From 5e7ef022c7013806ba75fe62478efcaad0f322f2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Feb 2025 18:32:18 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gm4m-9rm8-7rxj.json | 122 ++++++++++++++++++ .../GHSA-cjqx-m2ff-vgj5.json | 22 +++- .../GHSA-gm4m-9rm8-7rxj.json | 36 ------ .../GHSA-225v-7693-56j3.json | 2 +- .../GHSA-2jqf-9377-3hhp.json | 4 +- .../GHSA-3gqh-xgpm-cfvx.json | 2 +- .../GHSA-47pw-3g2g-9xj2.json | 6 +- .../GHSA-4g4v-5cg8-c9g6.json | 2 +- .../GHSA-4j6m-cxx4-9x6q.json | 6 +- .../GHSA-4mqf-c682-rprp.json | 1 + .../GHSA-64x6-jjx3-6ggh.json | 6 +- .../GHSA-6cv9-9p4c-38fq.json | 6 +- .../GHSA-7mgx-8745-58vp.json | 4 +- .../GHSA-7v8p-3ffx-7rjc.json | 6 +- .../GHSA-8v5j-pwr7-w5f8.json | 2 +- .../GHSA-8v94-jg2x-f3vr.json | 6 +- .../GHSA-9f7g-gqwh-jpf5.json | 2 +- .../GHSA-h7xj-xr99-gpjr.json | 6 +- .../GHSA-jxf3-h258-gvf9.json | 14 +- .../GHSA-m76f-5v6g-6jmr.json | 2 +- .../GHSA-r3h7-cpq4-j5rr.json | 6 +- .../GHSA-rj3h-7prw-4qqr.json | 2 +- .../GHSA-v46r-626m-f3pp.json | 4 +- .../GHSA-v4m2-x4rp-hv22.json | 6 +- .../GHSA-vg73-w7ww-xm56.json | 6 +- .../GHSA-wr4w-95gx-6cfr.json | 4 +- .../GHSA-x3pf-j9xx-29g6.json | 4 +- .../GHSA-99jh-9v4f-3xmf.json | 4 +- .../GHSA-2vp2-4cqw-xhcc.json | 4 +- .../GHSA-cgpg-xpvx-xqxj.json | 11 +- .../GHSA-cwpg-8775-j56v.json | 8 +- .../GHSA-vw87-wrx2-xwxq.json | 1 + .../GHSA-xhg6-78jc-3cwf.json | 7 +- .../GHSA-g82j-wprp-q9q9.json | 4 +- .../GHSA-p8rh-53x8-6ww5.json | 4 +- .../GHSA-xh5q-pch5-g3xq.json | 10 +- .../GHSA-22qj-f25c-22mc.json | 40 ++++++ .../GHSA-24fj-mqgp-74gr.json | 56 ++++++++ .../GHSA-257h-84mq-c7cf.json | 56 ++++++++ .../GHSA-2jj9-p9wg-x9q9.json | 36 ++++++ .../GHSA-359j-pv49-2m97.json | 29 +++++ .../GHSA-47gw-647h-mrp4.json | 52 ++++++++ .../GHSA-67qr-87v5-r3g3.json | 36 ++++++ .../GHSA-6gm8-27pm-mx3w.json | 36 ++++++ .../GHSA-6w55-mvg6-h5h5.json | 29 +++++ .../GHSA-7wc9-4gpr-w6xx.json | 40 ++++++ .../GHSA-99fv-v434-wh6f.json | 15 ++- .../GHSA-9cqp-q38m-rfw4.json | 36 ++++++ .../GHSA-f763-24vx-m6x9.json | 56 ++++++++ .../GHSA-fch8-h9xw-98mw.json | 1 + .../GHSA-g3mv-8h5x-hmj4.json | 56 ++++++++ .../GHSA-h2q9-88fw-gpmp.json | 36 ++++++ .../GHSA-hp62-9h62-jgpx.json | 29 +++++ .../GHSA-hvvr-j4rh-p665.json | 29 +++++ .../GHSA-j238-93mq-hf2r.json | 6 +- .../GHSA-j8rc-g3xr-w3p5.json | 36 ++++++ .../GHSA-jhhr-9p24-gxw8.json | 29 +++++ .../GHSA-m54m-vwf4-wrj2.json | 52 ++++++++ .../GHSA-pqv7-crpv-669v.json | 6 +- .../GHSA-pvrm-pgp5-5hc5.json | 6 +- .../GHSA-pxpx-vcwr-c656.json | 29 +++++ .../GHSA-qv4j-f75x-4v5x.json | 29 +++++ .../GHSA-xj6r-wgr5-8rxc.json | 36 ++++++ 63 files changed, 1154 insertions(+), 85 deletions(-) create mode 100644 advisories/github-reviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json delete mode 100644 advisories/unreviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-22qj-f25c-22mc/GHSA-22qj-f25c-22mc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-24fj-mqgp-74gr/GHSA-24fj-mqgp-74gr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-257h-84mq-c7cf/GHSA-257h-84mq-c7cf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2jj9-p9wg-x9q9/GHSA-2jj9-p9wg-x9q9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json create mode 100644 advisories/unreviewed/2025/02/GHSA-47gw-647h-mrp4/GHSA-47gw-647h-mrp4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-67qr-87v5-r3g3/GHSA-67qr-87v5-r3g3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6gm8-27pm-mx3w/GHSA-6gm8-27pm-mx3w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7wc9-4gpr-w6xx/GHSA-7wc9-4gpr-w6xx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9cqp-q38m-rfw4/GHSA-9cqp-q38m-rfw4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f763-24vx-m6x9/GHSA-f763-24vx-m6x9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g3mv-8h5x-hmj4/GHSA-g3mv-8h5x-hmj4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h2q9-88fw-gpmp/GHSA-h2q9-88fw-gpmp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hp62-9h62-jgpx/GHSA-hp62-9h62-jgpx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hvvr-j4rh-p665/GHSA-hvvr-j4rh-p665.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j8rc-g3xr-w3p5/GHSA-j8rc-g3xr-w3p5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jhhr-9p24-gxw8/GHSA-jhhr-9p24-gxw8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m54m-vwf4-wrj2/GHSA-m54m-vwf4-wrj2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pxpx-vcwr-c656/GHSA-pxpx-vcwr-c656.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xj6r-wgr5-8rxc/GHSA-xj6r-wgr5-8rxc.json diff --git a/advisories/github-reviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json b/advisories/github-reviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json new file mode 100644 index 00000000000..83728d19b45 --- /dev/null +++ b/advisories/github-reviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm4m-9rm8-7rxj", + "modified": "2025-02-12T18:30:45Z", + "published": "2022-08-20T00:00:30Z", + "aliases": [ + "CVE-2022-35692" + ], + "summary": "Magento Open Source has Improper Access Control vulnerability", + "details": "Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account details. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.3-p1" + }, + { + "fixed": "2.4.3-p3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.3.7-p1" + }, + { + "fixed": "2.3.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.3.