diff --git a/advisories/unreviewed/2022/12/GHSA-27rh-8757-23p3/GHSA-27rh-8757-23p3.json b/advisories/unreviewed/2022/12/GHSA-27rh-8757-23p3/GHSA-27rh-8757-23p3.json index 32335e90f2b..9cdef15b782 100644 --- a/advisories/unreviewed/2022/12/GHSA-27rh-8757-23p3/GHSA-27rh-8757-23p3.json +++ b/advisories/unreviewed/2022/12/GHSA-27rh-8757-23p3/GHSA-27rh-8757-23p3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-39fv-f7h5-p7jp/GHSA-39fv-f7h5-p7jp.json b/advisories/unreviewed/2022/12/GHSA-39fv-f7h5-p7jp/GHSA-39fv-f7h5-p7jp.json index c9f4a855937..e313348fae0 100644 --- a/advisories/unreviewed/2022/12/GHSA-39fv-f7h5-p7jp/GHSA-39fv-f7h5-p7jp.json +++ b/advisories/unreviewed/2022/12/GHSA-39fv-f7h5-p7jp/GHSA-39fv-f7h5-p7jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-39fv-f7h5-p7jp", - "modified": "2022-12-30T00:30:42Z", + "modified": "2025-04-18T15:31:30Z", "published": "2022-12-22T21:30:30Z", "aliases": [ "CVE-2022-22752" diff --git a/advisories/unreviewed/2022/12/GHSA-456v-qxqw-v893/GHSA-456v-qxqw-v893.json b/advisories/unreviewed/2022/12/GHSA-456v-qxqw-v893/GHSA-456v-qxqw-v893.json index 5a016ec36b0..6657a14369c 100644 --- a/advisories/unreviewed/2022/12/GHSA-456v-qxqw-v893/GHSA-456v-qxqw-v893.json +++ b/advisories/unreviewed/2022/12/GHSA-456v-qxqw-v893/GHSA-456v-qxqw-v893.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json b/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json index d4fad123995..3692b16e31a 100644 --- a/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json +++ b/advisories/unreviewed/2022/12/GHSA-664m-3r2m-mxpx/GHSA-664m-3r2m-mxpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-664m-3r2m-mxpx", - "modified": "2022-12-22T18:30:24Z", + "modified": "2025-04-18T15:31:30Z", "published": "2022-12-17T00:30:20Z", "aliases": [ "CVE-2022-38756" @@ -19,10 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38756" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/170768" + }, { "type": "WEB", "url": "https://portal.microfocus.com/s/article/KM000012374?language=en_US" }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2023/Jan/28" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/170768/Micro-Focus-GroupWise-Session-ID-Disclosure.html" diff --git a/advisories/unreviewed/2022/12/GHSA-6rx4-xv8f-g72g/GHSA-6rx4-xv8f-g72g.json b/advisories/unreviewed/2022/12/GHSA-6rx4-xv8f-g72g/GHSA-6rx4-xv8f-g72g.json index 62d015c6917..225c447df36 100644 --- a/advisories/unreviewed/2022/12/GHSA-6rx4-xv8f-g72g/GHSA-6rx4-xv8f-g72g.json +++ b/advisories/unreviewed/2022/12/GHSA-6rx4-xv8f-g72g/GHSA-6rx4-xv8f-g72g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-96wv-f87p-4445/GHSA-96wv-f87p-4445.json b/advisories/unreviewed/2022/12/GHSA-96wv-f87p-4445/GHSA-96wv-f87p-4445.json index 873951ae0b5..c93da415755 100644 --- a/advisories/unreviewed/2022/12/GHSA-96wv-f87p-4445/GHSA-96wv-f87p-4445.json +++ b/advisories/unreviewed/2022/12/GHSA-96wv-f87p-4445/GHSA-96wv-f87p-4445.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-9795-p8hc-23wx/GHSA-9795-p8hc-23wx.json b/advisories/unreviewed/2022/12/GHSA-9795-p8hc-23wx/GHSA-9795-p8hc-23wx.json index fe402bf2daa..ee0ba5ea5ce 100644 --- a/advisories/unreviewed/2022/12/GHSA-9795-p8hc-23wx/GHSA-9795-p8hc-23wx.json +++ b/advisories/unreviewed/2022/12/GHSA-9795-p8hc-23wx/GHSA-9795-p8hc-23wx.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json b/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json index e706e831f80..227f5903b29 100644 --- a/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json +++ b/advisories/unreviewed/2022/12/GHSA-999r-r2f8-xm55/GHSA-999r-r2f8-xm55.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-999r-r2f8-xm55", - "modified": "2022-12-22T18:30:24Z", + "modified": "2025-04-18T15:31:30Z", "published": "2022-12-17T00:30:21Z", "aliases": [ "CVE-2022-37832" diff --git a/advisories/unreviewed/2022/12/GHSA-c553-7q8c-vqg8/GHSA-c553-7q8c-vqg8.json b/advisories/unreviewed/2022/12/GHSA-c553-7q8c-vqg8/GHSA-c553-7q8c-vqg8.json index ac78c06defc..262d4c8888a 100644 --- a/advisories/unreviewed/2022/12/GHSA-c553-7q8c-vqg8/GHSA-c553-7q8c-vqg8.json +++ b/advisories/unreviewed/2022/12/GHSA-c553-7q8c-vqg8/GHSA-c553-7q8c-vqg8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-ggc6-8q3j-pc53/GHSA-ggc6-8q3j-pc53.json b/advisories/unreviewed/2022/12/GHSA-ggc6-8q3j-pc53/GHSA-ggc6-8q3j-pc53.json index 6282eebed11..1a713155694 100644 --- a/advisories/unreviewed/2022/12/GHSA-ggc6-8q3j-pc53/GHSA-ggc6-8q3j-pc53.json +++ b/advisories/unreviewed/2022/12/GHSA-ggc6-8q3j-pc53/GHSA-ggc6-8q3j-pc53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-r877-389w-8vx8/GHSA-r877-389w-8vx8.json b/advisories/unreviewed/2022/12/GHSA-r877-389w-8vx8/GHSA-r877-389w-8vx8.json index 5db4fdd4f69..b95e6f55bb7 100644 --- a/advisories/unreviewed/2022/12/GHSA-r877-389w-8vx8/GHSA-r877-389w-8vx8.json +++ b/advisories/unreviewed/2022/12/GHSA-r877-389w-8vx8/GHSA-r877-389w-8vx8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-v274-gp7p-3x89/GHSA-v274-gp7p-3x89.json b/advisories/unreviewed/2022/12/GHSA-v274-gp7p-3x89/GHSA-v274-gp7p-3x89.json index e57ce14865c..d7b22ac0708 100644 --- a/advisories/unreviewed/2022/12/GHSA-v274-gp7p-3x89/GHSA-v274-gp7p-3x89.json +++ b/advisories/unreviewed/2022/12/GHSA-v274-gp7p-3x89/GHSA-v274-gp7p-3x89.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w66w-cmgq-cc2j/GHSA-w66w-cmgq-cc2j.json b/advisories/unreviewed/2022/12/GHSA-w66w-cmgq-cc2j/GHSA-w66w-cmgq-cc2j.json index 13a62eb0306..2154236da71 100644 --- a/advisories/unreviewed/2022/12/GHSA-w66w-cmgq-cc2j/GHSA-w66w-cmgq-cc2j.json +++ b/advisories/unreviewed/2022/12/GHSA-w66w-cmgq-cc2j/GHSA-w66w-cmgq-cc2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w66w-cmgq-cc2j", - "modified": "2022-12-20T18:30:19Z", + "modified": "2025-04-18T15:31:26Z", "published": "2022-12-20T18:30:19Z", "aliases": [ "CVE-2022-36223" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36223" }, + { + "type": "WEB", + "url": "https://medium.com/%40cupc4k3/administrator-account-takeover-in-emby-media-server-616fc2a6704f" + }, { "type": "WEB", "url": "https://medium.com/@cupc4k3/administrator-account-takeover-in-emby-media-server-616fc2a6704f" + }, + { + "type": "WEB", + "url": "https://medium.com/stolabs/cve-2022-36223-administrator-account-takeover-in-emby-media-server-616fc2a6704f" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-wf52-hx48-jm6v/GHSA-wf52-hx48-jm6v.json b/advisories/unreviewed/2022/12/GHSA-wf52-hx48-jm6v/GHSA-wf52-hx48-jm6v.json index 4aae46ddbde..fd0ee654d85 100644 --- a/advisories/unreviewed/2022/12/GHSA-wf52-hx48-jm6v/GHSA-wf52-hx48-jm6v.json +++ b/advisories/unreviewed/2022/12/GHSA-wf52-hx48-jm6v/GHSA-wf52-hx48-jm6v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json b/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json index a2db1f3f265..3e04212b423 100644 --- a/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json +++ b/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4446-w42r-xvj9", - "modified": "2023-08-08T15:33:24Z", + "modified": "2025-04-18T15:31:29Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-25626" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-425" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vcqc-mr3x-q7wh/GHSA-vcqc-mr3x-q7wh.json b/advisories/unreviewed/2024/03/GHSA-vcqc-mr3x-q7wh/GHSA-vcqc-mr3x-q7wh.json index 494625e7f6a..16d9361912c 100644 --- a/advisories/unreviewed/2024/03/GHSA-vcqc-mr3x-q7wh/GHSA-vcqc-mr3x-q7wh.json +++ b/advisories/unreviewed/2024/03/GHSA-vcqc-mr3x-q7wh/GHSA-vcqc-mr3x-q7wh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json b/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json index dc093b4b250..d0cf28a134e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json +++ b/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9g26-4h79-vm4x/GHSA-9g26-4h79-vm4x.json b/advisories/unreviewed/2024/05/GHSA-9g26-4h79-vm4x/GHSA-9g26-4h79-vm4x.json index ce1df865b6b..0337a2ea165 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g26-4h79-vm4x/GHSA-9g26-4h79-vm4x.json +++ b/advisories/unreviewed/2024/05/GHSA-9g26-4h79-vm4x/GHSA-9g26-4h79-vm4x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9g26-4h79-vm4x", - "modified": "2024-05-06T06:30:45Z", + "modified": "2025-04-18T15:31:31Z", "published": "2024-05-06T06:30:45Z", "aliases": [ "CVE-2024-3755" ], "details": "The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T06:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json index fde5cc89220..a6e4b2f9de2 100644 --- a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json +++ b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpx5-6mwc-hxp6", - "modified": "2024-07-03T18:40:34Z", + "modified": "2025-04-18T15:31:32Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32615" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32615" }, + { + "type": "WEB", + "url": "https://github.com/HDFGroup/cve_hdf5/blob/main/CVE_list.md" + }, { "type": "WEB", "url": "https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4" diff --git a/advisories/unreviewed/2024/05/GHSA-ph4r-cprg-444j/GHSA-ph4r-cprg-444j.json b/advisories/unreviewed/2024/05/GHSA-ph4r-cprg-444j/GHSA-ph4r-cprg-444j.json index 7d87c3a8168..2fdac5456e3 100644 --- a/advisories/unreviewed/2024/05/GHSA-ph4r-cprg-444j/GHSA-ph4r-cprg-444j.json +++ b/advisories/unreviewed/2024/05/GHSA-ph4r-cprg-444j/GHSA-ph4r-cprg-444j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-5qg8-89vj-3364/GHSA-5qg8-89vj-3364.json b/advisories/unreviewed/2024/12/GHSA-5qg8-89vj-3364/GHSA-5qg8-89vj-3364.json index 0e32717e397..9f73ba59e1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-5qg8-89vj-3364/GHSA-5qg8-89vj-3364.json +++ b/advisories/unreviewed/2024/12/GHSA-5qg8-89vj-3364/GHSA-5qg8-89vj-3364.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qg8-89vj-3364", - "modified": "2024-12-28T12:30:48Z", + "modified": "2025-04-18T15:31:34Z", "published": "2024-12-28T12:30:48Z", "aliases": [ "CVE-2024-56705" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/4676e50444046b498555b849e6080a5c78cdda9b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/74aa783682c4d78c69d87898e40c78df1fec204e" diff --git a/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json b/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json index 8dd0928325a..7339f7d3ef8 100644 --- a/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json +++ b/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-889v-7c4r-6cg6", - "modified": "2025-01-14T18:31:53Z", + "modified": "2025-04-18T15:31:34Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53205" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/0b398b6b6c94315fd2ce3658e3cee96539dbd7b7" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a784bcdd7e54f0599da3b2360e472238412623e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e2cde1813418b39b5e95d86e10d6701dccf18af" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fb83c9a08324e37f321ffb400809aa4310387d65" diff --git a/advisories/unreviewed/2024/12/GHSA-fh52-7j8h-w7j3/GHSA-fh52-7j8h-w7j3.json b/advisories/unreviewed/2024/12/GHSA-fh52-7j8h-w7j3/GHSA-fh52-7j8h-w7j3.json index c0693440b38..79c62620ce8 100644 --- a/advisories/unreviewed/2024/12/GHSA-fh52-7j8h-w7j3/GHSA-fh52-7j8h-w7j3.json +++ b/advisories/unreviewed/2024/12/GHSA-fh52-7j8h-w7j3/GHSA-fh52-7j8h-w7j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fh52-7j8h-w7j3", - "modified": "2025-01-13T21:30:48Z", + "modified": "2025-04-18T15:31:33Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53204" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53204" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/258ea41c926b7b3a16d0d7aa210a1401c4a1601b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/48d52d3168749e10c1c37cd4ceccd18625851741" @@ -30,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/bf373d2919d98f3d1fe1b19a0304f72fe74386d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e27877990e54bfe4246dd850f7ec8646c999ce58" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json b/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json index 0e1bbb065c2..d2cdc485e12 100644 --- a/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json +++ b/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22cf-67wm-xj29", - "modified": "2025-03-05T15:30:51Z", + "modified": "2025-04-18T15:31:34Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-25951" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89638" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25951" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json b/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json index 4daa10ef045..74f08318abc 100644 --- a/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json +++ b/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27hr-9v6h-xmx3", - "modified": "2025-03-05T18:32:03Z", + "modified": "2025-04-18T15:31:35Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-25952" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89639" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25952" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json b/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json index 078f26eeadd..f9275567570 100644 --- a/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json +++ b/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44rm-j4gx-rrg2", - "modified": "2025-03-05T18:32:03Z", + "modified": "2025-04-18T15:31:34Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-25950" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89637" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25950" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json b/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json index 23fbde70836..8d393af9bc9 100644 --- a/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json +++ b/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-634g-m7q6-xphf", - "modified": "2025-03-05T18:32:03Z", + "modified": "2025-04-18T15:31:35Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-25953" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89640" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25953" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json index 548299c6cbd..a06b21757dc 100644 --- a/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json +++ b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8x3-4xx7-hm4v", - "modified": "2025-03-04T18:33:27Z", + "modified": "2025-04-18T15:31:34Z", "published": "2025-03-03T03:31:17Z", "aliases": [ "CVE-2025-25949" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89636" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25949" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json b/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json index f73465dd3fe..adedf9bac7e 100644 --- a/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json +++ b/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q269-fjx3-x255", - "modified": "2025-03-05T18:32:03Z", + "modified": "2025-04-18T15:31:34Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-25948" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-53637" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2025-25948" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-24g7-95rm-cqcc/GHSA-24g7-95rm-cqcc.json b/advisories/unreviewed/2025/04/GHSA-24g7-95rm-cqcc/GHSA-24g7-95rm-cqcc.json new file mode 100644 index 00000000000..5bc6069dce6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24g7-95rm-cqcc/GHSA-24g7-95rm-cqcc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24g7-95rm-cqcc", + "modified": "2025-04-18T15:31:39Z", + "published": "2025-04-18T15:31:39Z", + "aliases": [ + "CVE-2025-40364" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix io_req_prep_async with provided buffers\n\nio_req_prep_async() can import provided buffers, commit the ring state\nby giving up on that before, it'll be reimported later if needed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40364" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1b17713b32c75a90132ea2f92b1257f3bbc20f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json index 17149f81d4a..03353209c7f 100644 --- a/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json +++ b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24j3-w3xq-4r3w", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29460" ], "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2627-h6q4-h8xq/GHSA-2627-h6q4-h8xq.json b/advisories/unreviewed/2025/04/GHSA-2627-h6q4-h8xq/GHSA-2627-h6q4-h8xq.json new file mode 100644 index 00000000000..64618e8e7b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2627-h6q4-h8xq/GHSA-2627-h6q4-h8xq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2627-h6q4-h8xq", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38240" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr\n\nThe function mtk_dp_wait_hpd_asserted() may be called before the\n`mtk_dp->drm_dev` pointer is assigned in mtk_dp_bridge_attach().\nSpecifically it can be called via this callpath:\n - mtk_edp_wait_hpd_asserted\n - [panel probe]\n - dp_aux_ep_probe\n\nUsing \"drm\" level prints anywhere in this callpath causes a NULL\npointer dereference. Change the error message directly in\nmtk_dp_wait_hpd_asserted() to dev_err() to avoid this. Also change the\nerror messages in mtk_dp_parse_capabilities(), which is called by\nmtk_dp_wait_hpd_asserted().\n\nWhile touching these prints, also add the error code to them to make\nfuture debugging easier.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/106a6de46cf4887d535018185ec528ce822d6d84" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13ec849fd2eab808ee8eba2625df7ebea3b85edf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/149a5c38436c229950cf1020992ce65c9549bc19" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fda391ef7a701748abd7fa32232981b522c1e07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57a9fb47551b33cde7b76d17c0072c3b394f4620" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2gp8-xhxh-8h9c/GHSA-2gp8-xhxh-8h9c.json b/advisories/unreviewed/2025/04/GHSA-2gp8-xhxh-8h9c/GHSA-2gp8-xhxh-8h9c.json new file mode 100644 index 00000000000..35649cc7eb9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2gp8-xhxh-8h9c/GHSA-2gp8-xhxh-8h9c.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gp8-xhxh-8h9c", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38152" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: core: Clear table_sz when rproc_shutdown\n\nThere is case as below could trigger kernel dump:\nUse U-Boot to start remote processor(rproc) with resource table\npublished to a fixed address by rproc. After Kernel boots up,\nstop the rproc, load a new firmware which doesn't have resource table\n,and start rproc.\n\nWhen starting rproc with a firmware not have resource table,\n`memcpy(loaded_table, rproc->cached_table, rproc->table_sz)` will\ntrigger dump, because rproc->cache_table is set to NULL during the last\nstop operation, but rproc->table_sz is still valid.\n\nThis issue is found on i.MX8MP and i.MX9.\n\nDump as below:\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\nMem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\nuser pgtable: 4k pages, 48-bit VAs, pgdp=000000010af63000\n[0000000000000000] pgd=0000000000000000, p4d=0000000000000000\nInternal error: Oops: 0000000096000004 [#1] PREEMPT SMP\nModules linked in:\nCPU: 2 UID: 0 PID: 1060 Comm: sh Not tainted 6.14.0-rc7-next-20250317-dirty #38\nHardware name: NXP i.MX8MPlus EVK board (DT)\npstate: a0000005 (NzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : __pi_memcpy_generic+0x110/0x22c\nlr : rproc_start+0x88/0x1e0\nCall trace:\n __pi_memcpy_generic+0x110/0x22c (P)\n rproc_boot+0x198/0x57c\n state_store+0x40/0x104\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x7c/0x94\n kernfs_fop_write_iter+0x120/0x1cc\n vfs_write+0x240/0x378\n ksys_write+0x70/0x108\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x48/0x10c\n el0_svc_common.constprop.0+0xc0/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xcc\n el0t_64_sync_handler+0x10c/0x138\n el0t_64_sync+0x198/0x19c\n\nClear rproc->table_sz to address the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38152" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/068f6648ff5b0c7adeb6c363fae7fb188aa178fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2df19f5f6f72da6f6ebab7cdb3a3b9f7686bb476" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e66bca8cd51ebedd5d32426906a38e4a3c69c5f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c6bb82a6f3da6ab2d3fbea03901482231708b98" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e0fd2a3b9852ac3cf540edb06ccc0153b38b5af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6015ca453b82ec54aec9682dcc38773948fcc48" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efdde3d73ab25cef4ff2d06783b0aad8b093c0e4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json b/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json new file mode 100644 index 00000000000..fc2c8c756f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2h4h-cj8f-67g5/GHSA-2h4h-cj8f-67g5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h4h-cj8f-67g5", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39778" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nobjtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show()\n\nThe csts_state_names[] array only has six sparse entries, but the\niteration code in nvmet_ctrl_state_show() iterates seven, resulting in a\npotential out-of-bounds stack read. Fix that.