreviewed/2025/01/GHSA-9229-mw36-xgrg/GHSA-9229-mw36-xgrg.json index 42ca9f72d44..618f4f43c67 100644 --- a/advisories/unreviewed/2025/01/GHSA-9229-mw36-xgrg/GHSA-9229-mw36-xgrg.json +++ b/advisories/unreviewed/2025/01/GHSA-9229-mw36-xgrg/GHSA-9229-mw36-xgrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9229-mw36-xgrg", - "modified": "2025-01-29T00:31:54Z", + "modified": "2025-01-29T18:31:22Z", "published": "2025-01-29T00:31:54Z", "aliases": [ "CVE-2025-22917" ], "details": "A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-99gg-h722-7qw4/GHSA-99gg-h722-7qw4.json b/advisories/unreviewed/2025/01/GHSA-99gg-h722-7qw4/GHSA-99gg-h722-7qw4.json index 91137313ba0..f5eda90513c 100644 --- a/advisories/unreviewed/2025/01/GHSA-99gg-h722-7qw4/GHSA-99gg-h722-7qw4.json +++ b/advisories/unreviewed/2025/01/GHSA-99gg-h722-7qw4/GHSA-99gg-h722-7qw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99gg-h722-7qw4", - "modified": "2025-01-29T00:31:54Z", + "modified": "2025-01-29T18:31:21Z", "published": "2025-01-29T00:31:54Z", "aliases": [ "CVE-2024-57376" ], "details": "Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9r3r-662w-7j3w/GHSA-9r3r-662w-7j3w.json b/advisories/unreviewed/2025/01/GHSA-9r3r-662w-7j3w/GHSA-9r3r-662w-7j3w.json new file mode 100644 index 00000000000..a55ef340070 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9r3r-662w-7j3w/GHSA-9r3r-662w-7j3w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3r-662w-7j3w", + "modified": "2025-01-29T18:31:22Z", + "published": "2025-01-29T18:31:22Z", + "aliases": [ + "CVE-2025-24527" + ], + "details": "An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24527" + }, + { + "type": "WEB", + "url": "https://techdocs.akamai.com/eaa/changelog" + }, + { + "type": "WEB", + "url": "https://techdocs.akamai.com/eaa/changelog/january-29-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h6q9-c4w9-v66r/GHSA-h6q9-c4w9-v66r.json b/advisories/unreviewed/2025/01/GHSA-h6q9-c4w9-v66r/GHSA-h6q9-c4w9-v66r.json index 99646f3694d..0cd0e5a4b24 100644 --- a/advisories/unreviewed/2025/01/GHSA-h6q9-c4w9-v66r/GHSA-h6q9-c4w9-v66r.json +++ b/advisories/unreviewed/2025/01/GHSA-h6q9-c4w9-v66r/GHSA-h6q9-c4w9-v66r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6q9-c4w9-v66r", - "modified": "2025-01-29T00:31:54Z", + "modified": "2025-01-29T18:31:21Z", "published": "2025-01-29T00:31:54Z", "aliases": [ "CVE-2024-57514" ], "details": "The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hhw5-j8rq-43wg/GHSA-hhw5-j8rq-43wg.json b/advisories/unreviewed/2025/01/GHSA-hhw5-j8rq-43wg/GHSA-hhw5-j8rq-43wg.json new file mode 100644 index 00000000000..4d24e2e92a1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hhw5-j8rq-43wg/GHSA-hhw5-j8rq-43wg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhw5-j8rq-43wg", + "modified": "2025-01-29T18:31:22Z", + "published": "2025-01-29T18:31:22Z", + "aliases": [ + "CVE-2023-37413" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37413" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7181814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m3pc-rgm4-56jw/GHSA-m3pc-rgm4-56jw.json b/advisories/unreviewed/2025/01/GHSA-m3pc-rgm4-56jw/GHSA-m3pc-rgm4-56jw.json index 92f0de04f4a..e3b5ca2d706 100644 --- a/advisories/unreviewed/2025/01/GHSA-m3pc-rgm4-56jw/GHSA-m3pc-rgm4-56jw.json +++ b/advisories/unreviewed/2025/01/GHSA-m3pc-rgm4-56jw/GHSA-m3pc-rgm4-56jw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m3pc-rgm4-56jw", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-29T18:31:21Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-55192" ], "details": "OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qq5h-rjj9-q9qg/GHSA-qq5h-rjj9-q9qg.json b/advisories/unreviewed/2025/01/GHSA-qq5h-rjj9-q9qg/GHSA-qq5h-rjj9-q9qg.json index 59d7cbf03e3..ad85b37bfb7 100644 --- a/advisories/unreviewed/2025/01/GHSA-qq5h-rjj9-q9qg/GHSA-qq5h-rjj9-q9qg.json +++ b/advisories/unreviewed/2025/01/GHSA-qq5h-rjj9-q9qg/GHSA-qq5h-rjj9-q9qg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qq5h-rjj9-q9qg", - "modified": "2025-01-29T15:31:35Z", + "modified": "2025-01-29T18:31:22Z", "published": "2025-01-29T15:31:35Z", "aliases": [ "CVE-2024-57439" ], "details": "An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T15:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rrmh-m2fw-63jp/GHSA-rrmh-m2fw-63jp.json b/advisories/unreviewed/2025/01/GHSA-rrmh-m2fw-63jp/GHSA-rrmh-m2fw-63jp.json new file mode 100644 index 00000000000..ff5aca37a5c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrmh-m2fw-63jp/GHSA-rrmh-m2fw-63jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmh-m2fw-63jp", + "modified": "2025-01-29T18:31:22Z", + "published": "2025-01-29T18:31:22Z", + "aliases": [ + "CVE-2023-37412" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37412" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7181814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vf25-w4jq-mhx2/GHSA-vf25-w4jq-mhx2.json b/advisories/unreviewed/2025/01/GHSA-vf25-w4jq-mhx2/GHSA-vf25-w4jq-mhx2.json new file mode 100644 index 00000000000..a4947b60c03 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vf25-w4jq-mhx2/GHSA-vf25-w4jq-mhx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf25-w4jq-mhx2", + "modified": "2025-01-29T18:31:22Z", + "published": "2025-01-29T18:31:22Z", + "aliases": [ + "CVE-2023-37398" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37398" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7181814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json b/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json index 2e784de2f2f..5ac4ffed923 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json +++ b/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xh6m-fr4r-mqj3", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-29T18:31:21Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24117" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z"