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.3" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35692" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-02-12T18:30:44Z", + "nvd_published_at": "2022-08-19T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-cjqx-m2ff-vgj5/GHSA-cjqx-m2ff-vgj5.json b/advisories/unreviewed/2022/05/GHSA-cjqx-m2ff-vgj5/GHSA-cjqx-m2ff-vgj5.json index 40766f5724a..51f4022f46c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjqx-m2ff-vgj5/GHSA-cjqx-m2ff-vgj5.json +++ b/advisories/unreviewed/2022/05/GHSA-cjqx-m2ff-vgj5/GHSA-cjqx-m2ff-vgj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjqx-m2ff-vgj5", - "modified": "2022-05-24T19:03:38Z", + "modified": "2025-02-12T18:31:20Z", "published": "2022-05-24T19:03:38Z", "aliases": [ "CVE-2021-20240" ], "details": "A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -18,6 +23,18 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1926787" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BGZVCTH5O7WBJLYXZ2UOKLYNIFPVR55D" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EANWYODLOJDFLMBH6WEKJJMQ5PKLEWML" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5H3GNVWMZTYZR3JBYCK57PF7PFMQBNP" @@ -33,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-191", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json b/advisories/unreviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json deleted file mode 100644 index 27d41e3fdb6..00000000000 --- a/advisories/unreviewed/2022/08/GHSA-gm4m-9rm8-7rxj/GHSA-gm4m-9rm8-7rxj.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-gm4m-9rm8-7rxj", - "modified": "2022-08-20T00:00:30Z", - "published": "2022-08-20T00:00:30Z", - "aliases": [ - "CVE-2022-35692" - ], - "details": "Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35692" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-08-19T23:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-225v-7693-56j3/GHSA-225v-7693-56j3.json b/advisories/unreviewed/2023/04/GHSA-225v-7693-56j3/GHSA-225v-7693-56j3.json index fbf3999ced6..6e2392bb021 100644 --- a/advisories/unreviewed/2023/04/GHSA-225v-7693-56j3/GHSA-225v-7693-56j3.json +++ b/advisories/unreviewed/2023/04/GHSA-225v-7693-56j3/GHSA-225v-7693-56j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-225v-7693-56j3", - "modified": "2023-04-13T21:30:27Z", + "modified": "2025-02-12T18:31:26Z", "published": "2023-04-09T21:30:14Z", "aliases": [ "CVE-2023-27720" diff --git a/advisories/unreviewed/2023/04/GHSA-2jqf-9377-3hhp/GHSA-2jqf-9377-3hhp.json b/advisories/unreviewed/2023/04/GHSA-2jqf-9377-3hhp/GHSA-2jqf-9377-3hhp.json index d4a03c316e0..e6a569dc1bd 100644 --- a/advisories/unreviewed/2023/04/GHSA-2jqf-9377-3hhp/GHSA-2jqf-9377-3hhp.json +++ b/advisories/unreviewed/2023/04/GHSA-2jqf-9377-3hhp/GHSA-2jqf-9377-3hhp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json b/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json index b3a9211b282..0ae2a7193b4 100644 --- a/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json +++ b/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gqh-xgpm-cfvx", - "modified": "2023-04-14T18:30:20Z", + "modified": "2025-02-12T18:31:20Z", "published": "2023-04-05T18:30:18Z", "aliases": [ "CVE-2023-29389" diff --git a/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json b/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json index f4c2b1ddf31..a41afaa6b5e 100644 --- a/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json +++ b/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47pw-3g2g-9xj2", - "modified": "2023-04-13T18:30:32Z", + "modified": "2025-02-12T18:31:24Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27808" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27808" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/DeltriggerList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/DeltriggerList" diff --git a/advisories/unreviewed/2023/04/GHSA-4g4v-5cg8-c9g6/GHSA-4g4v-5cg8-c9g6.json b/advisories/unreviewed/2023/04/GHSA-4g4v-5cg8-c9g6/GHSA-4g4v-5cg8-c9g6.json index 5e0c70c76cc..8a930fb3268 100644 --- a/advisories/unreviewed/2023/04/GHSA-4g4v-5cg8-c9g6/GHSA-4g4v-5cg8-c9g6.json +++ b/advisories/unreviewed/2023/04/GHSA-4g4v-5cg8-c9g6/GHSA-4g4v-5cg8-c9g6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4v-5cg8-c9g6", - "modified": "2023-04-13T18:30:29Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T00:30:36Z", "aliases": [ "CVE-2023-29475" diff --git a/advisories/unreviewed/2023/04/GHSA-4j6m-cxx4-9x6q/GHSA-4j6m-cxx4-9x6q.json b/advisories/unreviewed/2023/04/GHSA-4j6m-cxx4-9x6q/GHSA-4j6m-cxx4-9x6q.json index 68806df4402..f95b883d415 100644 --- a/advisories/unreviewed/2023/04/GHSA-4j6m-cxx4-9x6q/GHSA-4j6m-cxx4-9x6q.json +++ b/advisories/unreviewed/2023/04/GHSA-4j6m-cxx4-9x6q/GHSA-4j6m-cxx4-9x6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j6m-cxx4-9x6q", - "modified": "2023-04-12T18:30:39Z", + "modified": "2025-02-12T18:31:20Z", "published": "2023-04-05T21:30:24Z", "aliases": [ "CVE-2023-1855" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/20230318122758.2140868-1-linux%40roeck-us.net" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20230318122758.2140868-1-linux@roeck-us.net" diff --git a/advisories/unreviewed/2023/04/GHSA-4mqf-c682-rprp/GHSA-4mqf-c682-rprp.json b/advisories/unreviewed/2023/04/GHSA-4mqf-c682-rprp/GHSA-4mqf-c682-rprp.json index dc1f54d1cab..fdfe0a21657 100644 --- a/advisories/unreviewed/2023/04/GHSA-4mqf-c682-rprp/GHSA-4mqf-c682-rprp.json +++ b/advisories/unreviewed/2023/04/GHSA-4mqf-c682-rprp/GHSA-4mqf-c682-rprp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json