\n\nFixes the following warning with an UBSAN kernel:\n\n vmlinux.o: warning: objtool: .text.nvmet_ctrl_state_show: unexpected end of section", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39778" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cc0efc58d6c741b2868d4af24874d7fec28a575" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/107a23185d990e3df6638d9a84c835f963fe30a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1adc93a525fdee8e2b311e6d5fd93eb69714ca05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fbf37a3577b4d64c150cafde338eee17b2f2ea4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json index d244dec90b3..2e9ebcd9723 100644 --- a/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json +++ b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhw-4vw3-x335", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29459" ], "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3f85-ch4h-849r/GHSA-3f85-ch4h-849r.json b/advisories/unreviewed/2025/04/GHSA-3f85-ch4h-849r/GHSA-3f85-ch4h-849r.json new file mode 100644 index 00000000000..4c7e5cab1a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3f85-ch4h-849r/GHSA-3f85-ch4h-849r.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f85-ch4h-849r", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38049" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors\n\nCommit\n\n 6eac36bb9eb0 (\"x86/resctrl: Allocate the cleanest CLOSID by searching closid_num_dirty_rmid\")\n\nadded logic that causes resctrl to search for the CLOSID with the fewest dirty\ncache lines when creating a new control group, if requested by the arch code.\nThis depends on the values read from the llc_occupancy counters. The logic is\napplicable to architectures where the CLOSID effectively forms part of the\nmonitoring identifier and so do not allow complete freedom to choose an unused\nmonitoring identifier for a given CLOSID.\n\nThis support missed that some platforms may not have these counters. This\ncauses a NULL pointer dereference when creating a new control group as the\narray was not allocated by dom_data_init().\n\nAs this feature isn't necessary on platforms that don't have cache occupancy\nmonitors, add this to the check that occurs when a new control group is\nallocated.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93a418fc61da13d1ee4047d4d1327990f7a2816a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a121798ae669351ec0697c94f71c3a692b2a755b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8a1bcc27d4607227088d80483164289b5348293" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed5addb55e403ad6598102bcf546e068ae01fef6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json b/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json new file mode 100644 index 00000000000..cc6ae21e2c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3xjw-75cj-9fvw/GHSA-3xjw-75cj-9fvw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xjw-75cj-9fvw", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-37893" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Fix off-by-one error in build_prologue()\n\nVincent reported that running BPF progs with tailcalls on LoongArch\ncauses kernel hard lockup. Debugging the issues shows that the JITed\nimage missing a jirl instruction at the end of the epilogue.\n\nThere are two passes in JIT compiling, the first pass set the flags and\nthe second pass generates JIT code based on those flags. With BPF progs\nmixing bpf2bpf and tailcalls, build_prologue() generates N insns in the\nfirst pass and then generates N+1 insns in the second pass. This makes\nepilogue_offset off by one and we will jump to some unexpected insn and\ncause lockup. Fix this by inserting a nop insn.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37893" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/205a2182c51ffebaef54d643e3745e720cded08b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48b904de2408af5f936f0e03f48dfcddeab58aa0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e2586991e36663c9bc48c828b83eab180ad30a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3ffad2f02db4aace6799fe0049508b8925eae45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c74d95a5679741ef428974ab788f5b0758dc78ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9ccb262b39ab01a5ac2e485b7996b8498e7b373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-425r-hmhf-r25x/GHSA-425r-hmhf-r25x.json b/advisories/unreviewed/2025/04/GHSA-425r-hmhf-r25x/GHSA-425r-hmhf-r25x.json new file mode 100644 index 00000000000..48c7cff481e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-425r-hmhf-r25x/GHSA-425r-hmhf-r25x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-425r-hmhf-r25x", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-40114" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: Add check for array bounds in veml6075_read_int_time_ms\n\nThe array contains only 5 elements, but the index calculated by\nveml6075_read_int_time_index can range from 0 to 7,\nwhich could lead to out-of-bounds access. The check prevents this issue.\n\nCoverity Issue\nCID 1574309: (#1 of 1): Out-of-bounds read (OVERRUN)\noverrun-local: Overrunning array veml6075_it_ms of 5 4-byte\nelements at element index 7 (byte offset 31) using\nindex int_index (which evaluates to 7)\n\nThis is hardening against potentially broken hardware. Good to have\nbut not necessary to backport.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18a08b5632809faa671279b3cd27d5f96cc5a3f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a40b52d4442178bee0cf1c36bc450ab951cef0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c40a68b7f97fa487e6c7e67fcf4f846a1f96692" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee735aa33db16c1fb5ebccbaf84ad38f5583f3cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4g98-mx94-f4wj/GHSA-4g98-mx94-f4wj.json b/advisories/unreviewed/2025/04/GHSA-4g98-mx94-f4wj/GHSA-4g98-mx94-f4wj.json new file mode 100644 index 00000000000..e99760fc5e1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4g98-mx94-f4wj/GHSA-4g98-mx94-f4wj.