diff --git a/advisories/github-reviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json b/advisories/github-reviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json index 88fc57a3822..2af9f607328 100644 --- a/advisories/github-reviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json +++ b/advisories/github-reviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78wr-2p64-hpwj", - "modified": "2024-12-04T18:28:55Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-10-03T12:30:48Z", "aliases": [ "CVE-2024-47554" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0010" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/10/03/2" diff --git a/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json b/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json index 159b61d923e..71671018a1a 100644 --- a/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json +++ b/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9vj-2wh5-fj8j", - "modified": "2024-10-25T21:35:11Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-10-25T19:43:41Z", "aliases": [ "CVE-2024-49766" @@ -58,6 +58,10 @@ { "type": "WEB", "url": "https://github.com/pallets/werkzeug/releases/tag/3.0.6" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0005" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json b/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json index 3d4c4ac0dad..88326651ac6 100644 --- a/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json +++ b/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-653p-vg55-5652", - "modified": "2024-12-18T19:33:02Z", + "modified": "2025-01-31T15:30:44Z", "published": "2024-12-17T15:31:43Z", "aliases": [ "CVE-2024-54677" @@ -182,6 +182,10 @@ "type": "WEB", "url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0006" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n" diff --git a/advisories/github-reviewed/2024/12/GHSA-v778-237x-gjrc/GHSA-v778-237x-gjrc.json b/advisories/github-reviewed/2024/12/GHSA-v778-237x-gjrc/GHSA-v778-237x-gjrc.json index ef48869ab9c..625994b4912 100644 --- a/advisories/github-reviewed/2024/12/GHSA-v778-237x-gjrc/GHSA-v778-237x-gjrc.json +++ b/advisories/github-reviewed/2024/12/GHSA-v778-237x-gjrc/GHSA-v778-237x-gjrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v778-237x-gjrc", - "modified": "2024-12-13T21:56:08Z", + "modified": "2025-01-31T15:30:43Z", "published": "2024-12-11T22:03:04Z", "aliases": [ "CVE-2024-45337" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-3321" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0007" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/12/11/2" diff --git a/advisories/unreviewed/2023/05/GHSA-2q3q-wgvc-2m5p/GHSA-2q3q-wgvc-2m5p.json b/advisories/unreviewed/2023/05/GHSA-2q3q-wgvc-2m5p/GHSA-2q3q-wgvc-2m5p.json index 92ebf984045..9aaf6a0e1c9 100644 --- a/advisories/unreviewed/2023/05/GHSA-2q3q-wgvc-2m5p/GHSA-2q3q-wgvc-2m5p.json +++ b/advisories/unreviewed/2023/05/GHSA-2q3q-wgvc-2m5p/GHSA-2q3q-wgvc-2m5p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-9p62-9q9c-q4wv/GHSA-9p62-9q9c-q4wv.json b/advisories/unreviewed/2023/05/GHSA-9p62-9q9c-q4wv/GHSA-9p62-9q9c-q4wv.json index 11ea1452252..98f6e459c97 100644 --- a/advisories/unreviewed/2023/05/GHSA-9p62-9q9c-q4wv/GHSA-9p62-9q9c-q4wv.json +++ b/advisories/unreviewed/2023/05/GHSA-9p62-9q9c-q4wv/GHSA-9p62-9q9c-q4wv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-9ww8-p9mv-xgqx/GHSA-9ww8-p9mv-xgqx.json b/advisories/unreviewed/2023/05/GHSA-9ww8-p9mv-xgqx/GHSA-9ww8-p9mv-xgqx.json index bc51d32cf28..41808022aa1 100644 --- a/advisories/unreviewed/2023/05/GHSA-9ww8-p9mv-xgqx/GHSA-9ww8-p9mv-xgqx.json +++ b/advisories/unreviewed/2023/05/GHSA-9ww8-p9mv-xgqx/GHSA-9ww8-p9mv-xgqx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-f3rh-h76j-wjwq/GHSA-f3rh-h76j-wjwq.json b/advisories/unreviewed/2023/05/GHSA-f3rh-h76j-wjwq/GHSA-f3rh-h76j-wjwq.json index 273a529f08a..f8c3bc8bf74 100644 --- a/advisories/unreviewed/2023/05/GHSA-f3rh-h76j-wjwq/GHSA-f3rh-h76j-wjwq.json +++ b/advisories/unreviewed/2023/05/GHSA-f3rh-h76j-wjwq/GHSA-f3rh-h76j-wjwq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-g753-vxgm-rphm/GHSA-g753-vxgm-rphm.json b/advisories/unreviewed/2023/05/GHSA-g753-vxgm-rphm/GHSA-g753-vxgm-rphm.json index b89ff800c86..cf35e9b2944 100644 --- a/advisories/unreviewed/2023/05/GHSA-g753-vxgm-rphm/GHSA-g753-vxgm-rphm.json +++ b/advisories/unreviewed/2023/05/GHSA-g753-vxgm-rphm/GHSA-g753-vxgm-rphm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g753-vxgm-rphm", - "modified": "2024-04-04T04:19:07Z", + "modified": "2025-01-31T15:30:40Z", "published": "2023-05-23T21:30:18Z", "aliases": [ "CVE-2023-23305" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/anvilsecure/garmin-ciq-app-research/blob/main/advisories/CVE-2023-23305.md" + }, + { + "type": "WEB", + "url": "https://github.com/anvilsecure/garmin-ciq-app-research/blob/main/poc/GRMN-06.prg" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-h3jh-74f5-29gh/GHSA-h3jh-74f5-29gh.json b/advisories/unreviewed/2023/05/GHSA-h3jh-74f5-29gh/GHSA-h3jh-74f5-29gh.json index 482aae3cfa7..251d0b9f127 100644 --- a/advisories/unreviewed/2023/05/GHSA-h3jh-74f5-29gh/GHSA-h3jh-74f5-29gh.json +++ b/advisories/unreviewed/2023/05/GHSA-h3jh-74f5-29gh/GHSA-h3jh-74f5-29gh.