b/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json index 3ac634b3630..ad7e6b0f8bb 100644 --- a/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json +++ b/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-64x6-jjx3-6ggh", - "modified": "2023-04-13T18:30:32Z", + "modified": "2025-02-12T18:31:24Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27810" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27810" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/ipqos_lanip_editlist" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/ipqos_lanip_editlist" diff --git a/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json b/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json index be72193af08..dc9ba511850 100644 --- a/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json +++ b/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cv9-9p4c-38fq", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27801" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27801" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/DelDNSHnList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/DelDNSHnList" diff --git a/advisories/unreviewed/2023/04/GHSA-7mgx-8745-58vp/GHSA-7mgx-8745-58vp.json b/advisories/unreviewed/2023/04/GHSA-7mgx-8745-58vp/GHSA-7mgx-8745-58vp.json index 13372e45ca9..2d379bbff96 100644 --- a/advisories/unreviewed/2023/04/GHSA-7mgx-8745-58vp/GHSA-7mgx-8745-58vp.json +++ b/advisories/unreviewed/2023/04/GHSA-7mgx-8745-58vp/GHSA-7mgx-8745-58vp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json b/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json index 3fb8393c3c1..4498da8ad94 100644 --- a/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json +++ b/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v8p-3ffx-7rjc", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27802" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27802" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/EditvsList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/EditvsList" diff --git a/advisories/unreviewed/2023/04/GHSA-8v5j-pwr7-w5f8/GHSA-8v5j-pwr7-w5f8.json b/advisories/unreviewed/2023/04/GHSA-8v5j-pwr7-w5f8/GHSA-8v5j-pwr7-w5f8.json index 550bafdf5d5..a89a3554a8c 100644 --- a/advisories/unreviewed/2023/04/GHSA-8v5j-pwr7-w5f8/GHSA-8v5j-pwr7-w5f8.json +++ b/advisories/unreviewed/2023/04/GHSA-8v5j-pwr7-w5f8/GHSA-8v5j-pwr7-w5f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8v5j-pwr7-w5f8", - "modified": "2023-11-25T12:30:21Z", + "modified": "2025-02-12T18:31:21Z", "published": "2023-04-06T18:30:21Z", "aliases": [ "CVE-2023-24534" diff --git a/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json b/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json index 7066f952ecd..0bbbdc3ae38 100644 --- a/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json +++ b/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8v94-jg2x-f3vr", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-12T18:31:24Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27805" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27805" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/EditSTList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/EditSTList" diff --git a/advisories/unreviewed/2023/04/GHSA-9f7g-gqwh-jpf5/GHSA-9f7g-gqwh-jpf5.json b/advisories/unreviewed/2023/04/GHSA-9f7g-gqwh-jpf5/GHSA-9f7g-gqwh-jpf5.json index 38714f87fbd..a73ee40124b 100644 --- a/advisories/unreviewed/2023/04/GHSA-9f7g-gqwh-jpf5/GHSA-9f7g-gqwh-jpf5.json +++ b/advisories/unreviewed/2023/04/GHSA-9f7g-gqwh-jpf5/GHSA-9f7g-gqwh-jpf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f7g-gqwh-jpf5", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-12T18:31:21Z", "published": "2023-04-06T18:30:21Z", "aliases": [ "CVE-2023-24536" diff --git a/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json b/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json index 9ad7ffc7e92..06e17ef4aaa 100644 --- a/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json +++ b/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7xj-xr99-gpjr", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-12T18:31:24Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27806" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27806" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/ipqos_lanip_dellist" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/ipqos_lanip_dellist" diff --git a/advisories/unreviewed/2023/04/GHSA-jxf3-h258-gvf9/GHSA-jxf3-h258-gvf9.json b/advisories/unreviewed/2023/04/GHSA-jxf3-h258-gvf9/GHSA-jxf3-h258-gvf9.json index 000b5678d13..ee88baf97ee 100644 --- a/advisories/unreviewed/2023/04/GHSA-jxf3-h258-gvf9/GHSA-jxf3-h258-gvf9.json +++ b/advisories/unreviewed/2023/04/GHSA-jxf3-h258-gvf9/GHSA-jxf3-h258-gvf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxf3-h258-gvf9", - "modified": "2023-04-12T18:30:38Z", + "modified": "2025-02-12T18:31:20Z", "published": "2023-04-06T06:30:19Z", "aliases": [ "CVE-2023-29421" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" diff --git a/advisories/unreviewed/2023/04/GHSA-m76f-5v6g-6jmr/GHSA-m76f-5v6g-6jmr.json b/advisories/unreviewed/2023/04/GHSA-m76f-5v6g-6jmr/GHSA-m76f-5v6g-6jmr.json index bdcea246023..acff683decc 100644 --- a/advisories/unreviewed/2023/04/GHSA-m76f-5v6g-6jmr/GHSA-m76f-5v6g-6jmr.json +++ b/advisories/unreviewed/2023/04/GHSA-m76f-5v6g-6jmr/GHSA-m76f-5v6g-6jmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m76f-5v6g-6jmr", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T00:30:36Z", "aliases": [ "CVE-2023-29474" diff --git a/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json b/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json index c9ddbfb3b5b..20b2213b0e1 100644 --- a/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json +++ b/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r3h7-cpq4-j5rr", - "modified": "2023-04-13T18:30:32Z", + "modified": "2025-02-12T18:31:24Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27807" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27807" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/Delstlist" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/Delstlist" diff --git a/advisories/unreviewed/2023/04/GHSA-rj3h-7prw-4qqr/GHSA-rj3h-7prw-4qqr.json b/advisories/unreviewed/2023/04/GHSA-rj3h-7prw-4qqr/GHSA-rj3h-7prw-4qqr.json index b3a3d1005f0..74fe77acf5c 100644 --- a/advisories/unreviewed/2023/04/GHSA-rj3h-7prw-4qqr/GHSA-rj3h-7prw-4qqr.json +++ b/advisories/unreviewed/2023/04/GHSA-rj3h-7prw-4qqr/GHSA-rj3h-7prw-4qqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rj3h-7prw-4qqr", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T00:30:36Z", "aliases": [ "CVE-2023-29473" diff --git a/advisories/unreviewed/2023/04/GHSA-v46r-626m-f3pp/GHSA-v46r-626m-f3pp.json b/advisories/unreviewed/2023/04/GHSA-v46r-626m-f3pp/GHSA-v46r-626m-f3pp.json index 8532b1a11f9..dc205cc2948 100644 --- a/advisories/unreviewed/2023/04/GHSA-v46r-626m-f3pp/GHSA-v46r-626m-f3pp.json +++ b/advisories/unreviewed/2023/04/GHSA-v46r-626m-f3pp/GHSA-v46r-626m-f3pp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-v4m2-x4rp-hv22/GHSA-v4m2-x4rp-hv22.json b/advisories/unreviewed/2023/04/GHSA-v4m2-x4rp-hv22/GHSA-v4m2-x4rp-hv22.json index 5f525cc0312..437af5b7511 100644 --- a/advisories/unreviewed/2023/04/GHSA-v4m2-x4rp-hv22/GHSA-v4m2-x4rp-hv22.json +++ b/advisories/unreviewed/2023/04/GHSA-v4m2-x4rp-hv22/GHSA-v4m2-x4rp-hv22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4m2-x4rp-hv22", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-12T18:31:22Z", "published": "2023-04-06T18:30:21Z", "aliases": [ "CVE-2023-24538" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241115-0007" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json b/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json index 144c4c54bb0..c64cdcdf547 100644 --- a/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json +++ b/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vg73-w7ww-xm56", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-12T18:31:23Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27803" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27803" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/EdittriggerList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/EdittriggerList" diff --git a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json index 59f16ac9a82..6f883b3ce9a 100644 --- a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json +++ b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-x3pf-j9xx-29g6/GHSA-x3pf-j9xx-29g6.json b/advisories/unreviewed/2023/04/GHSA-x3pf-j9xx-29g6/GHSA-x3pf-j9xx-29g6.json index afad9a44ca3..05eef42fdea 100644 --- a/advisories/unreviewed/2023/04/GHSA-x3pf-j9xx-29g6/GHSA-x3pf-j9xx-29g6.json +++ b/advisories/unreviewed/2023/04/GHSA-x3pf-j9xx-29g6/GHSA-x3pf-j9xx-29g6.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-99jh-9v4f-3xmf/GHSA-99jh-9v4f-3xmf.json b/advisories/unreviewed/2023/05/GHSA-99jh-9v4f-3xmf/GHSA-99jh-9v4f-3xmf.json index 0fa0cebaf66..ffe643a8181 100644 --- a/advisories/unreviewed/2023/05/GHSA-99jh-9v4f-3xmf/GHSA-99jh-9v4f-3xmf.json +++ b/advisories/unreviewed/2023/05/GHSA-99jh-9v4f-3xmf/GHSA-99jh-9v4f-3xmf.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2vp2-4cqw-xhcc/GHSA-2vp2-4cqw-xhcc.json b/advisories/unreviewed/2024/02/GHSA-2vp2-4cqw-xhcc/GHSA-2vp2-4cqw-xhcc.json index fcd2207e83d..b03908a12a0 100644 --- a/advisories/unreviewed/2024/02/GHSA-2vp2-4cqw-xhcc/GHSA-2vp2-4cqw-xhcc.json +++ b/advisories/unreviewed/2024/02/GHSA-2vp2-4cqw-xhcc/GHSA-2vp2-4cqw-xhcc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2vp2-4cqw-xhcc", - "modified": "2024-02-20T03:30:57Z", + "modified": "2025-02-12T18:31:27Z", "published": "2024-02-20T03:30:57Z", "aliases": [ "CVE-2024-0715" ], - "details": "Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.\n\n", + "details": "Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json b/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json index 2f49168fcac..27037b84c4d 100644 --- a/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json +++ b/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cgpg-xpvx-xqxj", - "modified": "2024-02-21T21:30:25Z", + "modified": "2025-02-12T18:31:28Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2024-25249" ], "details": "An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T20:15:46Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cwpg-8775-j56v/GHSA-cwpg-8775-j56v.json b/advisories/unreviewed/2024/02/GHSA-cwpg-8775-j56v/GHSA-cwpg-8775-j56v.json index 7e5eaffddd8..344a3b435c6 100644 --- a/advisories/unreviewed/2024/02/GHSA-cwpg-8775-j56v/GHSA-cwpg-8775-j56v.json +++ b/advisories/unreviewed/2024/02/GHSA-cwpg-8775-j56v/GHSA-cwpg-8775-j56v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cwpg-8775-j56v", - "modified": "2024-02-21T00:31:31Z", + "modified": "2025-02-12T18:31:27Z", "published": "2024-02-21T00:31:31Z", "aliases": [ "CVE-2023-6936" ], - "details": "In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).