From 5ae3398d0702d1dfcc78ae5e4193bd71235b418e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Apr 2025 21:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4v5x-9m47-cqr2.json | 6 +- .../GHSA-6hf5-gqpw-h5ww.json | 10 ++- .../GHSA-7g9p-cvcv-xgp8.json | 9 ++- .../GHSA-9h67-gqh5-w6f6.json | 10 ++- .../GHSA-grjq-m66f-rp7p.json | 1 + .../GHSA-qqc2-6qq8-p574.json | 9 ++- .../GHSA-vj77-9g38-f2fm.json | 9 ++- .../GHSA-qw5m-v83j-4g26.json | 2 +- .../GHSA-7639-pv9r-w8cv.json | 2 +- .../GHSA-q36w-mwcg-f7m3.json | 3 +- .../GHSA-24j2-327w-xq74.json | 4 +- .../GHSA-2x3r-rpmr-wmwh.json | 6 +- .../GHSA-6mx5-j85j-5862.json | 3 +- .../GHSA-c8mq-83h4-gm57.json | 1 + .../GHSA-hf37-cc25-65x2.json | 4 +- .../GHSA-q8cm-r6w4-28gm.json | 6 +- .../GHSA-6r47-4376-p42h.json | 2 +- .../GHSA-652f-58jv-j9fp.json | 2 +- .../GHSA-9qq8-mmh8-945v.json | 6 +- .../GHSA-fqg5-7rjv-45wh.json | 4 +- .../GHSA-p2fm-m9qc-j6x3.json | 2 +- .../GHSA-pxf9-jjq8-hvw8.json | 4 +- .../GHSA-xch8-frxx-v8q6.json | 2 +- .../GHSA-8qwh-6r32-9v26.json | 4 +- .../GHSA-9m9h-jcjj-xjvx.json | 1 + .../GHSA-f6jr-7pgg-f497.json | 3 +- .../GHSA-p5q9-hxvv-3rqq.json | 4 +- .../GHSA-2w4c-wrx8-g8wh.json | 2 +- .../GHSA-7j4f-2m7v-2cjv.json | 2 +- .../GHSA-936g-q8pj-qjhp.json | 2 +- .../GHSA-cgvh-9643-55w4.json | 2 +- .../GHSA-g9rx-gc8h-mpjj.json | 2 +- .../GHSA-gp97-78rf-vw76.json | 2 +- .../GHSA-wh3q-8jwf-qv4m.json | 2 +- .../GHSA-x8pf-qjr3-w5cf.json | 2 +- .../GHSA-2ccc-6qjv-38cv.json | 29 ++++++++ .../GHSA-2cx7-5g5j-x648.json | 50 ++++++++++++++ .../GHSA-2pq8-4rf3-3vh9.json | 15 ++-- .../GHSA-2qvw-44pq-38xj.json | 11 ++- .../GHSA-3c8w-xm49-2w5f.json | 29 ++++++++ .../GHSA-44p4-ww39-jj4m.json | 15 ++-- .../GHSA-4h6g-wfmr-qvjh.json | 52 ++++++++++++++ .../GHSA-4mpp-jp65-h4rw.json | 11 ++- .../GHSA-5p33-cx2m-4x9v.json | 48 +++++++++++++ .../GHSA-62c2-pjmr-4wx5.json | 29 ++++++++ .../GHSA-677p-h2hj-9j82.json | 15 ++-- .../GHSA-78xp-xvw2-6rw6.json | 15 ++-- .../GHSA-7g4r-49h3-32mr.json | 4 +- .../GHSA-7hqv-m3mr-cv2v.json | 6 +- .../GHSA-7vw9-hmx7-h29g.json | 60 ++++++++++++++++ .../GHSA-848p-384j-r4fv.json | 15 ++-- .../GHSA-89vx-8j4r-pm86.json | 40 +++++++++++ .../GHSA-8rrr-w669-26rg.json | 29 ++++++++ .../GHSA-9fw4-p66g-p3hh.json | 11 ++- .../GHSA-cj26-58c8-7wq6.json | 11 ++- .../GHSA-cp2p-wmjj-5m7m.json | 66 ++++++++++++++++++ .../GHSA-fgr8-gcxj-6pq5.json | 15 ++-- .../GHSA-fhm7-xr45-vvhp.json | 36 ++++++++++ .../GHSA-fvqg-wm9j-4gc4.json | 15 ++-- .../GHSA-g3pp-67rc-cjg2.json | 15 ++-- .../GHSA-g67h-7m25-7mmv.json | 15 ++-- .../GHSA-g8r8-g7qx-p4c7.json | 15 ++-- .../GHSA-gvc3-q38f-h355.json | 62 +++++++++++++++++ .../GHSA-h9c2-qf4j-fhfg.json | 56 +++++++++++++++ .../GHSA-hr94-jx6q-7pcg.json | 15 ++-- .../GHSA-j793-r5pf-7w34.json | 44 ++++++++++++ .../GHSA-j93w-j7jm-5c8h.json | 15 ++-- .../GHSA-jfph-3485-2gcv.json | 11 ++- .../GHSA-jh67-7rhf-7vg4.json | 56 +++++++++++++++ .../GHSA-jv9h-q2w4-vg83.json | 56 +++++++++++++++ .../GHSA-m46p-v6c6-2xv2.json | 48 +++++++++++++ .../GHSA-p84q-ch5j-7frh.json | 15 ++-- .../GHSA-pxwr-cc58-gq3m.json | 68 +++++++++++++++++++ .../GHSA-q8hq-xhpc-vm95.json | 15 ++-- .../GHSA-r527-4r6f-fjr3.json | 48 +++++++++++++ .../GHSA-r6p8-wxvj-85qw.json | 56 +++++++++++++++ .../GHSA-rjm4-6mrc-mh44.json | 4 +- .../GHSA-v3r6-268x-w57p.json | 11 ++- .../GHSA-v76p-9ff9-f29g.json | 44 ++++++++++++ .../GHSA-w22f-9vp5-hh8q.json | 11 ++- .../GHSA-wf73-fprx-hxjj.json | 68 +++++++++++++++++++ .../GHSA-wgwq-2crv-c4jj.json | 33 +++++++++ .../GHSA-wpf2-5j53-3cxv.json | 29 ++++++++ .../GHSA-x3v3-vr8q-m495.json | 44 ++++++++++++ .../GHSA-x74c-mr6j-xgx9.json | 44 ++++++++++++ .../GHSA-x8pm-wrg2-mqmx.json | 4 +- .../GHSA-xw3g-f28m-3q7j.json | 29 ++++++++ 87 files changed, 1569 insertions(+), 124 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2ccc-6qjv-38cv/GHSA-2ccc-6qjv-38cv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2cx7-5g5j-x648/GHSA-2cx7-5g5j-x648.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4h6g-wfmr-qvjh/GHSA-4h6g-wfmr-qvjh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5p33-cx2m-4x9v/GHSA-5p33-cx2m-4x9v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7vw9-hmx7-h29g/GHSA-7vw9-hmx7-h29g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-89vx-8j4r-pm86/GHSA-89vx-8j4r-pm86.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cp2p-wmjj-5m7m/GHSA-cp2p-wmjj-5m7m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gvc3-q38f-h355/GHSA-gvc3-q38f-h355.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j793-r5pf-7w34/GHSA-j793-r5pf-7w34.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jh67-7rhf-7vg4/GHSA-jh67-7rhf-7vg4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jv9h-q2w4-vg83/GHSA-jv9h-q2w4-vg83.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m46p-v6c6-2xv2/GHSA-m46p-v6c6-2xv2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pxwr-cc58-gq3m/GHSA-pxwr-cc58-gq3m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r527-4r6f-fjr3/GHSA-r527-4r6f-fjr3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v76p-9ff9-f29g/GHSA-v76p-9ff9-f29g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wf73-fprx-hxjj/GHSA-wf73-fprx-hxjj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wpf2-5j53-3cxv/GHSA-wpf2-5j53-3cxv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x3v3-vr8q-m495/GHSA-x3v3-vr8q-m495.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x74c-mr6j-xgx9/GHSA-x74c-mr6j-xgx9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json diff --git a/advisories/github-reviewed/2024/12/GHSA-4v5x-9m47-cqr2/GHSA-4v5x-9m47-cqr2.json b/advisories/github-reviewed/2024/12/GHSA-4v5x-9m47-cqr2/GHSA-4v5x-9m47-cqr2.json index 06442b7b7f3..5c84dfcfaf4 100644 --- a/advisories/github-reviewed/2024/12/GHSA-4v5x-9m47-cqr2/GHSA-4v5x-9m47-cqr2.json +++ b/advisories/github-reviewed/2024/12/GHSA-4v5x-9m47-cqr2/GHSA-4v5x-9m47-cqr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v5x-9m47-cqr2", - "modified": "2025-03-25T21:48:41Z", + "modified": "2025-04-17T21:30:43Z", "published": "2024-12-09T21:31:02Z", "withdrawn": "2025-03-25T21:48:41Z", "aliases": [], @@ -39,6 +39,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12369" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3989" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12369" diff --git a/advisories/unreviewed/2022/01/GHSA-6hf5-gqpw-h5ww/GHSA-6hf5-gqpw-h5ww.json b/advisories/unreviewed/2022/01/GHSA-6hf5-gqpw-h5ww/GHSA-6hf5-gqpw-h5ww.json index 34b99298b5a..1ab48d594a2 100644 --- a/advisories/unreviewed/2022/01/GHSA-6hf5-gqpw-h5ww/GHSA-6hf5-gqpw-h5ww.json +++ b/advisories/unreviewed/2022/01/GHSA-6hf5-gqpw-h5ww/GHSA-6hf5-gqpw-h5ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hf5-gqpw-h5ww", - "modified": "2022-01-14T00:03:00Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-01-11T00:01:35Z", "aliases": [ "CVE-2021-32996" ], "details": "The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-192", "CWE-681" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-7g9p-cvcv-xgp8/GHSA-7g9p-cvcv-xgp8.json b/advisories/unreviewed/2022/02/GHSA-7g9p-cvcv-xgp8/GHSA-7g9p-cvcv-xgp8.json index 8ca976c6111..6bd34c77785 100644 --- a/advisories/unreviewed/2022/02/GHSA-7g9p-cvcv-xgp8/GHSA-7g9p-cvcv-xgp8.json +++ b/advisories/unreviewed/2022/02/GHSA-7g9p-cvcv-xgp8/GHSA-7g9p-cvcv-xgp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g9p-cvcv-xgp8", - "modified": "2022-03-05T00:00:58Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-02-25T00:00:59Z", "aliases": [ "CVE-2020-14480" ], "details": "Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-9h67-gqh5-w6f6/GHSA-9h67-gqh5-w6f6.json b/advisories/unreviewed/2022/02/GHSA-9h67-gqh5-w6f6/GHSA-9h67-gqh5-w6f6.json index becceada814..5d1755cf363 100644 --- a/advisories/unreviewed/2022/02/GHSA-9h67-gqh5-w6f6/GHSA-9h67-gqh5-w6f6.json +++ b/advisories/unreviewed/2022/02/GHSA-9h67-gqh5-w6f6/GHSA-9h67-gqh5-w6f6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9h67-gqh5-w6f6", - "modified": "2022-03-05T00:00:58Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-02-25T00:00:59Z", "aliases": [ "CVE-2020-14481" ], "details": "The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-261", "CWE-326" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-grjq-m66f-rp7p/GHSA-grjq-m66f-rp7p.json b/advisories/unreviewed/2022/02/GHSA-grjq-m66f-rp7p/GHSA-grjq-m66f-rp7p.json index 329c6dc0808..c2987dc6270 100644 --- a/advisories/unreviewed/2022/02/GHSA-grjq-m66f-rp7p/GHSA-grjq-m66f-rp7p.json +++ b/advisories/unreviewed/2022/02/GHSA-grjq-m66f-rp7p/GHSA-grjq-m66f-rp7p.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/02/GHSA-qqc2-6qq8-p574/GHSA-qqc2-6qq8-p574.json b/advisories/unreviewed/2022/02/GHSA-qqc2-6qq8-p574/GHSA-qqc2-6qq8-p574.json index 7f62f9d1eb1..fd18e700284 100644 --- a/advisories/unreviewed/2022/02/GHSA-qqc2-6qq8-p574/GHSA-qqc2-6qq8-p574.json +++ b/advisories/unreviewed/2022/02/GHSA-qqc2-6qq8-p574/GHSA-qqc2-6qq8-p574.