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-r3cj-h858-jrrj/GHSA-r3cj-h858-jrrj.json b/advisories/unreviewed/2023/05/GHSA-r3cj-h858-jrrj/GHSA-r3cj-h858-jrrj.json index 9db99380478..6908b665967 100644 --- a/advisories/unreviewed/2023/05/GHSA-r3cj-h858-jrrj/GHSA-r3cj-h858-jrrj.json +++ b/advisories/unreviewed/2023/05/GHSA-r3cj-h858-jrrj/GHSA-r3cj-h858-jrrj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-x7p9-qfhh-r6x9/GHSA-x7p9-qfhh-r6x9.json b/advisories/unreviewed/2023/05/GHSA-x7p9-qfhh-r6x9/GHSA-x7p9-qfhh-r6x9.json index 534487e4605..b4c9e05f1ac 100644 --- a/advisories/unreviewed/2023/05/GHSA-x7p9-qfhh-r6x9/GHSA-x7p9-qfhh-r6x9.json +++ b/advisories/unreviewed/2023/05/GHSA-x7p9-qfhh-r6x9/GHSA-x7p9-qfhh-r6x9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-mhwh-jf8r-xgh4/GHSA-mhwh-jf8r-xgh4.json b/advisories/unreviewed/2023/07/GHSA-mhwh-jf8r-xgh4/GHSA-mhwh-jf8r-xgh4.json index c59b08f14ef..f60f9e2fdd0 100644 --- a/advisories/unreviewed/2023/07/GHSA-mhwh-jf8r-xgh4/GHSA-mhwh-jf8r-xgh4.json +++ b/advisories/unreviewed/2023/07/GHSA-mhwh-jf8r-xgh4/GHSA-mhwh-jf8r-xgh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhwh-jf8r-xgh4", - "modified": "2024-04-04T05:43:42Z", + "modified": "2025-01-31T15:30:39Z", "published": "2023-07-06T21:14:58Z", "aliases": [ "CVE-2023-30507" diff --git a/advisories/unreviewed/2024/03/GHSA-4223-r78w-6q8p/GHSA-4223-r78w-6q8p.json b/advisories/unreviewed/2024/03/GHSA-4223-r78w-6q8p/GHSA-4223-r78w-6q8p.json index 83863f97bcb..97f6c1fce14 100644 --- a/advisories/unreviewed/2024/03/GHSA-4223-r78w-6q8p/GHSA-4223-r78w-6q8p.json +++ b/advisories/unreviewed/2024/03/GHSA-4223-r78w-6q8p/GHSA-4223-r78w-6q8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4223-r78w-6q8p", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-31T15:30:41Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1380" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json index d55665820bd..d723ec6000f 100644 --- a/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json +++ b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8fvm-73q4-3j6f", - "modified": "2025-01-23T18:31:11Z", + "modified": "2025-01-31T15:30:41Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25709" diff --git a/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json b/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json index 2e02bb202a9..31f1628840e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json +++ b/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c5v-hp3x-r94q", - "modified": "2024-05-22T09:31:44Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-05-22T09:31:44Z", "aliases": [ "CVE-2021-47435" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix mempool NULL pointer race when completing IO\n\ndm_io_dec_pending() calls end_io_acct() first and will then dec md\nin-flight pending count. But if a task is swapping DM table at same\ntime this can result in a crash due to mempool->elements being NULL:\n\ntask1 task2\ndo_resume\n ->do_suspend\n ->dm_wait_for_completion\n bio_endio\n\t\t\t\t ->clone_endio\n\t\t\t\t ->dm_io_dec_pending\n\t\t\t\t ->end_io_acct\n\t\t\t\t ->wakeup task1\n ->dm_swap_table\n ->__bind\n ->__bind_mempools\n ->bioset_exit\n ->mempool_exit\n ->free_io\n\n[ 67.330330] Unable to handle kernel NULL pointer dereference at\nvirtual address 0000000000000000\n......\n[ 67.330494] pstate: 80400085 (Nzcv daIf +PAN -UAO)\n[ 67.330510] pc : mempool_free+0x70/0xa0\n[ 67.330515] lr : mempool_free+0x4c/0xa0\n[ 67.330520] sp : ffffff8008013b20\n[ 67.330524] x29: ffffff8008013b20 x28: 0000000000000004\n[ 67.330530] x27: ffffffa8c2ff40a0 x26: 00000000ffff1cc8\n[ 67.330535] x25: 0000000000000000 x24: ffffffdada34c800\n[ 67.330541] x23: 0000000000000000 x22: ffffffdada34c800\n[ 67.330547] x21: 00000000ffff1cc8 x20: ffffffd9a1304d80\n[ 67.330552] x19: ffffffdada34c970 x18: 000000b312625d9c\n[ 67.330558] x17: 00000000002dcfbf x16: 00000000000006dd\n[ 67.330563] x15: 000000000093b41e x14: 0000000000000010\n[ 67.330569] x13: 0000000000007f7a x12: 0000000034155555\n[ 67.330574] x11: 0000000000000001 x10: 0000000000000001\n[ 67.330579] x9 : 0000000000000000 x8 : 0000000000000000\n[ 67.330585] x7 : 0000000000000000 x6 : ffffff80148b5c1a\n[ 67.330590] x5 : ffffff8008013ae0 x4 : 0000000000000001\n[ 67.330596] x3 : ffffff80080139c8 x2 : ffffff801083bab8\n[ 67.330601] x1 : 0000000000000000 x0 : ffffffdada34c970\n[ 67.330609] Call trace:\n[ 67.330616] mempool_free+0x70/0xa0\n[ 67.330627] bio_put+0xf8/0x110\n[ 67.330638] dec_pending+0x13c/0x230\n[ 67.330644] clone_endio+0x90/0x180\n[ 67.330649] bio_endio+0x198/0x1b8\n[ 67.330655] dec_pending+0x190/0x230\n[ 67.330660] clone_endio+0x90/0x180\n[ 67.330665] bio_endio+0x198/0x1b8\n[ 67.330673] blk_update_request+0x214/0x428\n[ 67.330683] scsi_end_request+0x2c/0x300\n[ 67.330688] scsi_io_completion+0xa0/0x710\n[ 67.330695] scsi_finish_command+0xd8/0x110\n[ 67.330700] scsi_softirq_done+0x114/0x148\n[ 67.330708] blk_done_softirq+0x74/0xd0\n[ 67.330716] __do_softirq+0x18c/0x374\n[ 67.330724] irq_exit+0xb4/0xb8\n[ 67.330732] __handle_domain_irq+0x84/0xc0\n[ 67.330737] gic_handle_irq+0x148/0x1b0\n[ 67.330744] el1_irq+0xe8/0x190\n[ 67.330753] lpm_cpuidle_enter+0x4f8/0x538\n[ 67.330759] cpuidle_enter_state+0x1fc/0x398\n[ 67.330764] cpuidle_enter+0x18/0x20\n[ 67.330772] do_idle+0x1b4/0x290\n[ 67.330778] cpu_startup_entry+0x20/0x28\n[ 67.330786] secondary_start_kernel+0x160/0x170\n\nFix this by:\n1) Establishing pointers to 'struct dm_io' members in\ndm_io_dec_pending() so that they may be passed into end_io_acct()\n_after_ free_io() is called.