From 70bad5222da2faece8cb56688eda2827fb811434 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 May 2025 21:32:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2f7g-h3x9-626r.json | 6 ++- .../GHSA-2wrc-685p-7pgf.json | 2 +- .../GHSA-37rh-hqfw-42xx.json | 2 +- .../GHSA-3wph-8799-87r7.json | 10 ++++- .../GHSA-47jx-2m6r-9jxq.json | 3 +- .../GHSA-4h33-mvq3-wvqm.json | 2 +- .../GHSA-4j4x-4j2g-pccj.json | 6 ++- .../GHSA-65r5-w6f7-pj3p.json | 2 +- .../GHSA-7x55-vpf3-jcj3.json | 5 ++- .../GHSA-cxr9-v33w-vc4g.json | 6 ++- .../GHSA-w2vc-6qc2-rxm2.json | 2 +- .../GHSA-w3xv-9mxw-3wv4.json | 2 +- .../GHSA-v897-8cmv-r8gq.json | 2 +- .../GHSA-vv3f-2v3m-g822.json | 6 ++- .../GHSA-p528-6gx5-qw3c.json | 4 +- .../GHSA-vvvx-g9vg-6c4g.json | 4 +- .../GHSA-3pm4-j65g-c8hx.json | 4 +- .../GHSA-52h4-gx23-qjqh.json | 4 +- .../GHSA-67x3-pf53-7724.json | 4 +- .../GHSA-6j23-9625-chgm.json | 4 +- .../GHSA-cp87-ch4g-957j.json | 3 +- .../GHSA-f67q-rx5w-v4hr.json | 3 +- .../GHSA-f8cc-p399-4cfh.json | 4 +- .../GHSA-j27x-pp9j-vhj8.json | 4 +- .../GHSA-php9-vq53-w2xm.json | 4 +- .../GHSA-4pjm-2jf5-8h3g.json | 3 +- .../GHSA-2f3x-vm73-4v2v.json | 3 +- .../GHSA-2w88-4wpv-5768.json | 3 +- .../GHSA-45qh-j5f9-3rvr.json | 3 +- .../GHSA-5f2p-3q97-rpw3.json | 3 +- .../GHSA-983m-rvx3-7pf3.json | 3 +- .../GHSA-9wfx-p9gg-hp4f.json | 1 + .../GHSA-f24m-7jrp-68fr.json | 4 +- .../GHSA-h9c2-qf4j-fhfg.json | 3 +- .../GHSA-j2xv-j3qm-qc85.json | 3 +- .../GHSA-qffm-wchf-95hp.json | 3 +- .../GHSA-r6p8-wxvj-85qw.json | 3 +- .../GHSA-26h9-w3fm-wprg.json | 36 +++++++++++++++ .../GHSA-27w7-2jg3-x45x.json | 3 +- .../GHSA-2fmh-chfc-392c.json | 37 ++++++++++++++++ .../GHSA-3c5g-ff4p-m2gx.json | 29 ++++++++++++ .../GHSA-5w52-96jj-fv59.json | 29 ++++++++++++ .../GHSA-68gh-935w-wv3c.json | 33 ++++++++++++++ .../GHSA-6m6f-rwf2-ghvg.json | 33 ++++++++++++++ .../GHSA-6pp6-5h3q-mgg3.json | 36 +++++++++++++++ .../GHSA-746r-3x8x-jmcc.json | 3 +- .../GHSA-74m8-698c-prjf.json | 36 +++++++++++++++ .../GHSA-78rr-5vrh-jhqh.json | 36 +++++++++++++++ .../GHSA-8m4f-v87c-8xhm.json | 36 +++++++++++++++ .../GHSA-98vp-fcq9-gmj3.json | 11 +++-- .../GHSA-9wg5-mqr8-x4m3.json | 36 +++++++++++++++ .../GHSA-c644-3mgg-w2j9.json | 36 +++++++++++++++ .../GHSA-cp9r-g575-xc5f.json | 29 ++++++++++++ .../GHSA-f89j-4hpj-5qjm.json | 41 +++++++++++++++++ .../GHSA-g6jr-84fr-8jwx.json | 3 +- .../GHSA-ghrr-gjmc-qq88.json | 33 ++++++++++++++ .../GHSA-ghvv-mg26-g3c9.json | 36 +++++++++++++++ .../GHSA-gwqp-vrqv-c9q6.json | 29 ++++++++++++ .../GHSA-gx4r-c3v7-5x28.json | 36 +++++++++++++++ .../GHSA-hgrp-p24x-8rqw.json | 3 +- .../GHSA-j92j-6p6g-x235.json | 29 ++++++++++++ .../GHSA-m7cj-8qx5-j738.json | 33 ++++++++++++++ .../GHSA-p2h7-5rp6-x3fx.json | 33 ++++++++++++++ .../GHSA-p89h-p4ph-4vj6.json | 29 ++++++++++++ .../GHSA-p8p5-5q8p-vwcr.json | 3 +- .../GHSA-pwm3-776c-8q7q.json | 36 +++++++++++++++ .../GHSA-q7c3-x7hm-qq72.json | 29 ++++++++++++ .../GHSA-r93p-9jjr-wjhj.json | 36 +++++++++++++++ .../GHSA-rf73-97j8-9vqh.json | 29 ++++++++++++ .../GHSA-rmcv-f79g-83q3.json | 3 +- .../GHSA-vrqw-478g-gv6h.json | 44 +++++++++++++++++++ .../GHSA-vxhm-55mv-5fhx.json | 11 +++-- .../GHSA-w899-x298-m75w.json | 29 ++++++++++++ .../GHSA-x6ph-hgqm-c68g.json | 15 +++++-- .../GHSA-xrpq-4g9w-qrwj.json | 29 ++++++++++++ 75 files changed, 1105 insertions(+), 56 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-26h9-w3fm-wprg/GHSA-26h9-w3fm-wprg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5w52-96jj-fv59/GHSA-5w52-96jj-fv59.json create mode 100644 advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6pp6-5h3q-mgg3/GHSA-6pp6-5h3q-mgg3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-74m8-698c-prjf/GHSA-74m8-698c-prjf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8m4f-v87c-8xhm/GHSA-8m4f-v87c-8xhm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9wg5-mqr8-x4m3/GHSA-9wg5-mqr8-x4m3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c644-3mgg-w2j9/GHSA-c644-3mgg-w2j9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json create mode 100644 advisories/unreviewed/2025/05/GHSA-ghvv-mg26-g3c9/GHSA-ghvv-mg26-g3c9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gx4r-c3v7-5x28/GHSA-gx4r-c3v7-5x28.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p89h-p4ph-4vj6/GHSA-p89h-p4ph-4vj6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pwm3-776c-8q7q/GHSA-pwm3-776c-8q7q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q7c3-x7hm-qq72/GHSA-q7c3-x7hm-qq72.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r93p-9jjr-wjhj/GHSA-r93p-9jjr-wjhj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rf73-97j8-9vqh/GHSA-rf73-97j8-9vqh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vrqw-478g-gv6h/GHSA-vrqw-478g-gv6h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xrpq-4g9w-qrwj/GHSA-xrpq-4g9w-qrwj.json diff --git a/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json b/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json index d3fb45e9d45..505c81a764f 100644 --- a/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json +++ b/advisories/unreviewed/2022/10/GHSA-2f7g-h3x9-626r/GHSA-2f7g-h3x9-626r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2f7g-h3x9-626r", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41586" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-130" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-2wrc-685p-7pgf/GHSA-2wrc-685p-7pgf.json