\n", + "details": "In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).", "severity": [ { "type": "CVSS_V3", @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json b/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json index 56b59da102a..05a0be3fe2a 100644 --- a/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json +++ b/advisories/unreviewed/2024/02/GHSA-vw87-wrx2-xwxq/GHSA-vw87-wrx2-xwxq.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json b/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json index 66a21be9e01..924f8dafbab 100644 --- a/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json +++ b/advisories/unreviewed/2024/02/GHSA-xhg6-78jc-3cwf/GHSA-xhg6-78jc-3cwf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xhg6-78jc-3cwf", - "modified": "2024-02-21T21:30:24Z", + "modified": "2025-02-12T18:31:28Z", "published": "2024-02-21T21:30:24Z", "aliases": [ "CVE-2024-22473" ], - "details": "TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.\n\n", + "details": "TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.", "severity": [ { "type": "CVSS_V3", @@ -27,7 +27,8 @@ "database_specific": { "cwe_ids": [ "CWE-1279", - "CWE-330" + "CWE-330", + "CWE-331" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g82j-wprp-q9q9/GHSA-g82j-wprp-q9q9.json b/advisories/unreviewed/2024/05/GHSA-g82j-wprp-q9q9/GHSA-g82j-wprp-q9q9.json index 992dcc1d858..65e05a26386 100644 --- a/advisories/unreviewed/2024/05/GHSA-g82j-wprp-q9q9/GHSA-g82j-wprp-q9q9.json +++ b/advisories/unreviewed/2024/05/GHSA-g82j-wprp-q9q9/GHSA-g82j-wprp-q9q9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g82j-wprp-q9q9", - "modified": "2024-05-14T18:30:52Z", + "modified": "2025-02-12T18:31:28Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3461" ], - "details": "KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.\n", + "details": "KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-p8rh-53x8-6ww5/GHSA-p8rh-53x8-6ww5.json b/advisories/unreviewed/2024/05/GHSA-p8rh-53x8-6ww5/GHSA-p8rh-53x8-6ww5.json index 6e680c7ef18..0a733d80e11 100644 --- a/advisories/unreviewed/2024/05/GHSA-p8rh-53x8-6ww5/GHSA-p8rh-53x8-6ww5.json +++ b/advisories/unreviewed/2024/05/GHSA-p8rh-53x8-6ww5/GHSA-p8rh-53x8-6ww5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p8rh-53x8-6ww5", - "modified": "2024-05-14T18:30:52Z", + "modified": "2025-02-12T18:31:28Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3460" ], - "details": "In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these applications, one may launch any other programs. \nIn order to exploit this vulnerability external applications must be left running when the KioWare software is launched. Additionally, an attacker must know the PIN set for this Kioware instance and also slow down the application with some specific task which extends the usable time window.\n\n", + "details": "In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these applications, one may launch any other programs. \nIn order to exploit this vulnerability external applications must be left running when the KioWare software is launched. Additionally, an attacker must know the PIN set for this Kioware instance and also slow down the application with some specific task which extends the usable time window.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json index f22f3635d61..a6d2a3471e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5q-pch5-g3xq", - "modified": "2025-02-12T06:30:30Z", + "modified": "2025-02-12T18:31:35Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12085" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12085" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1227" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1225" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1128" diff --git a/advisories/unreviewed/2025/02/GHSA-22qj-f25c-22mc/GHSA-22qj-f25c-22mc.json b/advisories/unreviewed/2025/02/GHSA-22qj-f25c-22mc/GHSA-22qj-f25c-22mc.json new file mode 100644 index 00000000000..cbdc98b0e45 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-22qj-f25c-22mc/GHSA-22qj-f25c-22mc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22qj-f25c-22mc", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-9870" + ], + "details": "An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9870" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2734142" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/498911" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-441" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-24fj-mqgp-74gr/GHSA-24fj-mqgp-74gr.json b/advisories/unreviewed/2025/02/GHSA-24fj-mqgp-74gr/GHSA-24fj-mqgp-74gr.json new file mode 100644 index 00000000000..1b2cd29b5b8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-24fj-mqgp-74gr/GHSA-24fj-mqgp-74gr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24fj-mqgp-74gr", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-1209" + ], + "details": "A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1209" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/nanguawuming/CVE2/blob/main/cve2.