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqc2-6qq8-p574", - "modified": "2022-03-05T00:00:57Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-02-25T00:00:59Z", "aliases": [ "CVE-2020-14478" ], "details": "A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-vj77-9g38-f2fm/GHSA-vj77-9g38-f2fm.json b/advisories/unreviewed/2022/02/GHSA-vj77-9g38-f2fm/GHSA-vj77-9g38-f2fm.json index 7e73ec2de6e..aef62392fd4 100644 --- a/advisories/unreviewed/2022/02/GHSA-vj77-9g38-f2fm/GHSA-vj77-9g38-f2fm.json +++ b/advisories/unreviewed/2022/02/GHSA-vj77-9g38-f2fm/GHSA-vj77-9g38-f2fm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vj77-9g38-f2fm", - "modified": "2022-03-08T00:00:41Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-02-25T00:00:59Z", "aliases": [ "CVE-2020-14502" ], "details": "The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-qw5m-v83j-4g26/GHSA-qw5m-v83j-4g26.json b/advisories/unreviewed/2022/05/GHSA-qw5m-v83j-4g26/GHSA-qw5m-v83j-4g26.json index 53912e3d502..c982ba33067 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw5m-v83j-4g26/GHSA-qw5m-v83j-4g26.json +++ b/advisories/unreviewed/2022/05/GHSA-qw5m-v83j-4g26/GHSA-qw5m-v83j-4g26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw5m-v83j-4g26", - "modified": "2022-12-13T12:30:22Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-05-24T16:58:17Z", "aliases": [ "CVE-2019-16905" diff --git a/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json b/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json index 511d6332bfb..e5b916c4a47 100644 --- a/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json +++ b/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7639-pv9r-w8cv", - "modified": "2023-07-24T15:30:25Z", + "modified": "2025-04-17T21:30:37Z", "published": "2022-06-25T00:00:53Z", "aliases": [ "CVE-2022-1740" diff --git a/advisories/unreviewed/2022/06/GHSA-q36w-mwcg-f7m3/GHSA-q36w-mwcg-f7m3.json b/advisories/unreviewed/2022/06/GHSA-q36w-mwcg-f7m3/GHSA-q36w-mwcg-f7m3.json index a1be4f4b0cc..3f93c751ee0 100644 --- a/advisories/unreviewed/2022/06/GHSA-q36w-mwcg-f7m3/GHSA-q36w-mwcg-f7m3.json +++ b/advisories/unreviewed/2022/06/GHSA-q36w-mwcg-f7m3/GHSA-q36w-mwcg-f7m3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-912" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-24j2-327w-xq74/GHSA-24j2-327w-xq74.json b/advisories/unreviewed/2022/12/GHSA-24j2-327w-xq74/GHSA-24j2-327w-xq74.json index ba91ac6e1f6..14c91054921 100644 --- a/advisories/unreviewed/2022/12/GHSA-24j2-327w-xq74/GHSA-24j2-327w-xq74.json +++ b/advisories/unreviewed/2022/12/GHSA-24j2-327w-xq74/GHSA-24j2-327w-xq74.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-2x3r-rpmr-wmwh/GHSA-2x3r-rpmr-wmwh.json b/advisories/unreviewed/2022/12/GHSA-2x3r-rpmr-wmwh/GHSA-2x3r-rpmr-wmwh.json index c98b37b0182..02787f740b5 100644 --- a/advisories/unreviewed/2022/12/GHSA-2x3r-rpmr-wmwh/GHSA-2x3r-rpmr-wmwh.json +++ b/advisories/unreviewed/2022/12/GHSA-2x3r-rpmr-wmwh/GHSA-2x3r-rpmr-wmwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x3r-rpmr-wmwh", - "modified": "2022-12-24T06:30:26Z", + "modified": "2025-04-17T21:30:38Z", "published": "2022-12-20T21:30:17Z", "aliases": [ "CVE-2022-46312" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6mx5-j85j-5862/GHSA-6mx5-j85j-5862.json b/advisories/unreviewed/2022/12/GHSA-6mx5-j85j-5862/GHSA-6mx5-j85j-5862.json index 278d5e50cab..3f5865bbc3d 100644 --- a/advisories/unreviewed/2022/12/GHSA-6mx5-j85j-5862/GHSA-6mx5-j85j-5862.json +++ b/advisories/unreviewed/2022/12/GHSA-6mx5-j85j-5862/GHSA-6mx5-j85j-5862.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-c8mq-83h4-gm57/GHSA-c8mq-83h4-gm57.json b/advisories/unreviewed/2022/12/GHSA-c8mq-83h4-gm57/GHSA-c8mq-83h4-gm57.json index 110831b2c65..26ee21a8068 100644 --- a/advisories/unreviewed/2022/12/GHSA-c8mq-83h4-gm57/GHSA-c8mq-83h4-gm57.json +++ b/advisories/unreviewed/2022/12/GHSA-c8mq-83h4-gm57/GHSA-c8mq-83h4-gm57.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-193", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-hf37-cc25-65x2/GHSA-hf37-cc25-65x2.json b/advisories/unreviewed/2022/12/GHSA-hf37-cc25-65x2/GHSA-hf37-cc25-65x2.json index 4b1e331d2cb..18ee201a552 100644 --- a/advisories/unreviewed/2022/12/GHSA-hf37-cc25-65x2/GHSA-hf37-cc25-65x2.json +++ b/advisories/unreviewed/2022/12/GHSA-hf37-cc25-65x2/GHSA-hf37-cc25-65x2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json b/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json index 4a8bc43f082..04a5928425f 100644 --- a/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json +++ b/advisories/unreviewed/2022/12/GHSA-q8cm-r6w4-28gm/GHSA-q8cm-r6w4-28gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8cm-r6w4-28gm", - "modified": "2022-12-22T15:30:21Z", + "modified": "2025-04-17T21:30:38Z", "published": "2022-12-18T06:31:08Z", "aliases": [ "CVE-2022-47521" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/r/20221123153543.8568-4-philipturnbull%40github.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/r/20221123153543.8568-4-philipturnbull@github.com" diff --git a/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json b/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json index 44113760b80..89465f88955 100644 --- a/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json +++ b/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r47-4376-p42h", - "modified": "2024-04-04T05:30:55Z", + "modified": "2025-04-17T21:30:38Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-47209" diff --git a/advisories/unreviewed/2023/12/GHSA-652f-58jv-j9fp/GHSA-652f-58jv-j9fp.json b/advisories/unreviewed/2023/12/GHSA-652f-58jv-j9fp/GHSA-652f-58jv-j9fp.json index c5a30ccfb06..4eaba8829f0 100644 --- a/advisories/unreviewed/2023/12/GHSA-652f-58jv-j9fp/GHSA-652f-58jv-j9fp.json +++ b/advisories/unreviewed/2023/12/GHSA-652f-58jv-j9fp/GHSA-652f-58jv-j9fp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-652f-58jv-j9fp", - "modified": "2024-01-08T15:30:26Z", + "modified": "2025-04-17T21:30:39Z", "published": "2023-12-29T06:30:30Z", "aliases": [ "CVE-2023-31300" diff --git a/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json b/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json index 02277d5e0a7..bba5d875c86 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json +++ b/advisories/unreviewed/2023/12/GHSA-9qq8-mmh8-945v/GHSA-9qq8-mmh8-945v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qq8-mmh8-945v", - "modified": "2023-12-27T21:31:00Z", + "modified": "2025-04-17T21:30:38Z", "published": "2023-12-22T21:30:24Z", "aliases": [ "CVE-2023-51018" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json b/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json index 9e4a199261b..3d76ae506a6 100644 --- a/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json +++ b/advisories/unreviewed/2023/12/GHSA-fqg5-7rjv-45wh/GHSA-fqg5-7rjv-45wh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fqg5-7rjv-45wh", - "modified": "2023-12-29T06:30:29Z", + "modified": "2025-04-17T21:30:38Z", "published": "2023-12-29T06:30:29Z", "aliases": [ "CVE-2023-23443" ], - "details": "\nSome Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.\n\n", + "details": "Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-p2fm-m9qc-j6x3/GHSA-p2fm-m9qc-j6x3.json b/advisories/unreviewed/2023/12/GHSA-p2fm-m9qc-j6x3/GHSA-p2fm-m9qc-j6x3.json index 06e65d26f41..f774076c2a7 100644 --- a/advisories/unreviewed/2023/12/GHSA-p2fm-m9qc-j6x3/GHSA-p2fm-m9qc-j6x3.json +++ b/advisories/unreviewed/2023/12/GHSA-p2fm-m9qc-j6x3/GHSA-p2fm-m9qc-j6x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2fm-m9qc-j6x3", - "modified": "2024-01-05T21:30:32Z", + "modified": "2025-04-17T21:30:39Z", "published": "2023-12-30T03:30:19Z", "aliases": [ "CVE-2022-46487" diff --git a/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json b/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json index 1b498945705..6a134fa6946 100644 --- a/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json +++ b/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pxf9-jjq8-hvw8", - "modified": "2023-12-29T06:30:30Z", + "modified": "2025-04-17T21:30:39Z", "published": "2023-12-29T06:30:30Z", "aliases": [ "CVE-2023-51435" ], - "details": "\nSome Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.