b/advisories/unreviewed/2022/10/GHSA-2wrc-685p-7pgf/GHSA-2wrc-685p-7pgf.json index e2c2fcde28c..2d29bf45e5e 100644 --- a/advisories/unreviewed/2022/10/GHSA-2wrc-685p-7pgf/GHSA-2wrc-685p-7pgf.json +++ b/advisories/unreviewed/2022/10/GHSA-2wrc-685p-7pgf/GHSA-2wrc-685p-7pgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wrc-685p-7pgf", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T21:31:10Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41597" diff --git a/advisories/unreviewed/2022/10/GHSA-37rh-hqfw-42xx/GHSA-37rh-hqfw-42xx.json b/advisories/unreviewed/2022/10/GHSA-37rh-hqfw-42xx/GHSA-37rh-hqfw-42xx.json index ea739a0dd6e..506ca1c3166 100644 --- a/advisories/unreviewed/2022/10/GHSA-37rh-hqfw-42xx/GHSA-37rh-hqfw-42xx.json +++ b/advisories/unreviewed/2022/10/GHSA-37rh-hqfw-42xx/GHSA-37rh-hqfw-42xx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37rh-hqfw-42xx", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41593" diff --git a/advisories/unreviewed/2022/10/GHSA-3wph-8799-87r7/GHSA-3wph-8799-87r7.json b/advisories/unreviewed/2022/10/GHSA-3wph-8799-87r7/GHSA-3wph-8799-87r7.json index 67e5b1b70f4..2ff38e8adba 100644 --- a/advisories/unreviewed/2022/10/GHSA-3wph-8799-87r7/GHSA-3wph-8799-87r7.json +++ b/advisories/unreviewed/2022/10/GHSA-3wph-8799-87r7/GHSA-3wph-8799-87r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wph-8799-87r7", - "modified": "2022-10-19T19:00:21Z", + "modified": "2025-05-14T21:31:10Z", "published": "2022-10-17T19:00:27Z", "aliases": [ "CVE-2022-3165" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://gitlab.com/qemu-project/qemu/-/commit/d307040b18" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I36LKZA7Z65J3LJU2P37LVTWDFTXBMPU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTY7TVHX62OJWF6IOBCIGLR2N5K4QN3E" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I36LKZA7Z65J3LJU2P37LVTWDFTXBMPU" diff --git a/advisories/unreviewed/2022/10/GHSA-47jx-2m6r-9jxq/GHSA-47jx-2m6r-9jxq.json b/advisories/unreviewed/2022/10/GHSA-47jx-2m6r-9jxq/GHSA-47jx-2m6r-9jxq.json index 894c7097eba..83c1478ca6e 100644 --- a/advisories/unreviewed/2022/10/GHSA-47jx-2m6r-9jxq/GHSA-47jx-2m6r-9jxq.json +++ b/advisories/unreviewed/2022/10/GHSA-47jx-2m6r-9jxq/GHSA-47jx-2m6r-9jxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47jx-2m6r-9jxq", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T21:31:10Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41595" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/10/GHSA-4h33-mvq3-wvqm/GHSA-4h33-mvq3-wvqm.json b/advisories/unreviewed/2022/10/GHSA-4h33-mvq3-wvqm/GHSA-4h33-mvq3-wvqm.json index 37eab69a6f7..79fb671f208 100644 --- a/advisories/unreviewed/2022/10/GHSA-4h33-mvq3-wvqm/GHSA-4h33-mvq3-wvqm.json +++ b/advisories/unreviewed/2022/10/GHSA-4h33-mvq3-wvqm/GHSA-4h33-mvq3-wvqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h33-mvq3-wvqm", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41592" diff --git a/advisories/unreviewed/2022/10/GHSA-4j4x-4j2g-pccj/GHSA-4j4x-4j2g-pccj.json b/advisories/unreviewed/2022/10/GHSA-4j4x-4j2g-pccj/GHSA-4j4x-4j2g-pccj.json index ddf60a7e54b..41b89d50eae 100644 --- a/advisories/unreviewed/2022/10/GHSA-4j4x-4j2g-pccj/GHSA-4j4x-4j2g-pccj.json +++ b/advisories/unreviewed/2022/10/GHSA-4j4x-4j2g-pccj/GHSA-4j4x-4j2g-pccj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j4x-4j2g-pccj", - "modified": "2022-10-20T12:00:17Z", + "modified": "2025-05-14T21:31:11Z", "published": "2022-10-18T12:00:31Z", "aliases": [ "CVE-2022-41431" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://sudsy-fish-73d.notion.site/XSS-about-xzs-system-31f689f2f3014ba99f12423fae521e49" }, + { + "type": "WEB", + "url": "https://www.mindskip.net/xzs.html%3B" + }, { "type": "WEB", "url": "https://www.mindskip.net/xzs.html;" diff --git a/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json b/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json index 389e9994404..8a7d1c60ce6 100644 --- a/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json +++ b/advisories/unreviewed/2022/10/GHSA-65r5-w6f7-pj3p/GHSA-65r5-w6f7-pj3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65r5-w6f7-pj3p", - "modified": "2022-10-17T19:00:28Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41578" diff --git a/advisories/unreviewed/2022/10/GHSA-7x55-vpf3-jcj3/GHSA-7x55-vpf3-jcj3.json b/advisories/unreviewed/2022/10/GHSA-7x55-vpf3-jcj3/GHSA-7x55-vpf3-jcj3.json index 0bc0d176c48..724037b0cc1 100644 --- a/advisories/unreviewed/2022/10/GHSA-7x55-vpf3-jcj3/GHSA-7x55-vpf3-jcj3.json +++ b/advisories/unreviewed/2022/10/GHSA-7x55-vpf3-jcj3/GHSA-7x55-vpf3-jcj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x55-vpf3-jcj3", - "modified": "2022-10-15T12:00:55Z", + "modified": "2025-05-14T21:31:10Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41594" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-476" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json b/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json index 83146721b16..10eca6ec45c 100644 --- a/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json +++ b/advisories/unreviewed/2022/10/GHSA-cxr9-v33w-vc4g/GHSA-cxr9-v33w-vc4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxr9-v33w-vc4g", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41588" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1264" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json b/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json