Publish Advisories

GHSA-54hw-8q4q-2g6m
GHSA-32rr-g2cq-v328
GHSA-9xg5-c6xr-xwgc
GHSA-qm95-9v2h-5rq5
GHSA-5rmc-9cm9-28cr
GHSA-66mh-pcv7-gg73
GHSA-8pmj-vrj3-r692
GHSA-fgjj-2m6m-vf56
GHSA-gfmx-hgrp-xwrv
GHSA-gxwf-3xjr-jjqf
GHSA-jm38-gf7c-9f3f
GHSA-vf8c-ccvq-v376
GHSA-mj4r-rr6h-q62g
GHSA-p8w2-9mpv-5ccm
This commit is contained in:
advisory-database[bot]
2025-04-11 21:32:31 +00:00
parent 51f3e59bb2
commit 68cb5ad8dc
14 changed files with 132 additions and 17 deletions
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-269"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32rr-g2cq-v328",
"modified": "2024-03-27T09:30:40Z",
"modified": "2025-04-11T21:30:34Z",
"published": "2024-03-27T09:30:40Z",
"aliases": [
"CVE-2024-29918"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.",
"severity": [
{
"type": "CVSS_V3",
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rmc-9cm9-28cr",
"modified": "2025-03-25T03:30:25Z",
"modified": "2025-04-11T21:30:35Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2728"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520462"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66mh-pcv7-gg73",
"modified": "2025-03-25T03:30:25Z",
"modified": "2025-04-11T21:30:35Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2727"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520394"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pmj-vrj3-r692",
"modified": "2025-03-25T03:30:25Z",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2729"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520494"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgjj-2m6m-vf56",
"modified": "2025-03-25T03:30:24Z",
"modified": "2025-04-11T21:30:35Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2726"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520393"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfmx-hgrp-xwrv",
"modified": "2025-03-25T06:30:26Z",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-03-25T06:30:26Z",
"aliases": [
"CVE-2025-2731"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520497"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxwf-3xjr-jjqf",
"modified": "2025-03-25T06:30:26Z",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-03-25T06:30:26Z",
"aliases": [
"CVE-2025-2732"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520499"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jm38-gf7c-9f3f",
"modified": "2025-03-25T03:30:25Z",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2730"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520495"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf8c-ccvq-v376",
"modified": "2025-03-25T03:30:24Z",
"modified": "2025-04-11T21:30:35Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2725"
@@ -38,6 +38,14 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520390"
},
{
"type": "WEB",
"url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product"
},
{
"type": "WEB",
"url": "https://zhiliao.h3c.com/theme/details/229784"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mj4r-rr6h-q62g",
"modified": "2025-04-10T15:31:48Z",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-04-10T15:31:48Z",
"aliases": [
"CVE-2025-29088"
],
"details": "An issue in sqlite v.3.49.0 allows an attacker to cause a denial of service via the SQLITE_DBCONFIG_LOOKASIDE component",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T14:15:27Z"
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8w2-9mpv-5ccm",
"modified": "2025-04-11T21:30:36Z",
"published": "2025-04-11T21:30:36Z",
"aliases": [
"CVE-2024-11679"
],
"details": "An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11679"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-193044"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-11T19:15:41Z"
}
}