\n\n", + "details": "Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json b/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json index 687a5ef4060..b82336f486f 100644 --- a/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json +++ b/advisories/unreviewed/2023/12/GHSA-xch8-frxx-v8q6/GHSA-xch8-frxx-v8q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xch8-frxx-v8q6", - "modified": "2024-01-05T00:30:28Z", + "modified": "2025-04-17T21:30:38Z", "published": "2023-12-29T03:30:29Z", "aliases": [ "CVE-2023-31292" diff --git a/advisories/unreviewed/2024/01/GHSA-8qwh-6r32-9v26/GHSA-8qwh-6r32-9v26.json b/advisories/unreviewed/2024/01/GHSA-8qwh-6r32-9v26/GHSA-8qwh-6r32-9v26.json index f3f79a31c9f..de1a9b337fb 100644 --- a/advisories/unreviewed/2024/01/GHSA-8qwh-6r32-9v26/GHSA-8qwh-6r32-9v26.json +++ b/advisories/unreviewed/2024/01/GHSA-8qwh-6r32-9v26/GHSA-8qwh-6r32-9v26.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json index 16e8849a94a..00db4e420da 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json +++ b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-755" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json index 2e95e6a3dd1..79b7f35419f 100644 --- a/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json +++ b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json index 7d95e291317..b5c9aab429b 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json +++ b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p5q9-hxvv-3rqq", - "modified": "2024-01-11T18:31:23Z", + "modified": "2025-04-17T21:30:41Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34321" ], - "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n", + "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-2w4c-wrx8-g8wh/GHSA-2w4c-wrx8-g8wh.json b/advisories/unreviewed/2024/03/GHSA-2w4c-wrx8-g8wh/GHSA-2w4c-wrx8-g8wh.json index 9e11eaec774..fca648a6d90 100644 --- a/advisories/unreviewed/2024/03/GHSA-2w4c-wrx8-g8wh/GHSA-2w4c-wrx8-g8wh.json +++ b/advisories/unreviewed/2024/03/GHSA-2w4c-wrx8-g8wh/GHSA-2w4c-wrx8-g8wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2w4c-wrx8-g8wh", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:42Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2593" diff --git a/advisories/unreviewed/2024/03/GHSA-7j4f-2m7v-2cjv/GHSA-7j4f-2m7v-2cjv.json b/advisories/unreviewed/2024/03/GHSA-7j4f-2m7v-2cjv/GHSA-7j4f-2m7v-2cjv.json index cff4cf7b0c3..ae2090c44be 100644 --- a/advisories/unreviewed/2024/03/GHSA-7j4f-2m7v-2cjv/GHSA-7j4f-2m7v-2cjv.json +++ b/advisories/unreviewed/2024/03/GHSA-7j4f-2m7v-2cjv/GHSA-7j4f-2m7v-2cjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7j4f-2m7v-2cjv", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:42Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2596" diff --git a/advisories/unreviewed/2024/03/GHSA-936g-q8pj-qjhp/GHSA-936g-q8pj-qjhp.json b/advisories/unreviewed/2024/03/GHSA-936g-q8pj-qjhp/GHSA-936g-q8pj-qjhp.json index 1e16a4718e1..5732507ed85 100644 --- a/advisories/unreviewed/2024/03/GHSA-936g-q8pj-qjhp/GHSA-936g-q8pj-qjhp.json +++ b/advisories/unreviewed/2024/03/GHSA-936g-q8pj-qjhp/GHSA-936g-q8pj-qjhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-936g-q8pj-qjhp", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:42Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2597" diff --git a/advisories/unreviewed/2024/03/GHSA-cgvh-9643-55w4/GHSA-cgvh-9643-55w4.json b/advisories/unreviewed/2024/03/GHSA-cgvh-9643-55w4/GHSA-cgvh-9643-55w4.json index b5c533868c1..e52e789073b 100644 --- a/advisories/unreviewed/2024/03/GHSA-cgvh-9643-55w4/GHSA-cgvh-9643-55w4.json +++ b/advisories/unreviewed/2024/03/GHSA-cgvh-9643-55w4/GHSA-cgvh-9643-55w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvh-9643-55w4", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:41Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2590" diff --git a/advisories/unreviewed/2024/03/GHSA-g9rx-gc8h-mpjj/GHSA-g9rx-gc8h-mpjj.json b/advisories/unreviewed/2024/03/GHSA-g9rx-gc8h-mpjj/GHSA-g9rx-gc8h-mpjj.json index 363e91e571b..effa8bea49a 100644 --- a/advisories/unreviewed/2024/03/GHSA-g9rx-gc8h-mpjj/GHSA-g9rx-gc8h-mpjj.json +++ b/advisories/unreviewed/2024/03/GHSA-g9rx-gc8h-mpjj/GHSA-g9rx-gc8h-mpjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9rx-gc8h-mpjj", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:41Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2591" diff --git a/advisories/unreviewed/2024/03/GHSA-gp97-78rf-vw76/GHSA-gp97-78rf-vw76.json b/advisories/unreviewed/2024/03/GHSA-gp97-78rf-vw76/GHSA-gp97-78rf-vw76.json index dbcf41a9c25..1b9ea19fd64 100644 --- a/advisories/unreviewed/2024/03/GHSA-gp97-78rf-vw76/GHSA-gp97-78rf-vw76.json +++ b/advisories/unreviewed/2024/03/GHSA-gp97-78rf-vw76/GHSA-gp97-78rf-vw76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp97-78rf-vw76", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:42Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2595" diff --git a/advisories/unreviewed/2024/03/GHSA-wh3q-8jwf-qv4m/GHSA-wh3q-8jwf-qv4m.json b/advisories/unreviewed/2024/03/GHSA-wh3q-8jwf-qv4m/GHSA-wh3q-8jwf-qv4m.json index 1c97f88c4c0..3bb45b23b35 100644 --- a/advisories/unreviewed/2024/03/GHSA-wh3q-8jwf-qv4m/GHSA-wh3q-8jwf-qv4m.json +++ b/advisories/unreviewed/2024/03/GHSA-wh3q-8jwf-qv4m/GHSA-wh3q-8jwf-qv4m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wh3q-8jwf-qv4m", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:42Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2594" diff --git a/advisories/unreviewed/2024/03/GHSA-x8pf-qjr3-w5cf/GHSA-x8pf-qjr3-w5cf.json b/advisories/unreviewed/2024/03/GHSA-x8pf-qjr3-w5cf/GHSA-x8pf-qjr3-w5cf.json index fa206f69fcf..b4dc14ecc58 100644 --- a/advisories/unreviewed/2024/03/GHSA-x8pf-qjr3-w5cf/GHSA-x8pf-qjr3-w5cf.json +++ b/advisories/unreviewed/2024/03/GHSA-x8pf-qjr3-w5cf/GHSA-x8pf-qjr3-w5cf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8pf-qjr3-w5cf", - "modified": "2024-03-18T15:30:51Z", + "modified": "2025-04-17T21:30:43Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-2598" diff --git a/advisories/unreviewed/2025/04/GHSA-2ccc-6qjv-38cv/GHSA-2ccc-6qjv-38cv.json b/advisories/unreviewed/2025/04/GHSA-2ccc-6qjv-38cv/GHSA-2ccc-6qjv-38cv.json new file mode 100644 index 00000000000..772adb98b8a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2ccc-6qjv-38cv/GHSA-2ccc-6qjv-38cv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ccc-6qjv-38cv", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29449" + ], + "details": "An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29449" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/tawn9fxg1ggv1sdr" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cx7-5g5j-x648/GHSA-2cx7-5g5j-x648.json b/advisories/unreviewed/2025/04/GHSA-2cx7-5g5j-x648/GHSA-2cx7-5g5j-x648.json new file mode 100644 index 00000000000..c9fd17e6024 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cx7-5g5j-x648/GHSA-2cx7-5g5j-x648.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cx7-5g5j-x648", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49386" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw-nuss: Fix some refcount leaks\n\nof_get_child_by_name() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when not need anymore.\nam65_cpsw_init_cpts() and am65_cpsw_nuss_probe() don't release\nthe refcount in error case.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49386" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e44f21c384503562713b7d3b673c40bed20af3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dd89d2fc438457811cbbec07999ce0d80051ff5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78aca10a16f001c9f49f1cc4dadfee8d444bb173" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4b7ef3b159805ba6be061d0cd2403d84b9b0063" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7ba2cc57f404d2d9f26fb85bd3833d35a477829" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json b/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json index ef90c33dbe9..d3124675e96 100644 --- a/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json +++ b/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2pq8-4rf3-3vh9", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-17T21:31:03Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2025-29181" ], "details": "FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json b/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json index 268c3cc5f47..45501e4621e 100644 --- a/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json +++ b/advisories/unreviewed/2025/04/GHSA-2qvw-44pq-38xj/GHSA-2qvw-44pq-38xj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qvw-44pq-38xj", - "modified": "2025-04-17T06:30:35Z", + "modified": "2025-04-17T21:30:54Z", "published": "2025-04-17T06:30:35Z", "aliases": [ "CVE-2025-1525" ], "details": "The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json b/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json