index 2bd93dce253..c8d75e83ffd 100644 --- a/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json +++ b/advisories/unreviewed/2022/10/GHSA-w2vc-6qc2-rxm2/GHSA-w2vc-6qc2-rxm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2vc-6qc2-rxm2", - "modified": "2022-10-17T19:00:28Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41580" diff --git a/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json b/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json index f7a8a050f87..e68fb929a9e 100644 --- a/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json +++ b/advisories/unreviewed/2022/10/GHSA-w3xv-9mxw-3wv4/GHSA-w3xv-9mxw-3wv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3xv-9mxw-3wv4", - "modified": "2022-10-18T19:00:32Z", + "modified": "2025-05-14T21:31:09Z", "published": "2022-10-14T19:00:39Z", "aliases": [ "CVE-2022-41587" diff --git a/advisories/unreviewed/2022/11/GHSA-v897-8cmv-r8gq/GHSA-v897-8cmv-r8gq.json b/advisories/unreviewed/2022/11/GHSA-v897-8cmv-r8gq/GHSA-v897-8cmv-r8gq.json index 4eccf0e04df..006b40f5c4d 100644 --- a/advisories/unreviewed/2022/11/GHSA-v897-8cmv-r8gq/GHSA-v897-8cmv-r8gq.json +++ b/advisories/unreviewed/2022/11/GHSA-v897-8cmv-r8gq/GHSA-v897-8cmv-r8gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v897-8cmv-r8gq", - "modified": "2022-11-19T00:30:56Z", + "modified": "2025-05-14T21:31:11Z", "published": "2022-11-15T12:00:15Z", "aliases": [ "CVE-2022-40844" diff --git a/advisories/unreviewed/2024/01/GHSA-vv3f-2v3m-g822/GHSA-vv3f-2v3m-g822.json b/advisories/unreviewed/2024/01/GHSA-vv3f-2v3m-g822/GHSA-vv3f-2v3m-g822.json index 33e908d2be4..737b1941cb6 100644 --- a/advisories/unreviewed/2024/01/GHSA-vv3f-2v3m-g822/GHSA-vv3f-2v3m-g822.json +++ b/advisories/unreviewed/2024/01/GHSA-vv3f-2v3m-g822/GHSA-vv3f-2v3m-g822.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv3f-2v3m-g822", - "modified": "2024-01-17T18:31:36Z", + "modified": "2025-05-14T21:31:12Z", "published": "2024-01-11T09:30:34Z", "aliases": [ "CVE-2023-52030" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-p528-6gx5-qw3c/GHSA-p528-6gx5-qw3c.json b/advisories/unreviewed/2024/12/GHSA-p528-6gx5-qw3c/GHSA-p528-6gx5-qw3c.json index 58f4673ea62..9b67066c4e0 100644 --- a/advisories/unreviewed/2024/12/GHSA-p528-6gx5-qw3c/GHSA-p528-6gx5-qw3c.json +++ b/advisories/unreviewed/2024/12/GHSA-p528-6gx5-qw3c/GHSA-p528-6gx5-qw3c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-vvvx-g9vg-6c4g/GHSA-vvvx-g9vg-6c4g.json b/advisories/unreviewed/2024/12/GHSA-vvvx-g9vg-6c4g/GHSA-vvvx-g9vg-6c4g.json index ce315fc71ac..4efcdce2f7d 100644 --- a/advisories/unreviewed/2024/12/GHSA-vvvx-g9vg-6c4g/GHSA-vvvx-g9vg-6c4g.json +++ b/advisories/unreviewed/2024/12/GHSA-vvvx-g9vg-6c4g/GHSA-vvvx-g9vg-6c4g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-3pm4-j65g-c8hx/GHSA-3pm4-j65g-c8hx.json b/advisories/unreviewed/2025/02/GHSA-3pm4-j65g-c8hx/GHSA-3pm4-j65g-c8hx.json index aed6ba0d7bd..8d46550feb4 100644 --- a/advisories/unreviewed/2025/02/GHSA-3pm4-j65g-c8hx/GHSA-3pm4-j65g-c8hx.json +++ b/advisories/unreviewed/2025/02/GHSA-3pm4-j65g-c8hx/GHSA-3pm4-j65g-c8hx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-52h4-gx23-qjqh/GHSA-52h4-gx23-qjqh.json b/advisories/unreviewed/2025/02/GHSA-52h4-gx23-qjqh/GHSA-52h4-gx23-qjqh.json index 4eeb7b799d8..b6df810501e 100644 --- a/advisories/unreviewed/2025/02/GHSA-52h4-gx23-qjqh/GHSA-52h4-gx23-qjqh.json +++ b/advisories/unreviewed/2025/02/GHSA-52h4-gx23-qjqh/GHSA-52h4-gx23-qjqh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json b/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json index 3791a224bdc..a01bd8e0710 100644 --- a/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json +++ b/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-6j23-9625-chgm/GHSA-6j23-9625-chgm.json b/advisories/unreviewed/2025/02/GHSA-6j23-9625-chgm/GHSA-6j23-9625-chgm.json index e43b2a4c66f..c02cb068f5d 100644 --- a/advisories/unreviewed/2025/02/GHSA-6j23-9625-chgm/GHSA-6j23-9625-chgm.json +++ b/advisories/unreviewed/2025/02/GHSA-6j23-9625-chgm/GHSA-6j23-9625-chgm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-cp87-ch4g-957j/GHSA-cp87-ch4g-957j.json b/advisories/unreviewed/2025/02/GHSA-cp87-ch4g-957j/GHSA-cp87-ch4g-957j.json index 83413cacc7f..f52ed1b92b8 100644 --- a/advisories/unreviewed/2025/02/GHSA-cp87-ch4g-957j/GHSA-cp87-ch4g-957j.json +++ b/advisories/unreviewed/2025/02/GHSA-cp87-ch4g-957j/GHSA-cp87-ch4g-957j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-f67q-rx5w-v4hr/GHSA-f67q-rx5w-v4hr.json b/advisories/unreviewed/2025/02/GHSA-f67q-rx5w-v4hr/GHSA-f67q-rx5w-v4hr.json index 757dbc8adb2..7a04496f84f 100644 --- a/advisories/unreviewed/2025/02/GHSA-f67q-rx5w-v4hr/GHSA-f67q-rx5w-v4hr.json +++ b/advisories/unreviewed/2025/02/GHSA-f67q-rx5w-v4hr/GHSA-f67q-rx5w-v4hr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-f8cc-p399-4cfh/GHSA-f8cc-p399-4cfh.json b/advisories/unreviewed/2025/02/GHSA-f8cc-p399-4cfh/GHSA-f8cc-p399-4cfh.json index b6d3a58430e..6a280d0bf96 100644 --- a/advisories/unreviewed/2025/02/GHSA-f8cc-p399-4cfh/GHSA-f8cc-p399-4cfh.json +++ b/advisories/unreviewed/2025/02/GHSA-f8cc-p399-4cfh/GHSA-f8cc-p399-4cfh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json b/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json index 3eb912680f9..72adc2870ca 100644 --- a/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json +++ b/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-php9-vq53-w2xm/GHSA-php9-vq53-w2xm.json b/advisories/unreviewed/2025/02/GHSA-php9-vq53-w2xm/GHSA-php9-vq53-w2xm.json index 4e617975f9c..82214782e9c 100644 --- a/advisories/unreviewed/2025/02/GHSA-php9-vq53-w2xm/GHSA-php9-vq53-w2xm.json +++ b/advisories/unreviewed/2025/02/GHSA-php9-vq53-w2xm/GHSA-php9-vq53-w2xm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-4pjm-2jf5-8h3g/GHSA-4pjm-2jf5-8h3g.json b/advisories/unreviewed/2025/03/GHSA-4pjm-2jf5-8h3g/GHSA-4pjm-2jf5-8h3g.json index 6430f43f66d..7d517b6f24b 100644 --- a/advisories/unreviewed/2025/03/GHSA-4pjm-2jf5-8h3g/GHSA-4pjm-2jf5-8h3g.json +++ b/advisories/unreviewed/2025/03/GHSA-4pjm-2jf5-8h3g/GHSA-4pjm-2jf5-8h3g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-548" + "CWE-548", + "CWE-552" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2f3x-vm73-4v2v/GHSA-2f3x-vm73-4v2v.json b/advisories/unreviewed/2025/04/GHSA-2f3x-vm73-4v2v/GHSA-2f3x-vm73-4v2v.json index 3e10980f96f..0e02d278349 100644 --- a/advisories/unreviewed/2025/04/GHSA-2f3x-vm73-4v2v/GHSA-2f3x-vm73-4v2v.json +++ b/advisories/unreviewed/2025/04/GHSA-2f3x-vm73-4v2v/GHSA-2f3x-vm73-4v2v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2w88-4wpv-5768/GHSA-2w88-4wpv-5768.json b/advisories/unreviewed/2025/04/GHSA-2w88-4wpv-5768/GHSA-2w88-4wpv-5768.json index e2bba8b8666..c1a56d03860 100644 --- a/advisories/unreviewed/2025/04/GHSA-2w88-4wpv-5768/GHSA-2w88-4wpv-5768.json +++ b/advisories/unreviewed/2025/04/GHSA-2w88-4wpv-5768/GHSA-2w88-4wpv-5768.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-45qh-j5f9-3rvr/GHSA-45qh-j5f9-3rvr.json b/advisories/unreviewed/2025/04/GHSA-45qh-j5f9-3rvr/GHSA-45qh-j5f9-3rvr.json index e96225b7898..8fdc22b90d8 100644 --- a/advisories/unreviewed/2025/04/GHSA-45qh-j5f9-3rvr/GHSA-45qh-j5f9-3rvr.json +++ b/advisories/unreviewed/2025/04/GHSA-45qh-j5f9-3rvr/GHSA-45qh-j5f9-3rvr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json b/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json index b993da729b5..b8b2e24663e 100644 --- a/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json +++ b/advisories/unreviewed/2025/04/GHSA-5f2p-3q97-rpw3/GHSA-5f2p-3q97-rpw3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-983m-rvx3-7pf3/GHSA-983m-rvx3-7pf3.json b/advisories/unreviewed/2025/04/GHSA-983m-rvx3-7pf3/GHSA-983m-rvx3-7pf3.json index 6aed2c39692..289107cd0e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-983m-rvx3-7pf3/GHSA-983m-rvx3-7pf3.json +++ b/advisories/unreviewed/2025/04/GHSA-983m-rvx3-7pf3/GHSA-983m-rvx3-7pf3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9wfx-p9gg-hp4f/GHSA-9wfx-p9gg-hp4f.json b/advisories/unreviewed/2025/04/GHSA-9wfx-p9gg-hp4f/GHSA-9wfx-p9gg-hp4f.json index 50566bf76be..9a41e6f6cbe 100644 --- a/advisories/unreviewed/2025/04/GHSA-9wfx-p9gg-hp4f/GHSA-9wfx-p9gg-hp4f.json +++ b/advisories/unreviewed/2025/04/GHSA-9wfx-p9gg-hp4f/GHSA-9wfx-p9gg-hp4f.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-94", "CWE-96" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json b/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json index 812011ed0bd..06cedc4c323 100644 --- a/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json +++ b/advisories/unreviewed/2025/04/GHSA-f24m-7jrp-68fr/GHSA-f24m-7jrp-68fr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json b/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json index 9147f8c2c76..577ead6113e 100644 --- a/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json +++ b/advisories/unreviewed/2025/04/GHSA-h9c2-qf4j-fhfg/GHSA-h9c2-qf4j-fhfg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-j2xv-j3qm-qc85/GHSA-j2xv-j3qm-qc85.json b/advisories/unreviewed/2025/04/GHSA-j2xv-j3qm-qc85/GHSA-j2xv-j3qm-qc85.json index 4507aa97f10..5ac04160250 100644 --- a/advisories/unreviewed/2025/04/GHSA-j2xv-j3qm-qc85/GHSA-j2xv-j3qm-qc85.json +++ b/advisories/unreviewed/2025/04/GHSA-j2xv-j3qm-qc85/GHSA-j2xv-j3qm-qc85.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json b/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json index 0c19a26d490..fdd5dab7677 100644 --- a/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json +++ b/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json b/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json index c89ea74e6d6..2b82d7b92d2 100644 --- a/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json +++ b/advisories/unreviewed/2025/04/GHSA-r6p8-wxvj-85qw/GHSA-r6p8-wxvj-85qw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-26h9-w3fm-wprg/GHSA-26h9-w3fm-wprg.json b/advisories/unreviewed/2025/05/GHSA-26h9-w3fm-wprg/GHSA-26h9-w3fm-wprg.json new file mode 100644 index 00000000000..22af3b5cdcc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-26h9-w3fm-wprg/GHSA-26h9-w3fm-wprg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26h9-w3fm-wprg", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:17Z", + "aliases": [ + "CVE-2025-0132" + ], + "details": "A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. \n\nThe attacker must have network access to the Broker VM to exploit this issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0132" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0132" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-27w7-2jg3-x45x/GHSA-27w7-2jg3-x45x.json b/advisories/unreviewed/2025/05/GHSA-27w7-2jg3-x45x/GHSA-27w7-2jg3-x45x.json index e0d5883ed0a..856965a4127 