\n2) Moving end_io_acct() after free_io().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json b/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json index 4ad911026c9..ab9f5c357e8 100644 --- a/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json +++ b/advisories/unreviewed/2024/05/GHSA-7grp-x8pq-wh35/GHSA-7grp-x8pq-wh35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7grp-x8pq-wh35", - "modified": "2024-05-21T18:31:21Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52788" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni915/perf: Fix NULL deref bugs with drm_dbg() calls\n\nWhen i915 perf interface is not available dereferencing it will lead to\nNULL dereferences.\n\nAs returning -ENOTSUPP is pretty clear return when perf interface is not\navailable.\n\n[tursulin: added stable tag]\n(cherry picked from commit 36f27350ff745bd228ab04d7845dfbffc177a889)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json b/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json index 1b504dd9aa6..ee5c62b0be6 100644 --- a/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json +++ b/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j44q-5mx6-236v/GHSA-j44q-5mx6-236v.json b/advisories/unreviewed/2024/05/GHSA-j44q-5mx6-236v/GHSA-j44q-5mx6-236v.json index d5b87560ad3..5862e8b5686 100644 --- a/advisories/unreviewed/2024/05/GHSA-j44q-5mx6-236v/GHSA-j44q-5mx6-236v.json +++ b/advisories/unreviewed/2024/05/GHSA-j44q-5mx6-236v/GHSA-j44q-5mx6-236v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j44q-5mx6-236v", - "modified": "2024-05-19T12:30:39Z", + "modified": "2025-01-31T15:30:41Z", "published": "2024-05-19T12:30:39Z", "aliases": [ "CVE-2024-35945" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: phy_device: Prevent nullptr exceptions on ISR\n\nIf phydev->irq is set unconditionally, check\nfor valid interrupt handler or fall back to polling mode to prevent\nnullptr exceptions in interrupt service routine.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T11:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r596-gfj2-gc78/GHSA-r596-gfj2-gc78.json b/advisories/unreviewed/2024/05/GHSA-r596-gfj2-gc78/GHSA-r596-gfj2-gc78.json index b7460fb1d4d..9587cf52d7d 100644 --- a/advisories/unreviewed/2024/05/GHSA-r596-gfj2-gc78/GHSA-r596-gfj2-gc78.json +++ b/advisories/unreviewed/2024/05/GHSA-r596-gfj2-gc78/GHSA-r596-gfj2-gc78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r596-gfj2-gc78", - "modified": "2024-05-19T12:30:39Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-05-19T12:30:39Z", "aliases": [ "CVE-2024-35946" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fix null pointer access when abort scan\n\nDuring cancel scan we might use vif that weren't scanning.\nFix this by using the actual scanning vif.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T11:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-236w-p7wf-5ph8/GHSA-236w-p7wf-5ph8.json b/advisories/unreviewed/2024/06/GHSA-236w-p7wf-5ph8/GHSA-236w-p7wf-5ph8.json index 5090c4b0088..3b3a368c878 100644 --- a/advisories/unreviewed/2024/06/GHSA-236w-p7wf-5ph8/GHSA-236w-p7wf-5ph8.json +++ b/advisories/unreviewed/2024/06/GHSA-236w-p7wf-5ph8/GHSA-236w-p7wf-5ph8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-236w-p7wf-5ph8", - "modified": "2024-06-19T03:34:44Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-06-05T18:30:34Z", "aliases": [ "CVE-2024-24789" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2888" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0008" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/06/04/1" diff --git a/advisories/unreviewed/2024/06/GHSA-cv67-23pp-jfh2/GHSA-cv67-23pp-jfh2.json b/advisories/unreviewed/2024/06/GHSA-cv67-23pp-jfh2/GHSA-cv67-23pp-jfh2.json index 9c382b140c4..9e16aa07227 100644 --- a/advisories/unreviewed/2024/06/GHSA-cv67-23pp-jfh2/GHSA-cv67-23pp-jfh2.json +++ b/advisories/unreviewed/2024/06/GHSA-cv67-23pp-jfh2/GHSA-cv67-23pp-jfh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv67-23pp-jfh2", - "modified": "2024-06-19T15:30:53Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38574" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibbpf: Prevent null-pointer dereference when prog to load has no BTF\n\nIn bpf_objec_load_prog(), there's no guarantee that obj->btf is non-NULL\nwhen passing it to btf__fd(), and this function does not perform any\ncheck before dereferencing its argument (as bpf_object__btf_fd() used to\ndo). As a consequence, we get segmentation fault errors in bpftool (for\nexample) when trying to load programs that come without BTF information.\n\nv2: Keep btf__fd() in the fix instead of reverting to bpf_object__btf_fd().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:17Z" diff --git a/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json b/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json index c391ce61650..bf66c99345b 100644 --- a/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json +++ b/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55x8-qm73-mrfg", - "modified": "2024-07-16T15:30:50Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-07-16T15:30:50Z", "aliases": [ "CVE-2024-6435" ], "details": "A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious user with basic privileges could perform critical functions such as creating a user with elevated privileges and reading sensitive information in the “views” section.