Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-03 21:32:45 +00:00
parent 44e4ff3a28
commit 75cf5b4c4b
57 changed files with 1475 additions and 37 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29ph-8jj3-f6p6",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-03-03T21:30:55Z",
"published": "2023-03-13T15:30:19Z",
"aliases": [
"CVE-2023-26074"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html"
},
{
"type": "WEB",
"url": "https://project-zero.issues.chromium.org/issues/42451536"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/processor/mobile-processor"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5pgr-37hm-gqpw",
"modified": "2023-03-17T15:30:25Z",
"modified": "2025-03-03T21:30:54Z",
"published": "2023-03-13T12:30:17Z",
"aliases": [
"CVE-2023-24033"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-20"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8gcq-hc82-pqq2",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-03-03T21:30:55Z",
"published": "2023-03-13T15:30:19Z",
"aliases": [
"CVE-2023-24762"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24762"
},
{
"type": "WEB",
"url": "https://hackmd.io/%40uuXne2y3RjOdpWM87fw6_A/HyPK04zho"
},
{
"type": "WEB",
"url": "https://hackmd.io/@uuXne2y3RjOdpWM87fw6_A/HyPK04zho"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fj79-cqcm-7g2m",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-03-03T21:30:54Z",
"published": "2023-03-13T12:30:17Z",
"aliases": [
"CVE-2023-26072"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html"
},
{
"type": "WEB",
"url": "https://project-zero.issues.chromium.org/issues/42451534"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/processor/mobile-processor"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q978-xx62-9w9r",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-03-03T21:30:55Z",
"published": "2023-03-13T15:30:19Z",
"aliases": [
"CVE-2023-26073"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html"
},
{
"type": "WEB",
"url": "https://project-zero.issues.chromium.org/issues/42451535"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/processor/mobile-processor"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgrw-gggp-4wx3",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-03-03T21:30:55Z",
"published": "2023-03-13T21:30:39Z",
"aliases": [
"CVE-2023-25279"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x79p-xvfj-9wfq",
"modified": "2023-03-20T15:30:20Z",
"modified": "2025-03-03T21:30:54Z",
"published": "2023-03-13T06:30:25Z",
"aliases": [
"CVE-2022-2259"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-862"
],
"severity": "MODERATE",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p2q-7m86-j6ch",
"modified": "2025-02-21T18:31:15Z",
"modified": "2025-03-03T21:30:56Z",
"published": "2025-02-21T18:31:14Z",
"aliases": [
"CVE-2025-25766"
],
"details": "An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-21T18:16:12Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hwx-j6w8-9w2r",
"modified": "2025-02-21T21:32:08Z",
"modified": "2025-03-03T21:30:56Z",
"published": "2025-02-21T21:32:08Z",
"aliases": [
"CVE-2025-25767"
],
"details": "A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-21T19:15:14Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gghq-qp34-gqg8",
"modified": "2025-03-03T18:31:25Z",
"modified": "2025-03-03T21:30:56Z",
"published": "2025-02-12T15:32:02Z",
"aliases": [
"CVE-2025-1244"
@@ -47,6 +47,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2022"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2130"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:2157"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h76r-mvr3-76xg",
"modified": "2025-02-21T21:32:08Z",
"modified": "2025-03-03T21:30:56Z",
"published": "2025-02-21T21:32:08Z",
"aliases": [
"CVE-2025-25768"
],
"details": "MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \\servlet\\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-21T19:15:14Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw38-fx9m-f8jc",
"modified": "2025-02-21T18:31:15Z",
"modified": "2025-03-03T21:30:56Z",
"published": "2025-02-21T18:31:14Z",
"aliases": [
"CVE-2025-25765"
],
"details": "MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-21T18:16:12Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cj7-q7vw-gwx8",
"modified": "2025-03-03T21:31:01Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51966"
],
"details": "There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51966"
},
{
"type": "WEB",
"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T20:15:43Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qh6-98mm-p9vr",
"modified": "2025-03-03T21:31:00Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51953"
],
"details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51953"
},
{
"type": "WEB",
"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T20:15:41Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v56-g578-78g2",
"modified": "2025-03-03T21:31:01Z",
"published": "2025-03-03T21:31:01Z",
"aliases": [
"CVE-2025-1880"
],
"details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1880"
},
{
"type": "WEB",
"url": "https://github.com/geo-chen/i-Drive"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.298194"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.298194"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.510951"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T20:15:45Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42jw-v43h-79m9",
"modified": "2025-03-03T21:31:01Z",
"published": "2025-03-03T21:31:01Z",
"aliases": [
"CVE-2025-1882"
],
"details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1882"
},
{
"type": "WEB",
"url": "https://github.com/geo-chen/i-Drive"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.298196"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.298196"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.510955"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T21:15:18Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qxw-jwh4-2vjv",
"modified": "2025-03-02T06:33:26Z",
"modified": "2025-03-03T21:30:58Z",
"published": "2025-03-02T06:33:26Z",
"aliases": [
"CVE-2025-1809"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://github.com/yago3008/cves"
},
{
"type": "WEB",
"url": "https://github.com/yago3008/cves/tree/main/CVE-2025-1809"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.298067"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v9h-49hf-v7f8",
"modified": "2025-03-03T21:31:00Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51956"
],
"details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51956"
},
{
"type": "WEB",
"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T20:15:42Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5783-252r-fxpm",
"modified": "2025-03-03T21:30:59Z",
"published": "2025-03-03T21:30:59Z",
"aliases": [
"CVE-2024-10904"
],
"details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10904"
},
{
"type": "WEB",
"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T20:15:39Z"
}
}

Some files were not shown because too many files have changed in this diff Show More