new file mode 100644 index 00000000000..38861d1f568 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3c8w-xm49-2w5f/GHSA-3c8w-xm49-2w5f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c8w-xm49-2w5f", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29452" + ], + "details": "An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29452" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/dsvvsv8get5i2dzg" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-44p4-ww39-jj4m/GHSA-44p4-ww39-jj4m.json b/advisories/unreviewed/2025/04/GHSA-44p4-ww39-jj4m/GHSA-44p4-ww39-jj4m.json index be6c7668161..759e7d66730 100644 --- a/advisories/unreviewed/2025/04/GHSA-44p4-ww39-jj4m/GHSA-44p4-ww39-jj4m.json +++ b/advisories/unreviewed/2025/04/GHSA-44p4-ww39-jj4m/GHSA-44p4-ww39-jj4m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44p4-ww39-jj4m", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-17T21:30:44Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-1292" ], "details": "Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and \nbypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4h6g-wfmr-qvjh/GHSA-4h6g-wfmr-qvjh.json b/advisories/unreviewed/2025/04/GHSA-4h6g-wfmr-qvjh/GHSA-4h6g-wfmr-qvjh.json new file mode 100644 index 00000000000..3990e81f130 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4h6g-wfmr-qvjh/GHSA-4h6g-wfmr-qvjh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h6g-wfmr-qvjh", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-3762" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component MPUT Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3762" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-8d31b9e55c1c3d8f2cbf62e3e218f50b.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305396" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305396" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553567" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T19:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json b/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json index 824cb0f0142..a9012c24023 100644 --- a/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json +++ b/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4mpp-jp65-h4rw", - "modified": "2025-04-17T06:30:35Z", + "modified": "2025-04-17T21:30:54Z", "published": "2025-04-17T06:30:35Z", "aliases": [ "CVE-2025-1523" ], "details": "The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5p33-cx2m-4x9v/GHSA-5p33-cx2m-4x9v.json b/advisories/unreviewed/2025/04/GHSA-5p33-cx2m-4x9v/GHSA-5p33-cx2m-4x9v.json new file mode 100644 index 00000000000..9cbe17b1df9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5p33-cx2m-4x9v/GHSA-5p33-cx2m-4x9v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p33-cx2m-4x9v", + "modified": "2025-04-17T21:30:43Z", + "published": "2025-04-17T21:30:43Z", + "aliases": [ + "CVE-2022-49384" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: fix double free of io_acct_set bioset\n\nNow io_acct_set is alloc and free in personality. Remove the codes that\nfree io_acct_set in md_free and md_stop.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49384" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36a2fc44c574a59ee3b5e2cb327182f227b2b07e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42b805af102471f53e3c7867b8c2b502ea4eef7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea7d7bd90079d96f9c86bdaf0b106e0cd2a70661" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f99d5b5dc8a42c807b5f1176b925aa45d61962ab" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json b/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json new file mode 100644 index 00000000000..3a2ffd1823c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-62c2-pjmr-4wx5/GHSA-62c2-pjmr-4wx5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62c2-pjmr-4wx5", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29451" + ], + "details": "An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29451" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/xd2v1fxmoopgrfm7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json b/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json index fcfca0386e6..fef32fe70b7 100644 --- a/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json +++ b/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-677p-h2hj-9j82", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2021-47669" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: vxcan: vxcan_xmit: fix use after free bug\n\nAfter calling netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the canfd_frame cfd which aliases skb memory is accessed\nafter the netif_rx_ni().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json b/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json index b7ef802d394..ede2a026485 100644 --- a/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json +++ b/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78xp-xvw2-6rw6", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-17T21:31:03Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2021-47668" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_restart: fix use after free bug\n\nAfter calling netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the netif_rx_ni() in:\n stats->rx_bytes += cf->len;\n\nReordering the lines solves the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json b/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json index 6b552bf05c4..9ff6bc8058e 100644 --- a/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json +++ b/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json b/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json index ea4b479e97c..5196157f14a 100644 --- a/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json +++ b/advisories/unreviewed/2025/04/GHSA-7hqv-m3mr-cv2v/GHSA-7hqv-m3mr-cv2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hqv-m3mr-cv2v", - "modified": "2025-04-17T15:32:36Z", + "modified": "2025-04-17T21:30:54Z", "published": "2025-04-17T15:32:36Z", "aliases": [ "CVE-2025-25234" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-942" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7vw9-hmx7-h29g/GHSA-7vw9-hmx7-h29g.json b/advisories/unreviewed/2025/04/GHSA-7vw9-hmx7-h29g/GHSA-7vw9-hmx7-h29g.json new file mode 100644 index 00000000000..c97b1a6a796 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7vw9-hmx7-h29g/GHSA-7vw9-hmx7-h29g.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vw9-hmx7-h29g", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49410" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix potential double free in create_var_ref()\n\nIn create_var_ref(), init_var_ref() is called to initialize the fields\nof variable ref_field, which is allocated in the previous function call\nto create_hist_field(). Function init_var_ref() allocates the\ncorresponding fields such as ref_field->system, but frees these fields\nwhen the function encounters an error. The caller later calls\ndestroy_hist_field() to conduct error handling, which frees the fields\nand the variable itself. This results in double free of the fields which\nare already freed in the previous function.\n\nFix this by storing NULL to the corresponding fields when they are freed\nin init_var_ref().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49410" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/058cb6d86b9789377216c936506b346aaa1eb581" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37443b3508b8cce6832f8d25cb4550b2f7801f50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4fdfb15e08598711dbf50daf56a33965232daf0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99696a2592bca641eb88cc9a80c90e591afebd0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd83ff3bbfb003832481c9bff999d12385f396ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c27f744ceefadc7bbeb14233b6abc150ced617d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8b383f83cb573152c577eca1ef101e89995b72a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json b/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json index 75f2e39012d..12a9c43202c 100644 --- a/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json +++ b/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-848p-384j-r4fv", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2025-29722" ], "details": "A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-89vx-8j4r-pm86/GHSA-89vx-8j4r-pm86.json b/advisories/unreviewed/2025/04/GHSA-89vx-8j4r-pm86/GHSA-89vx-8j4r-pm86.json new file mode 100644 index 00000000000..2e9aa66f803 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89vx-8j4r-pm86/GHSA-89vx-8j4r-pm86.