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json b/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json index 152eef1606c..d88ff18a5e9 100644 --- a/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json +++ b/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cpv-q9vf-2h3j", - "modified": "2024-08-14T21:33:12Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-08-14T21:33:12Z", "aliases": [ "CVE-2024-7513" ], "details": "CVE-2024-7513 IMPACT\n\nA code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json b/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json index 13466f6f8c8..99acca8bc8f 100644 --- a/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json +++ b/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89fm-3w27-7c7q", - "modified": "2024-08-14T21:33:12Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-08-14T21:33:12Z", "aliases": [ "CVE-2024-40619" ], "details": "CVE-2024-40619 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json b/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json index d5d99e10bb8..7605e98ed20 100644 --- a/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json +++ b/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw7m-5v7h-8vqf", - "modified": "2024-08-14T21:33:12Z", + "modified": "2025-01-31T15:30:42Z", "published": "2024-08-14T21:33:12Z", "aliases": [ "CVE-2024-40620" ], "details": "CVE-2024-40620 IMPACT\n\nA vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json b/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json index dc0baef8579..a83ccf91509 100644 --- a/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json +++ b/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-789" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-3j57-8hvg-f4cv/GHSA-3j57-8hvg-f4cv.json b/advisories/unreviewed/2024/12/GHSA-3j57-8hvg-f4cv/GHSA-3j57-8hvg-f4cv.json index d5ac53357d0..33899ceb127 100644 --- a/advisories/unreviewed/2024/12/GHSA-3j57-8hvg-f4cv/GHSA-3j57-8hvg-f4cv.json +++ b/advisories/unreviewed/2024/12/GHSA-3j57-8hvg-f4cv/GHSA-3j57-8hvg-f4cv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-68vm-3r5x-qq59/GHSA-68vm-3r5x-qq59.json b/advisories/unreviewed/2024/12/GHSA-68vm-3r5x-qq59/GHSA-68vm-3r5x-qq59.json index bf378360a20..53ea6d7458b 100644 --- a/advisories/unreviewed/2024/12/GHSA-68vm-3r5x-qq59/GHSA-68vm-3r5x-qq59.json +++ b/advisories/unreviewed/2024/12/GHSA-68vm-3r5x-qq59/GHSA-68vm-3r5x-qq59.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68vm-3r5x-qq59", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-31T15:30:44Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56587" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nleds: class: Protect brightness_show() with led_cdev->led_access mutex\n\nThere is NULL pointer issue observed if from Process A where hid device\nbeing added which results in adding a led_cdev addition and later a\nanother call to access of led_cdev attribute from Process B can result\nin NULL pointer issue.\n\nUse mutex led_cdev->led_access to protect access to led->cdev and its\nattribute inside brightness_show() and max_brightness_show() and also\nupdate the comment for mutex that it should be used to protect the led\nclass device fields.\n\n\tProcess A \t\t\t\tProcess B\n\n kthread+0x114\n worker_thread+0x244\n process_scheduled_works+0x248\n uhid_device_add_worker+0x24\n hid_add_device+0x120\n device_add+0x268\n bus_probe_device+0x94\n device_initial_probe+0x14\n __device_attach+0xfc\n bus_for_each_drv+0x10c\n __device_attach_driver+0x14c\n driver_probe_device+0x3c\n __driver_probe_device+0xa0\n really_probe+0x190\n hid_device_probe+0x130\n ps_probe+0x990\n ps_led_register+0x94\n devm_led_classdev_register_ext+0x58\n led_classdev_register_ext+0x1f8\n device_create_with_groups+0x48\n device_create_groups_vargs+0xc8\n device_add+0x244\n kobject_uevent+0x14\n kobject_uevent_env[jt]+0x224\n mutex_unlock[jt]+0xc4\n __mutex_unlock_slowpath+0xd4\n wake_up_q+0x70\n try_to_wake_up[jt]+0x48c\n preempt_schedule_common+0x28\n __schedule+0x628\n __switch_to+0x174\n\t\t\t\t\t\tel0t_64_sync+0x1a8/0x1ac\n\t\t\t\t\t\tel0t_64_sync_handler+0x68/0xbc\n\t\t\t\t\t\tel0_svc+0x38/0x68\n\t\t\t\t\t\tdo_el0_svc+0x1c/0x28\n\t\t\t\t\t\tel0_svc_common+0x80/0xe0\n\t\t\t\t\t\tinvoke_syscall+0x58/0x114\n\t\t\t\t\t\t__arm64_sys_read+0x1c/0x2c\n\t\t\t\t\t\tksys_read+0x78/0xe8\n\t\t\t\t\t\tvfs_read+0x1e0/0x2c8\n\t\t\t\t\t\tkernfs_fop_read_iter+0x68/0x1b4\n\t\t\t\t\t\tseq_read_iter+0x158/0x4ec\n\t\t\t\t\t\tkernfs_seq_show+0x44/0x54\n\t\t\t\t\t\tsysfs_kf_seq_show+0xb4/0x130\n\t\t\t\t\t\tdev_attr_show+0x38/0x74\n\t\t\t\t\t\tbrightness_show+0x20/0x4c\n\t\t\t\t\t\tdualshock4_led_get_brightness+0xc/0x74\n\n[ 3313.874295][ T4013] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000060\n[ 3313.874301][ T4013] Mem abort info:\n[ 3313.874303][ T4013] ESR = 0x0000000096000006\n[ 3313.874305][ T4013] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 3313.874307][ T4013] SET = 0, FnV = 0\n[ 3313.874309][ T4013] EA = 0, S1PTW = 0\n[ 3313.874311][ T4013] FSC = 0x06: level 2 translation fault\n[ 3313.874313][ T4013] Data abort info:\n[ 3313.874314][ T4013] ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000\n[ 3313.874316][ T4013] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 3313.874318][ T4013] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 3313.874320][ T4013] user pgtable: 4k pages, 39-bit VAs, pgdp=00000008f2b0a000\n..