From 753b046778fdc2eef5ecb913d4865a505c049628 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 3 May 2025 15:31:59 +0000 Subject: [PATCH] Publish Advisories GHSA-5w6m-x8hm-6jcv GHSA-f2f6-hpmx-3wwh GHSA-q4pq-24r3-gcxj --- .../GHSA-5w6m-x8hm-6jcv.json | 14 ++++- .../GHSA-f2f6-hpmx-3wwh.json | 52 +++++++++++++++++++ .../GHSA-q4pq-24r3-gcxj.json | 52 +++++++++++++++++++ 3 files changed, 117 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q4pq-24r3-gcxj/GHSA-q4pq-24r3-gcxj.json diff --git a/advisories/unreviewed/2025/05/GHSA-5w6m-x8hm-6jcv/GHSA-5w6m-x8hm-6jcv.json b/advisories/unreviewed/2025/05/GHSA-5w6m-x8hm-6jcv/GHSA-5w6m-x8hm-6jcv.json index 913b36a15d8..b5144fdb08c 100644 --- a/advisories/unreviewed/2025/05/GHSA-5w6m-x8hm-6jcv/GHSA-5w6m-x8hm-6jcv.json +++ b/advisories/unreviewed/2025/05/GHSA-5w6m-x8hm-6jcv/GHSA-5w6m-x8hm-6jcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w6m-x8hm-6jcv", - "modified": "2025-05-03T12:30:25Z", + "modified": "2025-05-03T15:30:25Z", "published": "2025-05-03T12:30:25Z", "aliases": [ "CVE-2025-37799" @@ -14,9 +14,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37799" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33e131a10459d16f181c8184d3f17f1c318c7002" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/4c2227656d9003f4d77afc76f34dd81b95e4c2c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4312c4d244aa58e811ff0297e013124d115e793" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3ad76e36a37b0ff4a71b06d5b33530ee8c3a177" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json b/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json new file mode 100644 index 00000000000..d930b419668 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f2f6-hpmx-3wwh/GHSA-f2f6-hpmx-3wwh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2f6-hpmx-3wwh", + "modified": "2025-05-03T15:30:25Z", + "published": "2025-05-03T15:30:25Z", + "aliases": [ + "CVE-2025-4236" + ], + "details": "A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4236" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-900150983cd24fb0d6963f7d28e17f72.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561510" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-03T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q4pq-24r3-gcxj/GHSA-q4pq-24r3-gcxj.json b/advisories/unreviewed/2025/05/GHSA-q4pq-24r3-gcxj/GHSA-q4pq-24r3-gcxj.json new file mode 100644 index 00000000000..0970870382c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q4pq-24r3-gcxj/GHSA-q4pq-24r3-gcxj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4pq-24r3-gcxj", + "modified": "2025-05-03T15:30:25Z", + "published": "2025-05-03T15:30:25Z", + "aliases": [ + "CVE-2025-4237" + ], + "details": "A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4237" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-c4ca4238a0b923820dcc509a6f75849b.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307328" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307328" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561536" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-03T15:15:46Z" + } +} \ No newline at end of file