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vx-8j4r-pm86", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49391" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: mtk_scp: Fix a potential double free\n\n'scp->rproc' is allocated using devm_rproc_alloc(), so there is no need\nto free it explicitly in the remove function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49391" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adc02700236613b344a947a897fc2741d52a43b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eac3e5b1c12f85732e60f5f8b985444d273866bb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json b/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json new file mode 100644 index 00000000000..96266ea71de --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rrr-w669-26rg", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29454" + ], + "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29454" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/cyql4n0xiubspntl" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json b/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json index 6adfec3664c..c61751bf35c 100644 --- a/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json +++ b/advisories/unreviewed/2025/04/GHSA-9fw4-p66g-p3hh/GHSA-9fw4-p66g-p3hh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fw4-p66g-p3hh", - "modified": "2025-04-17T06:30:35Z", + "modified": "2025-04-17T21:30:54Z", "published": "2025-04-17T06:30:35Z", "aliases": [ "CVE-2025-1524" ], "details": "The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json b/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json index 28dafb7d2e5..087e6ad8db1 100644 --- a/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json +++ b/advisories/unreviewed/2025/04/GHSA-cj26-58c8-7wq6/GHSA-cj26-58c8-7wq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj26-58c8-7wq6", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-17T21:30:49Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2025-3736" ], "details": "Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cp2p-wmjj-5m7m/GHSA-cp2p-wmjj-5m7m.json b/advisories/unreviewed/2025/04/GHSA-cp2p-wmjj-5m7m/GHSA-cp2p-wmjj-5m7m.json new file mode 100644 index 00000000000..8782eeeb582 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cp2p-wmjj-5m7m/GHSA-cp2p-wmjj-5m7m.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp2p-wmjj-5m7m", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49389" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbip: fix a refcount leak in stub_probe()\n\nusb_get_dev() is called in stub_device_alloc(). When stub_probe() fails\nafter that, usb_put_dev() needs to be called to release the reference.\n\nFix this by moving usb_put_dev() to sdev_free error path handling.\n\nFind this by code review.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49389" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11c65408bd0ba1d9cd1307caa38169292de9cdfb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/247d3809e45a34d9e1a3a2bb7012e31ed8b46031" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f0ae93ec33c8456cdfbf7876b80403a6318ebce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51422046be504515eb5a591adf0f424b62f46804" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bafee2f18af5e5ac125e42960bc65496d0e56a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8afb048800919d0ab10c57983940eba956339f21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ec4cbf1cc55d126759051acfe328d489c5d6e60" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcbb795a9e78180d74c6ab21518da87e803dfdce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f20d2d3b3364ce6525c050a8b6b4c54c8c19674d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json b/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json index 2b5d3cb95a3..aa61baea77a 100644 --- a/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json +++ b/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fgr8-gcxj-6pq5", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2021-47671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path\n\nIn es58x_rx_err_msg(), if can->do_set_mode() fails, the function\ndirectly returns without calling netif_rx(skb). This means that the\nskb previously allocated by alloc_can_err_skb() is not freed. In other\nterms, this is a memory leak.\n\nThis patch simply removes the return statement in the error branch and\nlet the function continue.\n\nIssue was found with GCC -fanalyzer, please follow the link below for\ndetails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json b/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json new file mode 100644 index 00000000000..8665664f448 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhm7-xr45-vvhp/GHSA-fhm7-xr45-vvhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhm7-xr45-vvhp", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2024-42177" + ], + "details": "HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the weakness in the ciphers to intercept and decrypt encrypted data, steal sensitive information, or inject malicious code into the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42177" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120504" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json b/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json index 217e5e6f7e7..555adce2eb0 100644 --- a/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json +++ b/advisories/unreviewed/2025/04/GHSA-fvqg-wm9j-4gc4/GHSA-fvqg-wm9j-4gc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvqg-wm9j-4gc4", - "modified": "2025-04-16T18:31:51Z", + "modified": "2025-04-17T21:30:49Z", "published": "2025-04-16T18:31:51Z", "aliases": [ "CVE-2024-40069" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json b/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json index 590e51fa3ef..298eb4c5629 100644 --- a/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json +++ b/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3pp-67rc-cjg2", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2021-47670" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: fix use after free bugs\n\nAfter calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the peak_usb_netif_rx_ni().\n\nReordering the lines solves the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json b/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json index c98dce381c7..4901b796d42 100644 --- a/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json +++ b/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g67h-7m25-7mmv", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-17T21:31:03Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2025-29039" ], "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json b/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json index 8ce1077645c..f8040af07ab 100644 --- a/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json +++ b/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g8r8-g7qx-p4c7", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2025-28009" ], "details": "A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gvc3-q38f-h355/GHSA-gvc3-q38f-h355.json b/advisories/unreviewed/2025/04/GHSA-gvc3-q38f-h355/GHSA-gvc3-q38f-h355.json new file mode 100644 index 00000000000..0416421abe8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gvc3-q38f-h355/GHSA-gvc3-q38f-h355.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvc3-q38f-h355", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:43Z", + "aliases": [ + "CVE-2022-49382" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: rockchip: Fix refcount leak in rockchip_grf_init\n\nof_find_matching_node_and_match returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49382" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/042571fe1d171773655ad706715ecc865913d9a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28133325526b92921f3269fdf97a20d90b92b217" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b3e990f85eb034faa461e691e719e8ce9e2a3c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69a30b2ed620c2206cbbd1e9c112e4fc584e02bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f64e84924604bb969ee1fbc4b8d7d09b9214889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b59588d8be91c96bfb0371e912ceb4f16315dbf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aab25b669cb9fd3698c2631be4435f4fe92d9e59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5422f323858cad3ac3581075f9a3a5e0d41c0d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json b/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json new file mode 100644 index 00000000000..9147f8c2c76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9c2-qf4j-fhfg", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-3764" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /edit-product.