\n\n[ 3313.874332][ T4013] Dumping ftrace buffer:\n[ 3313.874334][ T4013] (ftrace buffer empty)\n..\n..\n[ dd3313.874639][ T4013] CPU: 6 PID: 4013 Comm: InputReader\n[ 3313.874648][ T4013] pc : dualshock4_led_get_brightness+0xc/0x74\n[ 3313.874653][ T4013] lr : led_update_brightness+0x38/0x60\n[ 3313.874656][ T4013] sp : ffffffc0b910bbd0\n..\n..\n[ 3313.874685][ T4013] Call trace:\n[ 3313.874687][ T4013] dualshock4_led_get_brightness+0xc/0x74\n[ 3313.874690][ T4013] brightness_show+0x20/0x4c\n[ 3313.874692][ T4013] dev_attr_show+0x38/0x74\n[ 3313.874696][ T4013] sysfs_kf_seq_show+0xb4/0x130\n[ 3313.874700][ T4013] kernfs_seq_show+0x44/0x54\n[ 3313.874703][ T4013] seq_read_iter+0x158/0x4ec\n[ 3313.874705][ T4013] kernfs_fop_read_iter+0x68/0x1b4\n[ 3313.874708][ T4013] vfs_read+0x1e0/0x2c8\n[ 3313.874711][ T4013] ksys_read+0x78/0xe8\n[ 3313.874714][ T4013] __arm64_sys_read+0x1c/0x2c\n[ 3313.874718][ T4013] invoke_syscall+0x58/0x114\n[ 3313.874721][ T4013] el0_svc_common+0x80/0xe0\n[ 3313.874724][ T4013] do_el0_svc+0x1c/0x28\n[ 3313.874727][ T4013] el0_svc+0x38/0x68\n[ 3313.874730][ T4013] el0t_64_sync_handler+0x68/0xbc\n[ 3313.874732][ T4013] el0t_64_sync+0x1a8/0x1ac", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c453-36cx-pv4g/GHSA-c453-36cx-pv4g.json b/advisories/unreviewed/2024/12/GHSA-c453-36cx-pv4g/GHSA-c453-36cx-pv4g.json index ca015cf8db2..0d67fddc8a2 100644 --- a/advisories/unreviewed/2024/12/GHSA-c453-36cx-pv4g/GHSA-c453-36cx-pv4g.json +++ b/advisories/unreviewed/2024/12/GHSA-c453-36cx-pv4g/GHSA-c453-36cx-pv4g.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json b/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json index 030872ff889..2d7c7b52da6 100644 --- a/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json +++ b/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-789" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json index 46352a9f5d0..221ab1aa6a8 100644 --- a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json +++ b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h288-5fq8-5pfw", - "modified": "2025-01-24T21:31:27Z", + "modified": "2025-01-31T15:30:43Z", "published": "2024-12-11T09:32:03Z", "aliases": [ "CVE-2024-11053" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250124-0012" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250131-0003" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1" diff --git a/advisories/unreviewed/2024/12/GHSA-m2pc-wfjr-69c4/GHSA-m2pc-wfjr-69c4.json b/advisories/unreviewed/2024/12/GHSA-m2pc-wfjr-69c4/GHSA-m2pc-wfjr-69c4.json index b8bdaa5b2aa..c40d41f33fc 100644 --- a/advisories/unreviewed/2024/12/GHSA-m2pc-wfjr-69c4/GHSA-m2pc-wfjr-69c4.json +++ b/advisories/unreviewed/2024/12/GHSA-m2pc-wfjr-69c4/GHSA-m2pc-wfjr-69c4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-862" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json index 677f84a3668..a995d0a766d 100644 --- a/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json +++ b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2f87-7wqp-6j6j", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24127" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json b/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json index 2c647e24a29..9ca34459b7b 100644 --- a/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json +++ b/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46pj-m82h-8px5", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24120" ], "details": "This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An attacker may be able to cause unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-58rp-5478-74m7/GHSA-58rp-5478-74m7.json b/advisories/unreviewed/2025/01/GHSA-58rp-5478-74m7/GHSA-58rp-5478-74m7.json index 7e7aa8891b1..d7f730e4e52 100644 --- a/advisories/unreviewed/2025/01/GHSA-58rp-5478-74m7/GHSA-58rp-5478-74m7.json +++ b/advisories/unreviewed/2025/01/GHSA-58rp-5478-74m7/GHSA-58rp-5478-74m7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58rp-5478-74m7", - "modified": "2025-01-19T12:31:27Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-19T12:31:27Z", "aliases": [ "CVE-2024-57926" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Set private->all_drm_private[i]->drm to NULL if mtk_drm_bind returns err\n\nThe pointer need to be set to NULL, otherwise KASAN complains about\nuse-after-free. Because in mtk_drm_bind, all private's drm are set\nas follows.\n\nprivate->all_drm_private[i]->drm = drm;\n\nAnd drm will be released by drm_dev_put in case mtk_drm_kms_init returns\nfailure. However, the shutdown path still accesses the previous allocated\nmemory in drm_atomic_helper_shutdown.\n\n[ 84.874820] watchdog: watchdog0: watchdog did not stop!