Publish Advisories

GHSA-3gjx-hg47-fq76
GHSA-4v73-45hj-cf9x
GHSA-5xgj-h7r6-ghm7
GHSA-78qc-93vm-f29v
GHSA-793p-3chh-7q87
GHSA-8c6j-hg38-f5mx
GHSA-99v2-4jx9-8fv3
GHSA-9x98-jv6r-7jg8
GHSA-hj5r-xh67-qwq9
GHSA-j5r6-pp4x-vxpq
GHSA-jhcc-gwm2-46v7
GHSA-jx33-373q-67x5
GHSA-m2hj-xmpv-m3qq
GHSA-m38h-87r3-2882
GHSA-m62j-8cr2-x42v
GHSA-rgpm-767r-vvhm
GHSA-x2q5-6m88-47fh
GHSA-x8mr-294g-g3j6
GHSA-xqmm-x45g-6wf4
This commit is contained in:
advisory-database[bot]
2025-05-09 00:31:44 +00:00
parent ecf93f1744
commit 6d0d90aa16
19 changed files with 833 additions and 0 deletions
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3gjx-hg47-fq76",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-29827"
],
"details": "Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29827"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29827"
}
],
"database_specific": {
"cwe_ids": [
"CWE-285"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v73-45hj-cf9x",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-4440"
],
"details": "A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4440"
},
{
"type": "WEB",
"url": "https://github.com/CH13hh/tmp_store_cc/blob/main/H3C%20GR-1800AX/1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308048"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308048"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.557087"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:53Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xgj-h7r6-ghm7",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-4107"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4107"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:53Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78qc-93vm-f29v",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-1331"
],
"details": "IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1331"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232923"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232924"
}
],
"database_specific": {
"cwe_ids": [
"CWE-242"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T22:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-793p-3chh-7q87",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-29972"
],
"details": "Server-Side Request Forgery (SSRF) in Azure allows an authorized attacker to perform spoofing over a network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29972"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29972"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c6j-hg38-f5mx",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-4442"
],
"details": "A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4442"
},
{
"type": "WEB",
"url": "https://github.com/jylsec/vuldb/blob/main/D-Link/dlink_dir605l/Buffer_overflow-formSetWAN_Wizard55-curTime/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308050"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308050"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.558352"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-09T00:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99v2-4jx9-8fv3",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-47732"
],
"details": "Microsoft Dataverse Remote Code Execution Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47732"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47732"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x98-jv6r-7jg8",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-4443"
],
"details": "A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4443"
},
{
"type": "WEB",
"url": "https://github.com/jylsec/vuldb/blob/main/D-Link/dlink_dir605l/Command_injection-sub_454F2C-sysCmd/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308051"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308051"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.558355"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-09T00:15:19Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hj5r-xh67-qwq9",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-4445"
],
"details": "A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4445"
},
{
"type": "WEB",
"url": "https://github.com/jylsec/vuldb/blob/main/D-Link/dlink_dir605l/Command_injection-wake_on_lan-mac/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308052"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308052"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.558356"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-09T00:15:19Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5r6-pp4x-vxpq",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-27720"
],
"details": "The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27720"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-128-01"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/about/contact"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/osirix/osirix-md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:51Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhcc-gwm2-46v7",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-29813"
],
"details": "An elevation of privilege vulnerability exists when Visual Studio improperly handles pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project.\nTo exploit this vulnerability, an attacker would first have to have access to the project and swap the short-term token for a long-term one.\nThe update addresses the vulnerability by correcting how the Visual Studio updater handles these tokens.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29813"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29813"
}
],
"database_specific": {
"cwe_ids": [
"CWE-302"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx33-373q-67x5",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-4441"
],
"details": "A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4441"
},
{
"type": "WEB",
"url": "https://github.com/jylsec/vuldb/blob/main/D-Link/dlink_dir605l/Buffer_overflow-formSetWAN_Wizard534-curTime/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308049"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308049"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.558351"
},
{
"type": "WEB",
"url": "https://www.dlink.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:53Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2hj-xmpv-m3qq",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-1330"
],
"details": "IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1330"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232923"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232924"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T22:15:18Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m38h-87r3-2882",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-31946"
],
"details": "Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31946"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-128-01"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/about/contact"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/osirix/osirix-md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m62j-8cr2-x42v",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-27578"
],
"details": "Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27578"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-128-01"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/about/contact"
},
{
"type": "WEB",
"url": "https://www.osirix-viewer.com/osirix/osirix-md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:51Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgpm-767r-vvhm",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-4446"
],
"details": "A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the function Edit_List_SSID of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack needs to be approached within the local network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4446"
},
{
"type": "WEB",
"url": "https://github.com/CH13hh/tmp_store_cc/blob/main/H3C%20GB5400AX/5.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308056"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308056"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.561866"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-09T00:15:19Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x2q5-6m88-47fh",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-1329"
],
"details": "IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the \n\ngethostbyaddr \n\n function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1329"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232923"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7232924"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T22:15:17Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8mr-294g-g3j6",
"modified": "2025-05-09T00:30:34Z",
"published": "2025-05-09T00:30:34Z",
"aliases": [
"CVE-2025-33072"
],
"details": "Improper access control in Azure allows an unauthorized attacker to disclose information over a network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33072"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33072"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:52Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqmm-x45g-6wf4",
"modified": "2025-05-09T00:30:35Z",
"published": "2025-05-09T00:30:35Z",
"aliases": [
"CVE-2025-47733"
],
"details": "Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47733"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47733"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T23:15:53Z"
}
}