100644 --- a/advisories/unreviewed/2025/05/GHSA-27w7-2jg3-x45x/GHSA-27w7-2jg3-x45x.json +++ b/advisories/unreviewed/2025/05/GHSA-27w7-2jg3-x45x/GHSA-27w7-2jg3-x45x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json b/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json new file mode 100644 index 00000000000..7f9301833db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2fmh-chfc-392c/GHSA-2fmh-chfc-392c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fmh-chfc-392c", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2025-32363" + ], + "details": "mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32363" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list/#unauthenticated-remote-code-execution-via-deserialization-of-untrusted-data-in-m" + }, + { + "type": "WEB", + "url": "https://medidok.de/aktuelles-neuigkeiten" + }, + { + "type": "WEB", + "url": "https://medidok.de/neueversionen/update-medidok-2-5-18-43-verfugbar" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json b/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json new file mode 100644 index 00000000000..c48517a1a91 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3c5g-ff4p-m2gx/GHSA-3c5g-ff4p-m2gx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c5g-ff4p-m2gx", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-44024" + ], + "details": "Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the login form. An attacker can inject malicious JavaScript code into the username or password fields during the login process", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44024" + }, + { + "type": "WEB", + "url": "https://github.com/zyx0814/Pichome/issues/50" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5w52-96jj-fv59/GHSA-5w52-96jj-fv59.json b/advisories/unreviewed/2025/05/GHSA-5w52-96jj-fv59/GHSA-5w52-96jj-fv59.json new file mode 100644 index 00000000000..4a704fb6044 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5w52-96jj-fv59/GHSA-5w52-96jj-fv59.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w52-96jj-fv59", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47886" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47886" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3548" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json b/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json new file mode 100644 index 00000000000..de2d23b61b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-68gh-935w-wv3c/GHSA-68gh-935w-wv3c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68gh-935w-wv3c", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2024-55569" + ], + "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds writes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55569" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-55569" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json b/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json new file mode 100644 index 00000000000..bf303713472 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6m6f-rwf2-ghvg/GHSA-6m6f-rwf2-ghvg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m6f-rwf2-ghvg", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2024-56427" + ], + "details": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds access via malformed RRC packets to the target.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56427" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-56427" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6pp6-5h3q-mgg3/GHSA-6pp6-5h3q-mgg3.json b/advisories/unreviewed/2025/05/GHSA-6pp6-5h3q-mgg3/GHSA-6pp6-5h3q-mgg3.json new file mode 100644 index 00000000000..27ba693f4ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6pp6-5h3q-mgg3/GHSA-6pp6-5h3q-mgg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pp6-5h3q-mgg3", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-2900" + ], + "details": "IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2900" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233415" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-746r-3x8x-jmcc/GHSA-746r-3x8x-jmcc.json b/advisories/unreviewed/2025/05/GHSA-746r-3x8x-jmcc/GHSA-746r-3x8x-jmcc.json index cfb5391b210..d0a7905ebf3 100644 --- a/advisories/unreviewed/2025/05/GHSA-746r-3x8x-jmcc/GHSA-746r-3x8x-jmcc.json +++ b/advisories/unreviewed/2025/05/GHSA-746r-3x8x-jmcc/GHSA-746r-3x8x-jmcc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-74m8-698c-prjf/GHSA-74m8-698c-prjf.json b/advisories/unreviewed/2025/05/GHSA-74m8-698c-prjf/GHSA-74m8-698c-prjf.json new file mode 100644 index 00000000000..6d224251a9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-74m8-698c-prjf/GHSA-74m8-698c-prjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74m8-698c-prjf", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-0135" + ], + "details": "An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app.