\n[ 86.512054] ==================================================================\n[ 86.513162] BUG: KASAN: use-after-free in drm_atomic_helper_shutdown+0x33c/0x378\n[ 86.514258] Read of size 8 at addr ffff0000d46fc068 by task shutdown/1\n[ 86.515213]\n[ 86.515455] CPU: 1 UID: 0 PID: 1 Comm: shutdown Not tainted 6.13.0-rc1-mtk+gfa1a78e5d24b-dirty #55\n[ 86.516752] Hardware name: Unknown Product/Unknown Product, BIOS 2022.10 10/01/2022\n[ 86.517960] Call trace:\n[ 86.518333] show_stack+0x20/0x38 (C)\n[ 86.518891] dump_stack_lvl+0x90/0xd0\n[ 86.519443] print_report+0xf8/0x5b0\n[ 86.519985] kasan_report+0xb4/0x100\n[ 86.520526] __asan_report_load8_noabort+0x20/0x30\n[ 86.521240] drm_atomic_helper_shutdown+0x33c/0x378\n[ 86.521966] mtk_drm_shutdown+0x54/0x80\n[ 86.522546] platform_shutdown+0x64/0x90\n[ 86.523137] device_shutdown+0x260/0x5b8\n[ 86.523728] kernel_restart+0x78/0xf0\n[ 86.524282] __do_sys_reboot+0x258/0x2f0\n[ 86.524871] __arm64_sys_reboot+0x90/0xd8\n[ 86.525473] invoke_syscall+0x74/0x268\n[ 86.526041] el0_svc_common.constprop.0+0xb0/0x240\n[ 86.526751] do_el0_svc+0x4c/0x70\n[ 86.527251] el0_svc+0x4c/0xc0\n[ 86.527719] el0t_64_sync_handler+0x144/0x168\n[ 86.528367] el0t_64_sync+0x198/0x1a0\n[ 86.528920]\n[ 86.529157] The buggy address belongs to the physical page:\n[ 86.529972] page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff0000d46fd4d0 pfn:0x1146fc\n[ 86.531319] flags: 0xbfffc0000000000(node=0|zone=2|lastcpupid=0xffff)\n[ 86.532267] raw: 0bfffc0000000000 0000000000000000 dead000000000122 0000000000000000\n[ 86.533390] raw: ffff0000d46fd4d0 0000000000000000 00000000ffffffff 0000000000000000\n[ 86.534511] page dumped because: kasan: bad access detected\n[ 86.535323]\n[ 86.535559] Memory state around the buggy address:\n[ 86.536265] ffff0000d46fbf00: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 86.537314] ffff0000d46fbf80: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 86.538363] >ffff0000d46fc000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 86.544733] ^\n[ 86.551057] ffff0000d46fc080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 86.557510] ffff0000d46fc100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 86.563928] ==================================================================\n[ 86.571093] Disabling lock debugging due to kernel taint\n[ 86.577642] Unable to handle kernel paging request at virtual address e0e9c0920000000b\n[ 86.581834] KASAN: maybe wild-memory-access in range [0x0752049000000058-0x075204900000005f]\n...", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6wcr-rvpr-597h/GHSA-6wcr-rvpr-597h.json b/advisories/unreviewed/2025/01/GHSA-6wcr-rvpr-597h/GHSA-6wcr-rvpr-597h.json index 17064b5fb68..d3e3beafd1f 100644 --- a/advisories/unreviewed/2025/01/GHSA-6wcr-rvpr-597h/GHSA-6wcr-rvpr-597h.json +++ b/advisories/unreviewed/2025/01/GHSA-6wcr-rvpr-597h/GHSA-6wcr-rvpr-597h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wcr-rvpr-597h", - "modified": "2025-01-19T12:31:26Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57914" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpci: fix NULL pointer issue on shared irq case\n\nThe tcpci_irq() may meet below NULL pointer dereference issue:\n\n[ 2.641851] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010\n[ 2.641951] status 0x1, 0x37f\n[ 2.650659] Mem abort info:\n[ 2.656490] ESR = 0x0000000096000004\n[ 2.660230] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 2.665532] SET = 0, FnV = 0\n[ 2.668579] EA = 0, S1PTW = 0\n[ 2.671715] FSC = 0x04: level 0 translation fault\n[ 2.676584] Data abort info:\n[ 2.679459] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 2.684936] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 2.689980] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 2.695284] [0000000000000010] user address but active_mm is swapper\n[ 2.701632] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 2.707883] Modules linked in:\n[ 2.710936] CPU: 1 UID: 0 PID: 87 Comm: irq/111-2-0051 Not tainted 6.12.0-rc6-06316-g7f63786ad3d1-dirty #4\n[ 2.720570] Hardware name: NXP i.MX93 11X11 EVK board (DT)\n[ 2.726040] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 2.732989] pc : tcpci_irq+0x38/0x318\n[ 2.736647] lr : _tcpci_irq+0x14/0x20\n[ 2.740295] sp : ffff80008324bd30\n[ 2.743597] x29: ffff80008324bd70 x28: ffff800080107894 x27: ffff800082198f70\n[ 2.750721] x26: ffff0000050e6680 x25: ffff000004d172ac x24: ffff0000050f0000\n[ 2.757845] x23: ffff000004d17200 x22: 0000000000000001 x21: ffff0000050f0000\n[ 2.764969] x20: ffff000004d17200 x19: 0000000000000000 x18: 0000000000000001\n[ 2.772093] x17: 0000000000000000 x16: ffff80008183d8a0 x15: ffff00007fbab040\n[ 2.779217] x14: ffff00007fb918c0 x13: 0000000000000000 x12: 000000000000017a\n[ 2.786341] x11: 0000000000000001 x10: 0000000000000a90 x9 : ffff80008324bd00\n[ 2.793465] x8 : ffff0000050f0af0 x7 : ffff00007fbaa840 x6 : 0000000000000031\n[ 2.800589] x5 : 000000000000017a x4 : 0000000000000002 x3 : 0000000000000002\n[ 2.807713] x2 : ffff80008324bd3a x1 : 0000000000000010 x0 : 0000000000000000\n[ 2.814838] Call trace:\n[ 2.817273] tcpci_irq+0x38/0x318\n[ 2.820583] _tcpci_irq+0x14/0x20\n[ 2.823885] irq_thread_fn+0x2c/0xa8\n[ 2.827456] irq_thread+0x16c/0x2f4\n[ 2.830940] kthread+0x110/0x114\n[ 2.834164] ret_from_fork+0x10/0x20\n[ 2.837738] Code: f9426420 f9001fe0 d2800000 52800201 (f9400a60)\n\nThis may happen on shared irq case. Such as two Type-C ports share one\nirq. After the first port finished tcpci_register_port(), it may trigger\ninterrupt. However, if the interrupt comes by chance the 2nd port finishes\ndevm_request_threaded_irq(), the 2nd port interrupt handler will run at\nfirst. Then the above issue happens due to tcpci is still a NULL pointer\nin tcpci_irq() when dereference to regmap.