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g98-mx94-f4wj", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38479" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-edma: free irq correctly in remove path\n\nAdd fsl_edma->txirq/errirq check to avoid below warning because no\nerrirq at i.MX9 platform. Otherwise there will be kernel dump:\nWARNING: CPU: 0 PID: 11 at kernel/irq/devres.c:144 devm_free_irq+0x74/0x80\nModules linked in:\nCPU: 0 UID: 0 PID: 11 Comm: kworker/u8:0 Not tainted 6.12.0-rc7#18\nHardware name: NXP i.MX93 11X11 EVK board (DT)\nWorkqueue: events_unbound deferred_probe_work_func\npstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : devm_free_irq+0x74/0x80\nlr : devm_free_irq+0x48/0x80\nCall trace:\n devm_free_irq+0x74/0x80 (P)\n devm_free_irq+0x48/0x80 (L)\n fsl_edma_remove+0xc4/0xc8\n platform_remove+0x28/0x44\n device_remove+0x4c/0x80", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38479" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38ff8769074db27387cb2323aaa751e59d168e6a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55e2dbe2ba787d4fc2306f6bb2f43fb32176e184" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3834d2d68749e4760c27325149765930ad876fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa70c4c3c580c239a0f9e83a14770ab026e8d820" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json b/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json index 960d775731a..a48b1d296fc 100644 --- a/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json +++ b/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4xwm-8vcx-7p9c", - "modified": "2025-04-17T18:31:15Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T18:31:15Z", "aliases": [ "CVE-2025-29042" ], "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T16:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-532h-wp9v-fjxq/GHSA-532h-wp9v-fjxq.json b/advisories/unreviewed/2025/04/GHSA-532h-wp9v-fjxq/GHSA-532h-wp9v-fjxq.json new file mode 100644 index 00000000000..129ae566ae2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-532h-wp9v-fjxq/GHSA-532h-wp9v-fjxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-532h-wp9v-fjxq", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-2492" + ], + "details": "An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions.\n\n\nRefer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2492" + }, + { + "type": "WEB", + "url": "https://www.asus.com/content/asus-product-security-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-53x5-v4j3-g5xm/GHSA-53x5-v4j3-g5xm.json b/advisories/unreviewed/2025/04/GHSA-53x5-v4j3-g5xm/GHSA-53x5-v4j3-g5xm.json new file mode 100644 index 00000000000..93fd6a77c7d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-53x5-v4j3-g5xm/GHSA-53x5-v4j3-g5xm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53x5-v4j3-g5xm", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39688" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()\n\nThe pynfs DELEG8 test fails when run against nfsd. It acquires a\ndelegation and then lets the lease time out. It then tries to use the\ndeleg stateid and expects to see NFS4ERR_DELEG_REVOKED, but it gets\nbad NFS4ERR_BAD_STATEID instead.\n\nWhen a delegation is revoked, it's initially marked with\nSC_STATUS_REVOKED, or SC_STATUS_ADMIN_REVOKED and later, it's marked\nwith the SC_STATUS_FREEABLE flag, which denotes that it is waiting for\ns FREE_STATEID call.\n\nnfs4_lookup_stateid() accepts a statusmask that includes the status\nflags that a found stateid is allowed to have. Currently, that mask\nnever includes SC_STATUS_FREEABLE, which means that revoked delegations\nare (almost) never found.\n\nAdd SC_STATUS_FREEABLE to the always-allowed status flags, and remove it\nfrom nfsd4_delegreturn() since it's now always implied.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39688" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52e209203c35a4fbff8af23cd3613efe5df40102" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5bcb44e650bc4ec7eac23df90c5e011a77fa2beb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1bc15b147d35b4cb7ca99a9a7d79d41ca342c13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc6f3295905d7185e71091870119a8c11c3808cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5rj6-rcrv-5v5p/GHSA-5rj6-rcrv-5v5p.json b/advisories/unreviewed/2025/04/GHSA-5rj6-rcrv-5v5p/GHSA-5rj6-rcrv-5v5p.json new file mode 100644 index 00000000000..a2ab5f4082a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5rj6-rcrv-5v5p/GHSA-5rj6-rcrv-5v5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rj6-rcrv-5v5p", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-1863" + ], + "details": "Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all functions related to settings and operations. As a result, an attacker can illegally manipulate and configure important data such as measured values and settings.\nThis issue affects GX10 / GX20 / GP10 / GP20 Paperless Recorders: R5.04.01 or earlier; GM Data Acquisition System: R5.05.01 or earlier; DX1000 / DX2000 / DX1000N Paperless Recorders: R4.21 or earlier; FX1000 Paperless Recorders: R1.31 or earlier; μR10000 / μR20000 Chart Recorders: R1.51 or earlier; MW100 Data Acquisition Units: All versions; DX1000T / DX2000T Paperless Recorders: All versions; CX1000 / CX2000 Paperless Recorders: All versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1863" + }, + { + "type": "WEB", + "url": "https://web-material3.yokogawa.com/1/36974/files/YSAR-25-0001-E.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T06:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json b/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json index d9bd57d180b..3fdb001e5af 100644 --- a/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json +++ b/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5x7h-mx43-qfvx", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2025-25454" ], "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-65gg-hq36-f232/GHSA-65gg-hq36-f232.json b/advisories/unreviewed/2025/04/GHSA-65gg-hq36-f232/GHSA-65gg-hq36-f232.json new file mode 100644 index 00000000000..f839c3eab07 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-65gg-hq36-f232/GHSA-65gg-hq36-f232.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65gg-hq36-f232", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39728" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: samsung: Fix UBSAN panic in samsung_clk_init()\n\nWith UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to\ndereferencing `ctx->clk_data.hws` before setting\n`ctx->clk_data.num = nr_clks`. Move that up to fix the crash.\n\n UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP\n \n Call trace:\n samsung_clk_init+0x110/0x124 (P)\n samsung_clk_init+0x48/0x124 (L)\n samsung_cmu_register_one+0x3c/0xa0\n exynos_arm64_register_cmu+0x54/0x64\n __gs101_cmu_top_of_clk_init_declare+0x28/0x60\n ...