\n\nThe GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0135" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json b/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json new file mode 100644 index 00000000000..e7b684211f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78rr-5vrh-jhqh", + "modified": "2025-05-14T21:31:17Z", + "published": "2025-05-14T21:31:17Z", + "aliases": [ + "CVE-2025-0131" + ], + "details": "An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:X/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0131" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0131" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8m4f-v87c-8xhm/GHSA-8m4f-v87c-8xhm.json b/advisories/unreviewed/2025/05/GHSA-8m4f-v87c-8xhm/GHSA-8m4f-v87c-8xhm.json new file mode 100644 index 00000000000..92482b51a48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8m4f-v87c-8xhm/GHSA-8m4f-v87c-8xhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m4f-v87c-8xhm", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-0137" + ], + "details": "An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator.\n\n\nThe attacker must have network access to the management web interface to exploit this issue. You greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0137" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0137" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-83" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json b/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json index 270312d1242..651ca205254 100644 --- a/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json +++ b/advisories/unreviewed/2025/05/GHSA-98vp-fcq9-gmj3/GHSA-98vp-fcq9-gmj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98vp-fcq9-gmj3", - "modified": "2025-05-14T18:30:48Z", + "modified": "2025-05-14T21:31:17Z", "published": "2025-05-14T18:30:48Z", "aliases": [ "CVE-2025-40595" ], "details": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9wg5-mqr8-x4m3/GHSA-9wg5-mqr8-x4m3.json b/advisories/unreviewed/2025/05/GHSA-9wg5-mqr8-x4m3/GHSA-9wg5-mqr8-x4m3.json new file mode 100644 index 00000000000..f4d6f481e43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9wg5-mqr8-x4m3/GHSA-9wg5-mqr8-x4m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wg5-mqr8-x4m3", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-0136" + ], + "details": "Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec.\n\nThis issue does not affect Cloud NGFWs, Prisma® Access instances, or PAN-OS VM-Series firewalls.\n\nNOTE: The AES-128-CCM encryption algorithm is not recommended for use.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0136" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0136" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c644-3mgg-w2j9/GHSA-c644-3mgg-w2j9.json b/advisories/unreviewed/2025/05/GHSA-c644-3mgg-w2j9/GHSA-c644-3mgg-w2j9.json new file mode 100644 index 00000000000..4378c036ed1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c644-3mgg-w2j9/GHSA-c644-3mgg-w2j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c644-3mgg-w2j9", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-33104" + ], + "details": "IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33104" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233438" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json b/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json new file mode 100644 index 00000000000..95125026f65 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cp9r-g575-xc5f/GHSA-cp9r-g575-xc5f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp9r-g575-xc5f", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47888" + ], + "details": "Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47888" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3353" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json b/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json new file mode 100644 index 00000000000..18d8c8f9fd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f89j-4hpj-5qjm", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2024-45516" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the victim's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, including malformed tags with embedded JavaScript. The vulnerability is triggered when the victim views a specially crafted email in the Classic UI, causing the malicious script to execute. No further user interaction is required beyond viewing the email.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45516" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g6jr-84fr-8jwx/GHSA-g6jr-84fr-8jwx.json b/advisories/unreviewed/2025/05/GHSA-g6jr-84fr-8jwx/GHSA-g6jr-84fr-8jwx.json index 77d6dd76301..361a24497ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-g6jr-84fr-8jwx/GHSA-g6jr-84fr-8jwx.json +++ b/advisories/unreviewed/2025/05/GHSA-g6jr-84fr-8jwx/GHSA-g6jr-84fr-8jwx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json b/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json new file mode 100644 index 00000000000..ffa83752864 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ghrr-gjmc-qq88/GHSA-ghrr-gjmc-qq88.