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3764" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/upload_in_edit-product.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305398" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305398" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553721" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json b/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json index 5f8d3a7b330..d4d1d6ba5d6 100644 --- a/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json +++ b/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hr94-jx6q-7pcg", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-17T21:31:03Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2025-29661" ], "details": "Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j793-r5pf-7w34/GHSA-j793-r5pf-7w34.json b/advisories/unreviewed/2025/04/GHSA-j793-r5pf-7w34/GHSA-j793-r5pf-7w34.json new file mode 100644 index 00000000000..bf844a2647d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j793-r5pf-7w34/GHSA-j793-r5pf-7w34.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j793-r5pf-7w34", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49408" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix memory leak in parse_apply_sb_mount_options()\n\nIf processing the on-disk mount options fails after any memory was\nallocated in the ext4_fs_context, e.g. s_qf_names, then this memory is\nleaked. Fix this by calling ext4_fc_free() instead of kfree() directly.\n\nReproducer:\n\n mkfs.ext4 -F /dev/vdc\n tune2fs /dev/vdc -E mount_opts=usrjquota=file\n echo clear > /sys/kernel/debug/kmemleak\n mount /dev/vdc /vdc\n echo scan > /sys/kernel/debug/kmemleak\n sleep 5\n echo scan > /sys/kernel/debug/kmemleak\n cat /sys/kernel/debug/kmemleak", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49408" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ea3e6168948189cec31d0678d2b55b395f88491" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c069db76ed7b681c69159f44be96d2137e9ca989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f92ded66e9d0aa20b883a2a5183973abc8f41815" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j93w-j7jm-5c8h/GHSA-j93w-j7jm-5c8h.json b/advisories/unreviewed/2025/04/GHSA-j93w-j7jm-5c8h/GHSA-j93w-j7jm-5c8h.json index dabdf1930a3..ee3c42ad580 100644 --- a/advisories/unreviewed/2025/04/GHSA-j93w-j7jm-5c8h/GHSA-j93w-j7jm-5c8h.json +++ b/advisories/unreviewed/2025/04/GHSA-j93w-j7jm-5c8h/GHSA-j93w-j7jm-5c8h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j93w-j7jm-5c8h", - "modified": "2025-04-15T21:31:43Z", + "modified": "2025-04-17T21:30:44Z", "published": "2025-04-15T21:31:43Z", "aliases": [ "CVE-2025-1122" ], "details": "Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and \nbypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json b/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json index d333b24a8a0..6d44c9bac83 100644 --- a/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json +++ b/advisories/unreviewed/2025/04/GHSA-jfph-3485-2gcv/GHSA-jfph-3485-2gcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jfph-3485-2gcv", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-17T21:30:49Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2025-3735" ], "details": "Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jh67-7rhf-7vg4/GHSA-jh67-7rhf-7vg4.json b/advisories/unreviewed/2025/04/GHSA-jh67-7rhf-7vg4/GHSA-jh67-7rhf-7vg4.json new file mode 100644 index 00000000000..7ed5847fc8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jh67-7rhf-7vg4/GHSA-jh67-7rhf-7vg4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh67-7rhf-7vg4", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49414" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix race condition between ext4_write and ext4_convert_inline_data\n\nHulk Robot reported a BUG_ON:\n ==================================================================\n EXT4-fs error (device loop3): ext4_mb_generate_buddy:805: group 0,\n block bitmap and bg descriptor inconsistent: 25 vs 31513 free clusters\n kernel BUG at fs/ext4/ext4_jbd2.c:53!\n invalid opcode: 0000 [#1] SMP KASAN PTI\n CPU: 0 PID: 25371 Comm: syz-executor.3 Not tainted 5.10.0+ #1\n RIP: 0010:ext4_put_nojournal fs/ext4/ext4_jbd2.c:53 [inline]\n RIP: 0010:__ext4_journal_stop+0x10e/0x110 fs/ext4/ext4_jbd2.c:116\n [...]\n Call Trace:\n ext4_write_inline_data_end+0x59a/0x730 fs/ext4/inline.c:795\n generic_perform_write+0x279/0x3c0 mm/filemap.c:3344\n ext4_buffered_write_iter+0x2e3/0x3d0 fs/ext4/file.c:270\n ext4_file_write_iter+0x30a/0x11c0 fs/ext4/file.c:520\n do_iter_readv_writev+0x339/0x3c0 fs/read_write.c:732\n do_iter_write+0x107/0x430 fs/read_write.c:861\n vfs_writev fs/read_write.c:934 [inline]\n do_pwritev+0x1e5/0x380 fs/read_write.c:1031\n [...]\n ==================================================================\n\nAbove issue may happen as follows:\n cpu1 cpu2\n__________________________|__________________________\ndo_pwritev\n vfs_writev\n do_iter_write\n ext4_file_write_iter\n ext4_buffered_write_iter\n generic_perform_write\n ext4_da_write_begin\n vfs_fallocate\n ext4_fallocate\n ext4_convert_inline_data\n ext4_convert_inline_data_nolock\n ext4_destroy_inline_data_nolock\n clear EXT4_STATE_MAY_INLINE_DATA\n ext4_map_blocks\n ext4_ext_map_blocks\n ext4_mb_new_blocks\n ext4_mb_regular_allocator\n ext4_mb_good_group_nolock\n ext4_mb_init_group\n ext4_mb_init_cache\n ext4_mb_generate_buddy --> error\n ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA)\n ext4_restore_inline_data\n set EXT4_STATE_MAY_INLINE_DATA\n ext4_block_write_begin\n ext4_da_write_end\n ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA)\n ext4_write_inline_data_end\n handle=NULL\n ext4_journal_stop(handle)\n __ext4_journal_stop\n ext4_put_nojournal(handle)\n ref_cnt = (unsigned long)handle\n BUG_ON(ref_cnt == 0) ---> BUG_ON\n\nThe lock held by ext4_convert_inline_data is xattr_sem, but the lock\nheld by generic_perform_write is i_rwsem. Therefore, the two locks can\nbe concurrent.\n\nTo solve above issue, we add inode_lock() for ext4_convert_inline_data().\nAt the same time, move ext4_convert_inline_data() in front of\next4_punch_hole(), remove similar handling from ext4_punch_hole().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49414" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14602353b350950b551eccc6b46411aa3b12ffe2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18881d7e517169193d9ef6c89c7f322e3e164277" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/725e00cb7039eae291890f1bb19bc867176745f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91f90b571f1a23f5b8a9c2b68a9aa5d6981a3c3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccc6639f831bee91aa8b41c8a1cdd020ecfb9f32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f87c7a4b084afc13190cbb263538e444cb2b392a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jv9h-q2w4-vg83/GHSA-jv9h-q2w4-vg83.json b/advisories/unreviewed/2025/04/GHSA-jv9h-q2w4-vg83/GHSA-jv9h-q2w4-vg83.json new file mode 100644 index 00000000000..84ee4901edd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jv9h-q2w4-vg83/GHSA-jv9h-q2w4-vg83.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv9h-q2w4-vg83", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-3763" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the function main of the component Password Handler. The manipulation of the argument s leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3763" + }, + { + "type": "WEB", + "url": "https://github.com/eeeee-vul/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305397" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305397" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553650" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T19:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m46p-v6c6-2xv2/GHSA-m46p-v6c6-2xv2.json b/advisories/unreviewed/2025/04/GHSA-m46p-v6c6-2xv2/GHSA-m46p-v6c6-2xv2.json new file mode 100644 index 00000000000..b60fc94fc51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m46p-v6c6-2xv2/GHSA-m46p-v6c6-2xv2.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m46p-v6c6-2xv2", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49400" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: Don't set mddev private to NULL in raid0 pers->free\n\nIn normal stop process, it does like this:\n do_md_stop\n |\n __md_stop (pers->free(); mddev->private=NULL)\n |\n md_free (free mddev)\n__md_stop sets mddev->private to NULL after pers->free. The raid device\nwill be stopped and mddev memory is free. But in reshape, it doesn't\nfree the mddev and mddev will still be used in new raid.