\n\n devm_request_threaded_irq()\n\t\t\t\t<-- port1 irq comes\n disable_irq(client->irq);\n tcpci_register_port()\n\nThis will restore the logic to the state before commit (77e85107a771 \"usb:\ntypec: tcpci: support edge irq\").\n\nHowever, moving tcpci_register_port() earlier creates a problem when use\nedge irq because tcpci_init() will be called before\ndevm_request_threaded_irq(). The tcpci_init() writes the ALERT_MASK to\nthe hardware to tell it to start generating interrupts but we're not ready\nto deal with them yet, then the ALERT events may be missed and ALERT line\nwill not recover to high level forever. To avoid the issue, this will also\nset ALERT_MASK register after devm_request_threaded_irq() return.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json b/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json index 6c2bf4cd9a5..ac05d7225af 100644 --- a/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json +++ b/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7745-gvqx-6pp9", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24128" ], "details": "The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json index 8abed0c96b9..f7f7a49fc09 100644 --- a/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json +++ b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7cw6-gq2v-qm88", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24114" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7q7g-fjp6-g4rg/GHSA-7q7g-fjp6-g4rg.json b/advisories/unreviewed/2025/01/GHSA-7q7g-fjp6-g4rg/GHSA-7q7g-fjp6-g4rg.json new file mode 100644 index 00000000000..7c6f60db1e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7q7g-fjp6-g4rg/GHSA-7q7g-fjp6-g4rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q7g-fjp6-g4rg", + "modified": "2025-01-31T15:30:45Z", + "published": "2025-01-31T15:30:45Z", + "aliases": [ + "CVE-2025-0930" + ], + "details": "Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter in ‘/teamcal/src/index.php’.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0930" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-teamcal-neo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96h7-cv3r-xqwx/GHSA-96h7-cv3r-xqwx.json b/advisories/unreviewed/2025/01/GHSA-96h7-cv3r-xqwx/GHSA-96h7-cv3r-xqwx.json new file mode 100644 index 00000000000..e48ecc5d9de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96h7-cv3r-xqwx/GHSA-96h7-cv3r-xqwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96h7-cv3r-xqwx", + "modified": "2025-01-31T15:30:45Z", + "published": "2025-01-31T15:30:45Z", + "aliases": [ + "CVE-2024-45650" + ], + "details": "IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45650" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7182169" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9fhm-w5m6-rqv5/GHSA-9fhm-w5m6-rqv5.json b/advisories/unreviewed/2025/01/GHSA-9fhm-w5m6-rqv5/GHSA-9fhm-w5m6-rqv5.json index 48e4c1d1b38..05b1f788bf1 100644 --- a/advisories/unreviewed/2025/01/GHSA-9fhm-w5m6-rqv5/GHSA-9fhm-w5m6-rqv5.json +++ b/advisories/unreviewed/2025/01/GHSA-9fhm-w5m6-rqv5/GHSA-9fhm-w5m6-rqv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fhm-w5m6-rqv5", - "modified": "2025-01-11T15:30:28Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-11T15:30:28Z", "aliases": [ "CVE-2024-47809" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix possible lkb_resource null dereference\n\nThis patch fixes a possible null pointer dereference when this function is\ncalled from request_lock() as lkb->lkb_resource is not assigned yet,\nonly after validate_lock_args() by calling attach_lkb(). Another issue\nis that a resource name could be a non printable bytearray and we cannot\nassume to be ASCII coded.\n\nThe log functionality is probably never being hit when DLM is used in\nnormal way and no debug logging is enabled. The null pointer dereference\ncan only occur on a new created lkb that does not have the resource\nassigned yet, it probably never hits the null pointer dereference but we\nshould be sure that other changes might not change this behaviour and we\nactually can hit the mentioned null pointer dereference.\n\nIn this patch we just drop the printout of the resource name, the lkb id\nis enough to make a possible connection to a resource name if this\nexists.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:22Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json index d1268c1fa47..ec349bbfb9e 100644 --- a/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json +++ b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c9hp-6vqm-w35v", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24116" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fhc4-5jch-gg65/GHSA-fhc4-5jch-gg65.json b/advisories/unreviewed/2025/01/GHSA-fhc4-5jch-gg65/GHSA-fhc4-5jch-gg65.json new file mode 100644 index 00000000000..136ca7615fe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fhc4-5jch-gg65/GHSA-fhc4-5jch-gg65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhc4-5jch-gg65", + "modified": "2025-01-31T15:30:44Z", + "published": "2025-01-31T15:30:44Z", + "aliases": [ + "CVE-2025-24828" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24828" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7842" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hv44-v25j-f7m2/GHSA-hv44-v25j-f7m2.json b/advisories/unreviewed/2025/01/GHSA-hv44-v25j-f7m2/GHSA-hv44-v25j-f7m2.json