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghrr-gjmc-qq88", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-26783" + ], + "details": "An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26783" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-26783" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ghvv-mg26-g3c9/GHSA-ghvv-mg26-g3c9.json b/advisories/unreviewed/2025/05/GHSA-ghvv-mg26-g3c9/GHSA-ghvv-mg26-g3c9.json new file mode 100644 index 00000000000..d3bb6d0c7b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ghvv-mg26-g3c9/GHSA-ghvv-mg26-g3c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghvv-mg26-g3c9", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-0134" + ], + "details": "A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0134" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0134" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json b/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json new file mode 100644 index 00000000000..255e17e1203 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gwqp-vrqv-c9q6/GHSA-gwqp-vrqv-c9q6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwqp-vrqv-c9q6", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2024-58101" + ], + "details": "Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58101" + }, + { + "type": "WEB", + "url": "https://www.tarlogic.com/blog/cve-2024-58101" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gx4r-c3v7-5x28/GHSA-gx4r-c3v7-5x28.json b/advisories/unreviewed/2025/05/GHSA-gx4r-c3v7-5x28/GHSA-gx4r-c3v7-5x28.json new file mode 100644 index 00000000000..68bc08a23e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gx4r-c3v7-5x28/GHSA-gx4r-c3v7-5x28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx4r-c3v7-5x28", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-0138" + ], + "details": "Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.\n\nCompute in Prisma Cloud Enterprise Edition is not affected by this issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0138" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hgrp-p24x-8rqw/GHSA-hgrp-p24x-8rqw.json b/advisories/unreviewed/2025/05/GHSA-hgrp-p24x-8rqw/GHSA-hgrp-p24x-8rqw.json index 6b653bc1975..1443672a727 100644 --- a/advisories/unreviewed/2025/05/GHSA-hgrp-p24x-8rqw/GHSA-hgrp-p24x-8rqw.json +++ b/advisories/unreviewed/2025/05/GHSA-hgrp-p24x-8rqw/GHSA-hgrp-p24x-8rqw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json b/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json new file mode 100644 index 00000000000..97af81065f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j92j-6p6g-x235/GHSA-j92j-6p6g-x235.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j92j-6p6g-x235", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2024-57096" + ], + "details": "An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57096" + }, + { + "type": "WEB", + "url": "https://github.com/paokuwansui/wps_exp/blob/main/README" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json b/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json new file mode 100644 index 00000000000..672f8fe7714 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m7cj-8qx5-j738/GHSA-m7cj-8qx5-j738.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7cj-8qx5-j738", + "modified": "2025-05-14T21:31:19Z", + "published": "2025-05-14T21:31:19Z", + "aliases": [ + "CVE-2025-25370" + ], + "details": "An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25370" + }, + { + "type": "WEB", + "url": "https://gist.github.com/krl5/4eeed04a065287489c2e606e6d48c1bc" + }, + { + "type": "WEB", + "url": "http://realme.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json b/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json new file mode 100644 index 00000000000..049f0feab10 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p2h7-5rp6-x3fx/GHSA-p2h7-5rp6-x3fx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2h7-5rp6-x3fx", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-27891" + ], + "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The lack of a length check leads to out-of-bounds reads via malformed NAS packets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27891" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-27891" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p89h-p4ph-4vj6/GHSA-p89h-p4ph-4vj6.json b/advisories/unreviewed/2025/05/GHSA-p89h-p4ph-4vj6/GHSA-p89h-p4ph-4vj6.json new file mode 100644 index 00000000000..956b44ebe7a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p89h-p4ph-4vj6/GHSA-p89h-p4ph-4vj6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p89h-p4ph-4vj6", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47889" + ], + "details": "In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the \"WSO2 Oauth\" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47889" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3481" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p8p5-5q8p-vwcr/GHSA-p8p5-5q8p-vwcr.json b/advisories/unreviewed/2025/05/GHSA-p8p5-5q8p-vwcr/GHSA-p8p5-5q8p-vwcr.json index 8db081dde22..1758cb205fb 100644 --- a/advisories/unreviewed/2025/05/GHSA-p8p5-5q8p-vwcr/GHSA-p8p5-5q8p-vwcr.json +++ b/advisories/unreviewed/2025/05/GHSA-p8p5-5q8p-vwcr/GHSA-p8p5-5q8p-vwcr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pwm3-776c-8q7q/GHSA-pwm3-776c-8q7q.json b/advisories/unreviewed/2025/05/GHSA-pwm3-776c-8q7q/GHSA-pwm3-776c-8q7q.json new file mode 100644 index 00000000000..f3f05b1d2be --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pwm3-776c-8q7q/GHSA-pwm3-776c-8q7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwm3-776c-8q7q", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-4641" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java.\n\nThis issue affects webdrivermanager: from 1.0.0 before 6.0.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4641" + }, + { + "type": "WEB", + "url": "https://github.com/bonigarcia/webdrivermanager/pull/1458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7c3-x7hm-qq72/GHSA-q7c3-x7hm-qq72.json b/advisories/unreviewed/2025/05/GHSA-q7c3-x7hm-qq72/GHSA-q7c3-x7hm-qq72.json new file mode 100644 index 00000000000..51604ba2171 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7c3-x7hm-qq72/GHSA-q7c3-x7hm-qq72.