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295146" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295146" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-257h-84mq-c7cf/GHSA-257h-84mq-c7cf.json b/advisories/unreviewed/2025/02/GHSA-257h-84mq-c7cf/GHSA-257h-84mq-c7cf.json new file mode 100644 index 00000000000..1b4d28dfd25 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-257h-84mq-c7cf/GHSA-257h-84mq-c7cf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-257h-84mq-c7cf", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-1207" + ], + "details": "A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1207" + }, + { + "type": "WEB", + "url": "https://github.com/DMCERTCE/TFTPD64_DOS" + }, + { + "type": "WEB", + "url": "https://github.com/DMCERTCE/TFTPD64_DOS/blob/main/poc.py" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295144" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295144" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2jj9-p9wg-x9q9/GHSA-2jj9-p9wg-x9q9.json b/advisories/unreviewed/2025/02/GHSA-2jj9-p9wg-x9q9/GHSA-2jj9-p9wg-x9q9.json new file mode 100644 index 00000000000..b8388f4d5bd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2jj9-p9wg-x9q9/GHSA-2jj9-p9wg-x9q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jj9-p9wg-x9q9", + "modified": "2025-02-12T18:31:36Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-6097" + ], + "details": "In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6097" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/reporting/knowledge-base/kb-security-absolute-path-traversal-CVE-2024-6097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json b/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json new file mode 100644 index 00000000000..7c946a6b62b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-359j-pv49-2m97", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25351" + ], + "details": "PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25351" + }, + { + "type": "WEB", + "url": "https://github.com/vkcyberexpert/CVE-Writeup/blob/main/PHPGurukul/Daily%20Expense%20Tracker%20System/SQL%20Injection%20dateexpense%20daily%20expense.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-47gw-647h-mrp4/GHSA-47gw-647h-mrp4.json b/advisories/unreviewed/2025/02/GHSA-47gw-647h-mrp4/GHSA-47gw-647h-mrp4.json new file mode 100644 index 00000000000..7354392f0c6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-47gw-647h-mrp4/GHSA-47gw-647h-mrp4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47gw-647h-mrp4", + "modified": "2025-02-12T18:31:36Z", + "published": "2025-02-12T18:31:36Z", + "aliases": [ + "CVE-2025-1214" + ], + "details": "A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1214" + }, + { + "type": "WEB", + "url": "https://github.com/janssensjelle/published-pocs/blob/main/pihomehvac-improper-access-control.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295173" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295173" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497533" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-67qr-87v5-r3g3/GHSA-67qr-87v5-r3g3.json b/advisories/unreviewed/2025/02/GHSA-67qr-87v5-r3g3/GHSA-67qr-87v5-r3g3.json new file mode 100644 index 00000000000..40712a67e6e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-67qr-87v5-r3g3/GHSA-67qr-87v5-r3g3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67qr-87v5-r3g3", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-11629" + ], + "details": "In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11629" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/document-processing/knowledge-base/kb-security-rtf-filecontent-export-cve-2024-11629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6gm8-27pm-mx3w/GHSA-6gm8-27pm-mx3w.json b/advisories/unreviewed/2025/02/GHSA-6gm8-27pm-mx3w/GHSA-6gm8-27pm-mx3w.json new file mode 100644 index 00000000000..a21d4ebae7c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6gm8-27pm-mx3w/GHSA-6gm8-27pm-mx3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gm8-27pm-mx3w", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-0332" + ], + "details": "In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0332" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/winforms/knowledge-base/kb-security-path-traversal-cve-2025-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json b/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json new file mode 100644 index 00000000000..8ed88d78a15 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w55-mvg6-h5h5", + "modified": "2025-02-12T18:31:36Z", + "published": "2025-02-12T18:31:36Z", + "aliases": [ + "CVE-2025-25741" + ], + "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the IPv6_PppoePassword parameter in the SetIPv6PppoeSettings module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25741" + }, + { + "type": "WEB", + "url": "https://dear-sunshine-ba5.notion.site/D-Link-DIR-853-7-1812386a664480b7ac54d281afa629f5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7wc9-4gpr-w6xx/GHSA-7wc9-4gpr-w6xx.json b/advisories/unreviewed/2025/02/GHSA-7wc9-4gpr-w6xx/GHSA-7wc9-4gpr-w6xx.json new file mode 100644 index 00000000000..8d779c31488 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7wc9-4gpr-w6xx/GHSA-7wc9-4gpr-w6xx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wc9-4gpr-w6xx", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-0516" + ], + "details": "Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0516" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2914644" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/513540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json index 56fb08f35b0..85e5bfb23eb 100644 --- a/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json +++ b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99fv-v434-wh6f", - "modified": "2025-02-12T00:32:17Z", + "modified": "2025-02-12T18:31:34Z", "published": "2025-02-12T00:32:17Z", "aliases": [ "CVE-2024-54916" ], "details": "An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9cqp-q38m-rfw4/GHSA-9cqp-q38m-rfw4.json b/advisories/unreviewed/2025/02/GHSA-9cqp-q38m-rfw4/GHSA-9cqp-q38m-rfw4.json new file mode 100644 index 00000000000..2aedf2c3b0e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9cqp-q38m-rfw4/GHSA-9cqp-q38m-rfw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cqp-q38m-rfw4", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-11343" + ], + "details": "In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11343" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/document-processing/knowledge-base/kb-security-path-traversal-cve-2024-11343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f763-24vx-m6x9/GHSA-f763-24vx-m6x9.json b/advisories/unreviewed/2025/02/GHSA-f763-24vx-m6x9/GHSA-f763-24vx-m6x9.json new file mode 100644 index 00000000000..7ed2ad478d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f763-24vx-m6x9/GHSA-f763-24vx-m6x9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f763-24vx-m6x9", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-1210" + ], + "details": "A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1210" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/nanguawuming/CVE2/blob/main/cve3.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295147" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295147" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fch8-h9xw-98mw/GHSA-fch8-h9xw-98mw.json b/advisories/unreviewed/2025/02/GHSA-fch8-h9xw-98mw/GHSA-fch8-h9xw-98mw.json index 01397ec43fe..b447d0cabb9 100644 --- a/advisories/unreviewed/2025/02/GHSA-fch8-h9xw-98mw/GHSA-fch8-h9xw-98mw.json +++ b/advisories/unreviewed/2025/02/GHSA-fch8-h9xw-98mw/GHSA-fch8-h9xw-98mw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-316" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-g3mv-8h5x-hmj4/GHSA-g3mv-8h5x-hmj4.json b/advisories/unreviewed/2025/02/GHSA-g3mv-8h5x-hmj4/GHSA-g3mv-8h5x-hmj4.json new file mode 100644 index 00000000000..9ba1874e1d9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g3mv-8h5x-hmj4/GHSA-g3mv-8h5x-hmj4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3mv-8h5x-hmj4", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-1208" + ], + "details": "A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1208" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/nanguawuming/CVE2/blob/main/cve1.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295145" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295145" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h2q9-88fw-gpmp/GHSA-h2q9-88fw-gpmp.json b/advisories/unreviewed/2025/02/GHSA-h2q9-88fw-gpmp/GHSA-h2q9-88fw-gpmp.json new file mode 100644 index 00000000000..10ff224638a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h2q9-88fw-gpmp/GHSA-h2q9-88fw-gpmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2q9-88fw-gpmp", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-12629" + ], + "details": "In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12629" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/kendo-react-ui/components/knowledge-base/kb-security-protoype-pollution-2024-12629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hp62-9h62-jgpx/GHSA-hp62-9h62-jgpx.json b/advisories/unreviewed/2025/02/GHSA-hp62-9h62-jgpx/GHSA-hp62-9h62-jgpx.json new file mode 100644 index 00000000000..8682a686453 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hp62-9h62-jgpx/GHSA-hp62-9h62-jgpx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp62-9h62-jgpx", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25744" + ], + "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25744" + }, + { + "type": "WEB", + "url": "https://dear-sunshine-ba5.notion.site/D-Link-DIR-853-4-1812386a664480378626cc13b98e18f5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hvvr-j4rh-p665/GHSA-hvvr-j4rh-p665.json b/advisories/unreviewed/2025/02/GHSA-hvvr-j4rh-p665/GHSA-hvvr-j4rh-p665.json new file mode 100644 index 00000000000..22d967bfb52 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hvvr-j4rh-p665/GHSA-hvvr-j4rh-p665.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvvr-j4rh-p665", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25746" + ], + "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25746" + }, + { + "type": "WEB", + "url": "https://dear-sunshine-ba5.notion.site/D-Link-DIR-853-5-1812386a66448044b489f223b8c2e78a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j238-93mq-hf2r/GHSA-j238-93mq-hf2r.json b/advisories/unreviewed/2025/02/GHSA-j238-93mq-hf2r/GHSA-j238-93mq-hf2r.json index dea6066357f..da918db89c4 100644 --- a/advisories/unreviewed/2025/02/GHSA-j238-93mq-hf2r/GHSA-j238-93mq-hf2r.json +++ b/advisories/unreviewed/2025/02/GHSA-j238-93mq-hf2r/GHSA-j238-93mq-hf2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j238-93mq-hf2r", - "modified": "2025-02-12T03:31:14Z", + "modified": "2025-02-12T18:31:35Z", "published": "2025-02-12T03:31:14Z", "aliases": [ "CVE-2024-0145" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2108" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2113" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-j8rc-g3xr-w3p5/GHSA-j8rc-g3xr-w3p5.json