new file mode 100644 index 00000000000..309d590fe74 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hv44-v25j-f7m2/GHSA-hv44-v25j-f7m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv44-v25j-f7m2", + "modified": "2025-01-31T15:30:44Z", + "published": "2025-01-31T15:30:44Z", + "aliases": [ + "CVE-2025-24829" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24829" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7839" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j58h-ppm8-rm4x/GHSA-j58h-ppm8-rm4x.json b/advisories/unreviewed/2025/01/GHSA-j58h-ppm8-rm4x/GHSA-j58h-ppm8-rm4x.json index 176405ed8e5..b09251ae516 100644 --- a/advisories/unreviewed/2025/01/GHSA-j58h-ppm8-rm4x/GHSA-j58h-ppm8-rm4x.json +++ b/advisories/unreviewed/2025/01/GHSA-j58h-ppm8-rm4x/GHSA-j58h-ppm8-rm4x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j58h-ppm8-rm4x", - "modified": "2025-01-19T12:31:27Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-19T12:31:27Z", "aliases": [ "CVE-2024-57927" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: Fix oops in nfs_netfs_init_request() when copying to cache\n\nWhen netfslib wants to copy some data that has just been read on behalf of\nnfs, it creates a new write request and calls nfs_netfs_init_request() to\ninitialise it, but with a NULL file pointer. This causes\nnfs_file_open_context() to oops - however, we don't actually need the nfs\ncontext as we're only going to write to the cache.\n\nFix this by just returning if we aren't given a file pointer and emit a\nwarning if the request was for something other than copy-to-cache.\n\nFurther, fix nfs_netfs_free_request() so that it doesn't try to free the\ncontext if the pointer is NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qw8g-4j5w-5j26/GHSA-qw8g-4j5w-5j26.json b/advisories/unreviewed/2025/01/GHSA-qw8g-4j5w-5j26/GHSA-qw8g-4j5w-5j26.json index ecb8cb9d773..15ad81f5eb4 100644 --- a/advisories/unreviewed/2025/01/GHSA-qw8g-4j5w-5j26/GHSA-qw8g-4j5w-5j26.json +++ b/advisories/unreviewed/2025/01/GHSA-qw8g-4j5w-5j26/GHSA-qw8g-4j5w-5j26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qw8g-4j5w-5j26", - "modified": "2025-01-21T12:30:48Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-21T12:30:48Z", "aliases": [ "CVE-2024-57933" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: guard XSK operations on the existence of queues\n\nThis patch predicates the enabling and disabling of XSK pools on the\nexistence of queues. As it stands, if the interface is down, disabling\nor enabling XSK pools would result in a crash, as the RX queue pointer\nwould be NULL. XSK pool registration will occur as part of the next\ninterface up.\n\nSimilarly, xsk_wakeup needs be guarded against queues disappearing\nwhile the function is executing, so a check against the\nGVE_PRIV_FLAGS_NAPI_ENABLED flag is added to synchronize with the\ndisabling of the bit and the synchronize_net() in gve_turndown.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T12:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r6w7-prm6-r9gc/GHSA-r6w7-prm6-r9gc.json b/advisories/unreviewed/2025/01/GHSA-r6w7-prm6-r9gc/GHSA-r6w7-prm6-r9gc.json new file mode 100644 index 00000000000..3782e34780a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r6w7-prm6-r9gc/GHSA-r6w7-prm6-r9gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6w7-prm6-r9gc", + "modified": "2025-01-31T15:30:44Z", + "published": "2025-01-31T15:30:44Z", + "aliases": [ + "CVE-2025-24831" + ], + "details": "Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24831" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-6153" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json b/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json index f9509986760..052c3b31b95 100644 --- a/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json +++ b/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v87f-3m66-pc8x", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-31T15:30:44Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24129" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w77m-g74v-gvgg/GHSA-w77m-g74v-gvgg.json b/advisories/unreviewed/2025/01/GHSA-w77m-g74v-gvgg/GHSA-w77m-g74v-gvgg.json new file mode 100644 index 00000000000..fe621b396fc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w77m-g74v-gvgg/GHSA-w77m-g74v-gvgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w77m-g74v-gvgg", + "modified": "2025-01-31T15:30:45Z", + "published": "2025-01-31T15:30:45Z", + "aliases": [ + "CVE-2025-0929" + ], + "details": "SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0929" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-teamcal-neo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w7qf-x8rx-fxrq/GHSA-w7qf-x8rx-fxrq.json b/advisories/unreviewed/2025/01/GHSA-w7qf-x8rx-fxrq/GHSA-w7qf-x8rx-fxrq.json new file mode 100644 index 00000000000..8d737e65ae8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w7qf-x8rx-fxrq/GHSA-w7qf-x8rx-fxrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7qf-x8rx-fxrq", + "modified": "2025-01-31T15:30:44Z", + "published": "2025-01-31T15:30:44Z", + "aliases": [ + "CVE-2025-24830" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24830" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7829" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T13:15:28Z" + } +} \ No newline at end of file