\n\nIn reshape, it first sets mddev->private to new_pers and then runs\nold_pers->free(). Now raid0 sets mddev->private to NULL in raid0_free.\nThe new raid can't work anymore. It will panic when dereference\nmddev->private because of NULL pointer dereference.\n\nIt can panic like this:\n[63010.814972] kernel BUG at drivers/md/raid10.c:928!\n[63010.819778] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[63010.825011] CPU: 3 PID: 44437 Comm: md0_resync Kdump: loaded Not tainted 5.14.0-86.el9.x86_64 #1\n[63010.833789] Hardware name: Dell Inc. PowerEdge R6415/07YXFK, BIOS 1.15.0 09/11/2020\n[63010.841440] RIP: 0010:raise_barrier+0x161/0x170 [raid10]\n[63010.865508] RSP: 0018:ffffc312408bbc10 EFLAGS: 00010246\n[63010.870734] RAX: 0000000000000000 RBX: ffffa00bf7d39800 RCX: 0000000000000000\n[63010.877866] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffa00bf7d39800\n[63010.884999] RBP: 0000000000000000 R08: fffffa4945e74400 R09: 0000000000000000\n[63010.892132] R10: ffffa00eed02f798 R11: 0000000000000000 R12: ffffa00bbc435200\n[63010.899266] R13: ffffa00bf7d39800 R14: 0000000000000400 R15: 0000000000000003\n[63010.906399] FS: 0000000000000000(0000) GS:ffffa00eed000000(0000) knlGS:0000000000000000\n[63010.914485] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[63010.920229] CR2: 00007f5cfbe99828 CR3: 0000000105efe000 CR4: 00000000003506e0\n[63010.927363] Call Trace:\n[63010.929822] ? bio_reset+0xe/0x40\n[63010.933144] ? raid10_alloc_init_r10buf+0x60/0xa0 [raid10]\n[63010.938629] raid10_sync_request+0x756/0x1610 [raid10]\n[63010.943770] md_do_sync.cold+0x3e4/0x94c\n[63010.947698] md_thread+0xab/0x160\n[63010.951024] ? md_write_inc+0x50/0x50\n[63010.954688] kthread+0x149/0x170\n[63010.957923] ? set_kthread_struct+0x40/0x40\n[63010.962107] ret_from_fork+0x22/0x30\n\nRemoving the code that sets mddev->private to NULL in raid0 can fix\nproblem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49400" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f2571ad7a30ff6b33cde142439f9378669f8b4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7da3454a65f8a56e65dfb44fa0ccac08cbc2f5a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7a51df785031cc49caf1c59766ca89cfa97b54b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f63fd1e0e0fc158023cc67ea6a07e278019061ba" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json b/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json index 5135d7a7260..425c410746c 100644 --- a/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json +++ b/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p84q-ch5j-7frh", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-17T21:31:04Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2024-55211" ], "details": "An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-565" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pxwr-cc58-gq3m/GHSA-pxwr-cc58-gq3m.json b/advisories/unreviewed/2025/04/GHSA-pxwr-cc58-gq3m/GHSA-pxwr-cc58-gq3m.json new file mode 100644 index 00000000000..e3d8861d57b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pxwr-cc58-gq3m/GHSA-pxwr-cc58-gq3m.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxwr-cc58-gq3m", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49395" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\num: Fix out-of-bounds read in LDT setup\n\nsyscall_stub_data() expects the data_count parameter to be the number of\nlongs, not bytes.\n\n ==================================================================\n BUG: KASAN: stack-out-of-bounds in syscall_stub_data+0x70/0xe0\n Read of size 128 at addr 000000006411f6f0 by task swapper/1\n\n CPU: 0 PID: 1 Comm: swapper Not tainted 5.18.0+ #18\n Call Trace:\n show_stack.cold+0x166/0x2a7\n __dump_stack+0x3a/0x43\n dump_stack_lvl+0x1f/0x27\n print_report.cold+0xdb/0xf81\n kasan_report+0x119/0x1f0\n kasan_check_range+0x3a3/0x440\n memcpy+0x52/0x140\n syscall_stub_data+0x70/0xe0\n write_ldt_entry+0xac/0x190\n init_new_ldt+0x515/0x960\n init_new_context+0x2c4/0x4d0\n mm_init.constprop.0+0x5ed/0x760\n mm_alloc+0x118/0x170\n 0x60033f48\n do_one_initcall+0x1d7/0x860\n 0x60003e7b\n kernel_init+0x6e/0x3d4\n new_thread_handler+0x1e7/0x2c0\n\n The buggy address belongs to stack of task swapper/1\n and is located at offset 64 in frame:\n init_new_ldt+0x0/0x960\n\n This frame has 2 objects:\n [32, 40) 'addr'\n [64, 80) 'desc'\n ==================================================================", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49395" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10995a382271254bd276627ec74136da4a23c4a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24ca648bf5f72ed8878cf09b5d4431935779681e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a4a62a14be1947fa945c5c11ebf67326381a568" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3549ab4b962cf619e8c55484a0d870a34b3f845f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/668ca34a428d6ffc0f99a1a6a9b661a288d4183b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91e5ba2af2d729d5126aefd5aa3eadc69b8426e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9caad70819aef3431abaf73ba5163b55b161aba0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf0dabc37446c5ee538ae7b4c467ab0e53fa5463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef1dc929a1e5fa1b2d842256db9fb8710d3be910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json b/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json index e84b1915adf..fd2c0d300b0 100644 --- a/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json +++ b/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q8hq-xhpc-vm95", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-17T21:31:03Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2025-29180" ], "details": "In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r527-4r6f-fjr3/GHSA-r527-4r6f-fjr3.json b/advisories/unreviewed/2025/04/GHSA-r527-4r6f-fjr3/GHSA-r527-4r6f-fjr3.json new file mode 100644 index 00000000000..326e03b946a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r527-4r6f-fjr3/GHSA-r527-4r6f-fjr3.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r527-4r6f-fjr3", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49392" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_aspeed_vuart: Fix potential NULL dereference in aspeed_vuart_probe\n\nplatform_get_resource() may fail and return NULL, so we should\nbetter check it's return value to avoid a NULL pointer dereference.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49392" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e0fd55719fa081de6f9e5d9e6cef48efb04d34a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90a6b6fc52bfdcfe9698454bf5bea26112abbcd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/923d34ce069e8e51a4d003caa6b66a8cd6ecd0ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5f1275f101e0e8a172d300d897f5a12e87e3485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json b/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json new file mode 100644 index 00000000000..c89ea74e6d6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6p8-wxvj-85qw", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-3765" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3765" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/upload_in_edit-photo.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305399" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305399" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553722" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rjm4-6mrc-mh44/GHSA-rjm4-6mrc-mh44.json b/advisories/unreviewed/2025/04/GHSA-rjm4-6mrc-mh44/GHSA-rjm4-6mrc-mh44.json index 7c9433f7fda..d7a3e02df9a 100644 --- a/advisories/unreviewed/2025/04/GHSA-rjm4-6mrc-mh44/GHSA-rjm4-6mrc-mh44.json +++ b/advisories/unreviewed/2025/04/GHSA-rjm4-6mrc-mh44/GHSA-rjm4-6mrc-mh44.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json b/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json index ee426780e49..84d55da250e 100644 --- a/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json +++ b/advisories/unreviewed/2025/04/GHSA-v3r6-268x-w57p/GHSA-v3r6-268x-w57p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3r6-268x-w57p", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-17T21:30:49Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2025-3737" ], "details": "Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v76p-9ff9-f29g/GHSA-v76p-9ff9-f29g.json b/advisories/unreviewed/2025/04/GHSA-v76p-9ff9-f29g/GHSA-v76p-9ff9-f29g.json new file mode 100644 index 00000000000..9d42d08b83d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v76p-9ff9-f29g/GHSA-v76p-9ff9-f29g.