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7c3-x7hm-qq72", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47884" + ], + "details": "In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47884" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3574" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r93p-9jjr-wjhj/GHSA-r93p-9jjr-wjhj.json b/advisories/unreviewed/2025/05/GHSA-r93p-9jjr-wjhj/GHSA-r93p-9jjr-wjhj.json new file mode 100644 index 00000000000..3af864cea75 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r93p-9jjr-wjhj/GHSA-r93p-9jjr-wjhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r93p-9jjr-wjhj", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:17Z", + "aliases": [ + "CVE-2025-0133" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN.\n\nThere is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal.\n\n\n\nFor GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0133" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0133" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rf73-97j8-9vqh/GHSA-rf73-97j8-9vqh.json b/advisories/unreviewed/2025/05/GHSA-rf73-97j8-9vqh/GHSA-rf73-97j8-9vqh.json new file mode 100644 index 00000000000..8abfeb78523 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rf73-97j8-9vqh/GHSA-rf73-97j8-9vqh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf73-97j8-9vqh", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47887" + ], + "details": "Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47887" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3548" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rmcv-f79g-83q3/GHSA-rmcv-f79g-83q3.json b/advisories/unreviewed/2025/05/GHSA-rmcv-f79g-83q3/GHSA-rmcv-f79g-83q3.json index 386808c17e5..7aeddcda9e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-rmcv-f79g-83q3/GHSA-rmcv-f79g-83q3.json +++ b/advisories/unreviewed/2025/05/GHSA-rmcv-f79g-83q3/GHSA-rmcv-f79g-83q3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vrqw-478g-gv6h/GHSA-vrqw-478g-gv6h.json b/advisories/unreviewed/2025/05/GHSA-vrqw-478g-gv6h/GHSA-vrqw-478g-gv6h.json new file mode 100644 index 00000000000..782817df80c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrqw-478g-gv6h/GHSA-vrqw-478g-gv6h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrqw-478g-gv6h", + "modified": "2025-05-14T21:31:18Z", + "published": "2025-05-14T21:31:18Z", + "aliases": [ + "CVE-2025-4640" + ], + "details": "Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4640" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/pull/6246" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac" + }, + { + "type": "WEB", + "url": "https://github.com/PointCloudLibrary/pcl/blob/master/surface/CMakeLists.txt#L70" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T19:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json b/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json index 56c8f06fab6..a04e3ef932a 100644 --- a/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json +++ b/advisories/unreviewed/2025/05/GHSA-vxhm-55mv-5fhx/GHSA-vxhm-55mv-5fhx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vxhm-55mv-5fhx", - "modified": "2025-05-14T18:30:51Z", + "modified": "2025-05-14T21:31:17Z", "published": "2025-05-14T18:30:51Z", "aliases": [ "CVE-2025-4664" ], "details": "Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T18:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json b/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json new file mode 100644 index 00000000000..3b36095b2b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w899-x298-m75w/GHSA-w899-x298-m75w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w899-x298-m75w", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-44879" + ], + "details": "WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44879" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/03/17/Buffer%20Overflow%20in%20upload.cgi%20of%20WINSTAR_WN572HP3%20Device" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json b/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json index 8f3b1f9c801..701450fa764 100644 --- a/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json +++ b/advisories/unreviewed/2025/05/GHSA-x6ph-hgqm-c68g/GHSA-x6ph-hgqm-c68g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x6ph-hgqm-c68g", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-14T21:31:17Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31218" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the hostnames of new network connections.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xrpq-4g9w-qrwj/GHSA-xrpq-4g9w-qrwj.json b/advisories/unreviewed/2025/05/GHSA-xrpq-4g9w-qrwj/GHSA-xrpq-4g9w-qrwj.json new file mode 100644 index 00000000000..37c7f7edb72 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xrpq-4g9w-qrwj/GHSA-xrpq-4g9w-qrwj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrpq-4g9w-qrwj", + "modified": "2025-05-14T21:31:20Z", + "published": "2025-05-14T21:31:20Z", + "aliases": [ + "CVE-2025-47885" + ], + "details": "Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47885" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3559" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T21:15:59Z" + } +} \ No newline at end of file