b/advisories/unreviewed/2025/02/GHSA-j8rc-g3xr-w3p5/GHSA-j8rc-g3xr-w3p5.json new file mode 100644 index 00000000000..9d9a77d9ef5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j8rc-g3xr-w3p5/GHSA-j8rc-g3xr-w3p5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8rc-g3xr-w3p5", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-0556" + ], + "details": "In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0556" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/report-server/knowledge-base/kb-security-cleartext-transmission-cve-2025-0556" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jhhr-9p24-gxw8/GHSA-jhhr-9p24-gxw8.json b/advisories/unreviewed/2025/02/GHSA-jhhr-9p24-gxw8/GHSA-jhhr-9p24-gxw8.json new file mode 100644 index 00000000000..b72d68fa0d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jhhr-9p24-gxw8/GHSA-jhhr-9p24-gxw8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhhr-9p24-gxw8", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25743" + ], + "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25743" + }, + { + "type": "WEB", + "url": "https://dear-sunshine-ba5.notion.site/D-Link-DIR-853-1812386a664480229910c137ded2d3f1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m54m-vwf4-wrj2/GHSA-m54m-vwf4-wrj2.json b/advisories/unreviewed/2025/02/GHSA-m54m-vwf4-wrj2/GHSA-m54m-vwf4-wrj2.json new file mode 100644 index 00000000000..b3372ad15b1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m54m-vwf4-wrj2/GHSA-m54m-vwf4-wrj2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m54m-vwf4-wrj2", + "modified": "2025-02-12T18:31:36Z", + "published": "2025-02-12T18:31:36Z", + "aliases": [ + "CVE-2025-1213" + ], + "details": "A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1213" + }, + { + "type": "WEB", + "url": "https://github.com/janssensjelle/published-pocs/blob/main/pihome_xss_index.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295172" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295172" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497521" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pqv7-crpv-669v/GHSA-pqv7-crpv-669v.json b/advisories/unreviewed/2025/02/GHSA-pqv7-crpv-669v/GHSA-pqv7-crpv-669v.json index f90d21e30af..0ac7f75e025 100644 --- a/advisories/unreviewed/2025/02/GHSA-pqv7-crpv-669v/GHSA-pqv7-crpv-669v.json +++ b/advisories/unreviewed/2025/02/GHSA-pqv7-crpv-669v/GHSA-pqv7-crpv-669v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqv7-crpv-669v", - "modified": "2025-02-12T12:30:47Z", + "modified": "2025-02-12T18:31:35Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2024-32838" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/7l88h17pn9nf8zpx5bbojk7ko5oxo1dy" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/12/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-pvrm-pgp5-5hc5/GHSA-pvrm-pgp5-5hc5.json b/advisories/unreviewed/2025/02/GHSA-pvrm-pgp5-5hc5/GHSA-pvrm-pgp5-5hc5.json index 4facf8aa70d..ea11c193327 100644 --- a/advisories/unreviewed/2025/02/GHSA-pvrm-pgp5-5hc5/GHSA-pvrm-pgp5-5hc5.json +++ b/advisories/unreviewed/2025/02/GHSA-pvrm-pgp5-5hc5/GHSA-pvrm-pgp5-5hc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pvrm-pgp5-5hc5", - "modified": "2025-02-12T03:31:14Z", + "modified": "2025-02-12T18:31:34Z", "published": "2025-02-12T03:31:14Z", "aliases": [ "CVE-2024-0144" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5596" }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2108" + }, { "type": "WEB", "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2113" diff --git a/advisories/unreviewed/2025/02/GHSA-pxpx-vcwr-c656/GHSA-pxpx-vcwr-c656.json b/advisories/unreviewed/2025/02/GHSA-pxpx-vcwr-c656/GHSA-pxpx-vcwr-c656.json new file mode 100644 index 00000000000..e1e55e5e5e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxpx-vcwr-c656/GHSA-pxpx-vcwr-c656.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxpx-vcwr-c656", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25742" + ], + "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25742" + }, + { + "type": "WEB", + "url": "https://dear-sunshine-ba5.notion.site/D-Link-DIR-853-3-1812386a664480feaf1ceab444b132b3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json b/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json new file mode 100644 index 00000000000..451929bf7e9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv4j-f75x-4v5x", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2025-25349" + ], + "details": "PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25349" + }, + { + "type": "WEB", + "url": "https://github.com/vkcyberexpert/CVE-Writeup/blob/main/PHPGurukul/Daily%20Expense%20Tracker%20System/SQL%20Injection%20item%20add-expense%20costitem%20parameter.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xj6r-wgr5-8rxc/GHSA-xj6r-wgr5-8rxc.json b/advisories/unreviewed/2025/02/GHSA-xj6r-wgr5-8rxc/GHSA-xj6r-wgr5-8rxc.json new file mode 100644 index 00000000000..3d59a9a9cd1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xj6r-wgr5-8rxc/GHSA-xj6r-wgr5-8rxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj6r-wgr5-8rxc", + "modified": "2025-02-12T18:31:35Z", + "published": "2025-02-12T18:31:35Z", + "aliases": [ + "CVE-2024-11628" + ], + "details": "In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11628" + }, + { + "type": "WEB", + "url": "https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-protoype-pollution-2024-11628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T17:15:22Z" + } +} \ No newline at end of file