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v76p-9ff9-f29g", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49403" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/string_helpers: fix not adding strarray to device's resource list\n\nAdd allocated strarray to device's resource list. This is a must to\nautomatically release strarray when the device disappears.\n\nWithout this fix we have a memory leak in the few drivers which use\ndevm_kasprintf_strarray().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49403" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a152eb42fcecfe41239c3c6695342f3a128593e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf29edab0c9ff3d2633b8306a67d04c357e2a385" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd290a9839cee2f6641558877e707bd373c8f6f1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json b/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json index 976f78943fc..4dbe239b09b 100644 --- a/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json +++ b/advisories/unreviewed/2025/04/GHSA-w22f-9vp5-hh8q/GHSA-w22f-9vp5-hh8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w22f-9vp5-hh8q", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-17T21:30:49Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2025-3738" ], "details": "Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wf73-fprx-hxjj/GHSA-wf73-fprx-hxjj.json b/advisories/unreviewed/2025/04/GHSA-wf73-fprx-hxjj/GHSA-wf73-fprx-hxjj.json new file mode 100644 index 00000000000..cc31fcf8fd8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wf73-fprx-hxjj/GHSA-wf73-fprx-hxjj.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf73-fprx-hxjj", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49404" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hfi1: Fix potential integer multiplication overflow errors\n\nWhen multiplying of different types, an overflow is possible even when\nstoring the result in a larger type. This is because the conversion is\ndone after the multiplication. So arithmetic overflow and thus in\nincorrect value is possible.\n\nCorrect an instance of this in the inter packet delay calculation. Fix by\nensuring one of the operands is u64 which will promote the other to u64 as\nwell ensuring no overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49404" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06039d8afefdbac05bcea5f397188407eba2996d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/252f4afd4557a2e7075f793a5c80fe6dd9e9ee4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31dca00d0cc9f4133320d72eb7e3720badc6d6e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f09ec80f115d2875d747ed28adc1773037e0f8b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79c164e61f818054cd6012e9035701840d895c51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8858284dd74906fa00f04f0252c75df4893a7959" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a89cb7ddf6a89bab6012e19da38b7cdb26175c19" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef5ab2e48a5f9960e2352332b7cdb7064bb49032" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f93e91a0372c922c20d5bee260b0f43b4b8a1bee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json b/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json new file mode 100644 index 00000000000..7a4c05ed8e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wgwq-2crv-c4jj/GHSA-wgwq-2crv-c4jj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgwq-2crv-c4jj", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:04Z", + "aliases": [ + "CVE-2025-29316" + ], + "details": "An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29316" + }, + { + "type": "WEB", + "url": "https://app.filemail.com/d/fjyvgdkchxdzefl" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Donsat12/c9295859e6f7ce406b787ded72701ea4?short_path=0e57ef8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T19:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wpf2-5j53-3cxv/GHSA-wpf2-5j53-3cxv.json b/advisories/unreviewed/2025/04/GHSA-wpf2-5j53-3cxv/GHSA-wpf2-5j53-3cxv.json new file mode 100644 index 00000000000..70c35afde82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wpf2-5j53-3cxv/GHSA-wpf2-5j53-3cxv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpf2-5j53-3cxv", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29450" + ], + "details": "An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29450" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/ftlzvxve3t5713c6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x3v3-vr8q-m495/GHSA-x3v3-vr8q-m495.json b/advisories/unreviewed/2025/04/GHSA-x3v3-vr8q-m495/GHSA-x3v3-vr8q-m495.json new file mode 100644 index 00000000000..6e8fcdee69b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x3v3-vr8q-m495/GHSA-x3v3-vr8q-m495.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3v3-vr8q-m495", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:43Z", + "aliases": [ + "CVE-2022-49387" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: rzg2l_wdt: Fix 32bit overflow issue\n\nThe value of timer_cycle_us can be 0 due to 32bit overflow.\nFor eg:- If we assign the counter value \"0xfff\" for computing\nmaxval.\n\nThis patch fixes this issue by appending ULL to 1024, so that\nit is promoted to 64bit.\n\nThis patch also fixes the warning message, 'watchdog: Invalid min and\nmax timeout values, resetting to 0!'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49387" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b95a47667d34e76c2c9013f8e3b1e5039a5a0b76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e07b9fa0dc32b492de85528caaf9f0c605d8424f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea2949df22a533cdf75e4583c00b1ce94cd5a83b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x74c-mr6j-xgx9/GHSA-x74c-mr6j-xgx9.json b/advisories/unreviewed/2025/04/GHSA-x74c-mr6j-xgx9/GHSA-x74c-mr6j-xgx9.json new file mode 100644 index 00000000000..84ec0c87d98 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x74c-mr6j-xgx9/GHSA-x74c-mr6j-xgx9.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74c-mr6j-xgx9", + "modified": "2025-04-17T21:30:44Z", + "published": "2025-04-17T21:30:44Z", + "aliases": [ + "CVE-2022-49406" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix potential deadlock in blk_ia_range_sysfs_show()\n\nWhen being read, a sysfs attribute is already protected against removal\nwith the kobject node active reference counter. As a result, in\nblk_ia_range_sysfs_show(), there is no need to take the queue sysfs\nlock when reading the value of a range attribute. Using the queue sysfs\nlock in this function creates a potential deadlock situation with the\ndisk removal, something that a lockdep signals with a splat when the\ndevice is removed:\n\n[ 760.703551] Possible unsafe locking scenario:\n[ 760.703551]\n[ 760.703554] CPU0 CPU1\n[ 760.703556] ---- ----\n[ 760.703558] lock(&q->sysfs_lock);\n[ 760.703565] lock(kn->active#385);\n[ 760.703573] lock(&q->sysfs_lock);\n[ 760.703579] lock(kn->active#385);\n[ 760.703587]\n[ 760.703587] *** DEADLOCK ***\n\nSolve this by removing the mutex_lock()/mutex_unlock() calls from\nblk_ia_range_sysfs_show().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49406" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41e46b3c2aa24f755b2ae9ec4ce931ba5f0d8532" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/717b078bc745ba9a262abebed9806a17e8bbb77b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc107c805cde709866b59867ef72b9390199205e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json b/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json index 12e7bc1accc..2b1a158b9bf 100644 --- a/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json +++ b/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json b/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json new file mode 100644 index 00000000000..ecc20720b24 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw3g-f28m-3q7j", + "modified": "2025-04-17T21:31:05Z", + "published": "2025-04-17T21:31:05Z", + "aliases": [ + "CVE-2025-29455" + ], + "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas\" function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29455" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/hfonnxwggi2kfgmw" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T21:15:50Z" + } +} \ No newline at end of file