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39728" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00307934eb94aaa0a99addfb37b9fe206f945004" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fef48f4a70e45a93e73c39023c3a6ea624714d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/157de9e48007a20c65d02fc0229a16f38134a72d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24307866e0ac0a5ddb462e766ceda5e27a6fbbe3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d29a6dcb51e346595a15b49693eeb728925ca43" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1500b98cd81a32fdfb9bc63c33bb9f0c2a0a1bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d19d7345a7bcdb083b65568a11b11adffe0687af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d974e177369c034984cece9d7d4fada9f8b9c740" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json b/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json new file mode 100644 index 00000000000..e1c45bd8b2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-68p2-2v8j-wr5h/GHSA-68p2-2v8j-wr5h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68p2-2v8j-wr5h", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3786" + ], + "details": "A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3786" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/cve/tree/AC15WifiExtraSet" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305609" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305609" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553703" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json index 5e1eaf8bd6e..fecc285c468 100644 --- a/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json +++ b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6rrc-vwrv-cwxc", - "modified": "2025-04-15T15:30:53Z", + "modified": "2025-04-18T15:31:36Z", "published": "2025-04-15T15:30:53Z", "aliases": [ "CVE-2025-3608" ], "details": "A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T13:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6vq9-8h9g-mcv6/GHSA-6vq9-8h9g-mcv6.json b/advisories/unreviewed/2025/04/GHSA-6vq9-8h9g-mcv6/GHSA-6vq9-8h9g-mcv6.json new file mode 100644 index 00000000000..fd42b88aa86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vq9-8h9g-mcv6/GHSA-6vq9-8h9g-mcv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vq9-8h9g-mcv6", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-39469" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pantherius Modal Survey allows Reflected XSS.This issue affects Modal Survey: from n/a through 2.0.2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/modal-survey/vulnerability/wordpress-modal-survey-plugin-2-0-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T05:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json b/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json index 9a9bb8583ab..04d8c24916f 100644 --- a/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json +++ b/advisories/unreviewed/2025/04/GHSA-7c77-7vhg-xpxp/GHSA-7c77-7vhg-xpxp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7c77-7vhg-xpxp", - "modified": "2025-04-17T15:32:36Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T15:32:36Z", "aliases": [ "CVE-2025-29044" ], "details": "Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:54Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7v2j-8c8w-fjmm/GHSA-7v2j-8c8w-fjmm.json b/advisories/unreviewed/2025/04/GHSA-7v2j-8c8w-fjmm/GHSA-7v2j-8c8w-fjmm.json new file mode 100644 index 00000000000..f78d862b635 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7v2j-8c8w-fjmm/GHSA-7v2j-8c8w-fjmm.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v2j-8c8w-fjmm", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3106" + ], + "details": "The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3106" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/assets/js/addons/tablet-contents.min.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3275257" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/lastudio-element-kit/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7c633419-e231-437f-a2af-6f564cffc2df?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7x5v-hwh5-w3m8/GHSA-7x5v-hwh5-w3m8.json b/advisories/unreviewed/2025/04/GHSA-7x5v-hwh5-w3m8/GHSA-7x5v-hwh5-w3m8.json new file mode 100644 index 00000000000..0fa34fd0113 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7x5v-hwh5-w3m8/GHSA-7x5v-hwh5-w3m8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x5v-hwh5-w3m8", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-39471" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pantherius Modal Survey.This issue affects Modal Survey: from n/a through 2.0.2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39471" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/modal-survey/vulnerability/wordpress-modal-survey-plugin-2-0-2-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T05:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json b/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json new file mode 100644 index 00000000000..8ef6d4fd5ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8ccv-3j8r-hx7f/GHSA-8ccv-3j8r-hx7f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ccv-3j8r-hx7f", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-37925" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: reject on-disk inodes of an unsupported type\n\nSyzbot has reported the following BUG:\n\nkernel BUG at fs/inode.c:668!\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 3 UID: 0 PID: 139 Comm: jfsCommit Not tainted 6.12.0-rc4-syzkaller-00085-g4e46774408d9 #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014\nRIP: 0010:clear_inode+0x168/0x190\nCode: 4c 89 f7 e8 ba fe e5 ff e9 61 ff ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 7c c1 4c 89 f7 e8 90 ff e5 ff eb b7\n 0b e8 01 5d 7f ff 90 0f 0b e8 f9 5c 7f ff 90 0f 0b e8 f1 5c 7f\nRSP: 0018:ffffc900027dfae8 EFLAGS: 00010093\nRAX: ffffffff82157a87 RBX: 0000000000000001 RCX: ffff888104d4b980\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000\nRBP: ffffc900027dfc90 R08: ffffffff82157977 R09: fffff520004fbf38\nR10: dffffc0000000000 R11: fffff520004fbf38 R12: dffffc0000000000\nR13: ffff88811315bc00 R14: ffff88811315bda8 R15: ffff88811315bb80\nFS: 0000000000000000(0000) GS:ffff888135f00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005565222e0578 CR3: 0000000026ef0000 CR4: 00000000000006f0\nCall Trace:\n \n ? __die_body+0x5f/0xb0\n ? die+0x9e/0xc0\n ? do_trap+0x15a/0x3a0\n ? clear_inode+0x168/0x190\n ? do_error_trap+0x1dc/0x2c0\n ? clear_inode+0x168/0x190\n ? __pfx_do_error_trap+0x10/0x10\n ? report_bug+0x3cd/0x500\n ? handle_invalid_op+0x34/0x40\n ? clear_inode+0x168/0x190\n ? exc_invalid_op+0x38/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? clear_inode+0x57/0x190\n ? clear_inode+0x167/0x190\n ? clear_inode+0x168/0x190\n ? clear_inode+0x167/0x190\n jfs_evict_inode+0xb5/0x440\n ? __pfx_jfs_evict_inode+0x10/0x10\n evict+0x4ea/0x9b0\n ? __pfx_evict+0x10/0x10\n ? iput+0x713/0xa50\n txUpdateMap+0x931/0xb10\n ? __pfx_txUpdateMap+0x10/0x10\n jfs_lazycommit+0x49a/0xb80\n ? _raw_spin_unlock_irqrestore+0x8f/0x140\n ? lockdep_hardirqs_on+0x99/0x150\n ? __pfx_jfs_lazycommit+0x10/0x10\n ? __pfx_default_wake_function+0x10/0x10\n ? __kthread_parkme+0x169/0x1d0\n ? __pfx_jfs_lazycommit+0x10/0x10\n kthread+0x2f2/0x390\n ? __pfx_jfs_lazycommit+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x4d/0x80\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nThis happens when 'clear_inode()' makes an attempt to finalize an underlying\nJFS inode of unknown type. According to JFS layout description from\nhttps://jfs.sourceforge.net/project/pub/jfslayout.pdf, inode types from 5 to\n15 are reserved for future extensions and should not be encountered on a valid\nfilesystem. So add an extra check for valid inode type in 'copy_from_dinode()'.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37925" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8987891c4653874d5e3f5d11f063912f4e0b58eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c3f9a70d2d4dd6c640afe294b05c6a0a45434d9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json index 59a6b124824..4671fc37960 100644 --- a/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json +++ b/advisories/unreviewed/2025/04/GHSA-8f6m-fvf9-6397/GHSA-8f6m-fvf9-6397.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-8fxv-494j-gqxv/GHSA-8fxv-494j-gqxv.json b/advisories/unreviewed/2025/04/GHSA-8fxv-494j-gqxv/GHSA-8fxv-494j-gqxv.json new file mode 100644 index 00000000000..2b7dfab7bec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fxv-494j-gqxv/GHSA-8fxv-494j-gqxv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxv-494j-gqxv", + "modified": "2025-04-18T15:31:39Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3788" + ], + "details": "A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /a/sys/user/save. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3788" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/JSite/XSS1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554565" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json b/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json index 72c5a727c88..17b80a03384 100644 --- a/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json +++ b/advisories/unreviewed/2025/04/GHSA-8qh5-83cf-f7qw/GHSA-8qh5-83cf-f7qw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qh5-83cf-f7qw", - "modified": "2025-04-17T15:32:37Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T15:32:37Z", "aliases": [ "CVE-2025-29047" ], "details": "Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json b/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json index c0e12573602..46c50fbff5a 100644 --- a/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json +++ b/advisories/unreviewed/2025/04/GHSA-8x2h-39pf-v8fc/GHSA-8x2h-39pf-v8fc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8x2h-39pf-v8fc", - "modified": "2025-04-17T15:32:37Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T15:32:37Z", "aliases": [ "CVE-2025-29046" ], "details": "Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9ghj-mrhr-8wxx/GHSA-9ghj-mrhr-8wxx.json b/advisories/unreviewed/2025/04/GHSA-9ghj-mrhr-8wxx/GHSA-9ghj-mrhr-8wxx.json new file mode 100644 index 00000000000..24f8102496e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9ghj-mrhr-8wxx/GHSA-9ghj-mrhr-8wxx.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ghj-mrhr-8wxx", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38637" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: skbprio: Remove overly strict queue assertions\n\nIn the current implementation, skbprio enqueue/dequeue contains an assertion\nthat fails under certain conditions when SKBPRIO is used as a child qdisc under\nTBF with specific parameters. The failure occurs because TBF sometimes peeks at\npackets in the child qdisc without actually dequeuing them when tokens are\nunavailable.\n\nThis peek operation creates a discrepancy between the parent and child qdisc\nqueue length counters. When TBF later receives a high-priority packet,\nSKBPRIO's queue length may show a different value than what's reflected in its\ninternal priority queue tracking, triggering the assertion.\n\nThe fix removes this overly strict assertions in SKBPRIO, they are not\nnecessary at all.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38637" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/034b293bf17c124fec0f0e663f81203b00aa7a50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1284733bab736e598341f1d3f3b94e2a322864a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dcc144c322a8d526b791135604c0663f1af9d85" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2286770b07cb5268c03d11274b8efd43dff0d380" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f35b7673a3aa3d09b3eb05811669622ebaa98ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32ee79682315e6d3c99947b3f38b078a09a66919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7abc8318ce0712182bf0783dcfdd9a6a8331160e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/864ca690ff135078d374bd565b9872f161c614bc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce8fe975fd99b49c29c42e50f2441ba53112b2e8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9q9v-qmg6-ffwc/GHSA-9q9v-qmg6-ffwc.json b/advisories/unreviewed/2025/04/GHSA-9q9v-qmg6-ffwc/GHSA-9q9v-qmg6-ffwc.json new file mode 100644 index 00000000000..210fe350dec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9q9v-qmg6-ffwc/GHSA-9q9v-qmg6-ffwc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q9v-qmg6-ffwc", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39930" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()\n\ncommit 419d1918105e (\"ASoC: simple-card-utils: use __free(device_node) for\ndevice node\") uses __free(device_node) for dlc->of_node, but we need to\nkeep it while driver is in use.\n\nDon't use __free(device_node) in graph_util_parse_dai().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39930" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/232a32e8a7e9be8a2ee238df9b5304eed2f4e195" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de74ec718e0788e1998eb7289ad07970e27cae27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cf3p-93cf-9wfg/GHSA-cf3p-93cf-9wfg.json b/advisories/unreviewed/2025/04/GHSA-cf3p-93cf-9wfg/GHSA-cf3p-93cf-9wfg.json new file mode 100644 index 00000000000..6301e86eead --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cf3p-93cf-9wfg/GHSA-cf3p-93cf-9wfg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf3p-93cf-9wfg", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3789" + ], + "details": "A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a/sys/area/save. The manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3789" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/JSite/XSS3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T13:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json b/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json index ca138eb6029..75b8c9cb091 100644 --- a/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json +++ b/advisories/unreviewed/2025/04/GHSA-chj7-pc2g-84px/GHSA-chj7-pc2g-84px.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chj7-pc2g-84px", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-29710" ], "details": "SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json b/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json index 0ebb8f1acba..bb6d746e9da 100644 --- a/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json +++ b/advisories/unreviewed/2025/04/GHSA-cphf-4pm4-j37r/GHSA-cphf-4pm4-j37r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cphf-4pm4-j37r", - "modified": "2025-04-17T15:32:37Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T15:32:37Z", "aliases": [ "CVE-2025-29045" ], "details": "Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T15:15:54Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f4cr-6p7w-h5xh/GHSA-f4cr-6p7w-h5xh.json b/advisories/unreviewed/2025/04/GHSA-f4cr-6p7w-h5xh/GHSA-f4cr-6p7w-h5xh.json new file mode 100644 index 00000000000..81c540745e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f4cr-6p7w-h5xh/GHSA-f4cr-6p7w-h5xh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4cr-6p7w-h5xh", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3790" + ], + "details": "A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache Druid Monitoring Console. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3790" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/JSite/durid%E6%9C%AA%E6%8E%88%E6%9D%83.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554572" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T13:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc4p-3956-4278/GHSA-fc4p-3956-4278.json b/advisories/unreviewed/2025/04/GHSA-fc4p-3956-4278/GHSA-fc4p-3956-4278.json new file mode 100644 index 00000000000..8261943703d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc4p-3956-4278/GHSA-fc4p-3956-4278.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc4p-3956-4278", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3056" + ], + "details": "The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3056" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3275196" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/download-manager/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dd9e6ba7-f107-4d7c-a7da-35e603f3a1a8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json b/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json new file mode 100644 index 00000000000..90dd3d249b0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ffc2-m4f8-5m2g/GHSA-ffc2-m4f8-5m2g.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffc2-m4f8-5m2g", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-2162" + ], + "details": "The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2162" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/06063788-7ab8-49cc-9911-1d9926fcf99d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T06:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgvj-q3hx-cpwr/GHSA-fgvj-q3hx-cpwr.json b/advisories/unreviewed/2025/04/GHSA-fgvj-q3hx-cpwr/GHSA-fgvj-q3hx-cpwr.json index 1b39970ac1c..0d8a837fc39 100644 --- a/advisories/unreviewed/2025/04/GHSA-fgvj-q3hx-cpwr/GHSA-fgvj-q3hx-cpwr.json +++ b/advisories/unreviewed/2025/04/GHSA-fgvj-q3hx-cpwr/GHSA-fgvj-q3hx-cpwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgvj-q3hx-cpwr", - "modified": "2025-04-18T03:31:22Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-18T03:31:22Z", "aliases": [ "CVE-2025-25427" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/slin99/2025-25427" + }, + { + "type": "WEB", + "url": "https://github.com/slin99/2025-25427/blob/master/readme.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-g6cq-6vg4-4hh5/GHSA-g6cq-6vg4-4hh5.json b/advisories/unreviewed/2025/04/GHSA-g6cq-6vg4-4hh5/GHSA-g6cq-6vg4-4hh5.json new file mode 100644 index 00000000000..70cac3d0615 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6cq-6vg4-4hh5/GHSA-g6cq-6vg4-4hh5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6cq-6vg4-4hh5", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2024-26014" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26014" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json b/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json index 7a6ffbc0b44..b4cc1f49080 100644 --- a/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json +++ b/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g9pc-8g42-g6vq", - "modified": "2025-04-08T21:31:40Z", + "modified": "2025-04-18T15:31:36Z", "published": "2025-04-08T21:31:40Z", "aliases": [ "CVE-2025-22871" ], "details": "The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-08T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-ggjj-3vpj-g73c/GHSA-ggjj-3vpj-g73c.json b/advisories/unreviewed/2025/04/GHSA-ggjj-3vpj-g73c/GHSA-ggjj-3vpj-g73c.json new file mode 100644 index 00000000000..0f289eec896 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggjj-3vpj-g73c/GHSA-ggjj-3vpj-g73c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggjj-3vpj-g73c", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2024-46089" + ], + "details": "74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46089" + }, + { + "type": "WEB", + "url": "https://gitee.com/Q16G/laravel_bug/blob/master/74cms.md" + }, + { + "type": "WEB", + "url": "https://github.com/Q16G/cve_detail/blob/main/74cms/unzipRCE.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json b/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json index ef114595246..be8460a0753 100644 --- a/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json +++ b/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjvx-hp9r-h988", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2024-40124" ], "details": "Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T17:15:31Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hmfp-mwgf-vxwx/GHSA-hmfp-mwgf-vxwx.json b/advisories/unreviewed/2025/04/GHSA-hmfp-mwgf-vxwx/GHSA-hmfp-mwgf-vxwx.json new file mode 100644 index 00000000000..d0794f8249c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hmfp-mwgf-vxwx/GHSA-hmfp-mwgf-vxwx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmfp-mwgf-vxwx", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3787" + ], + "details": "A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3787" + }, + { + "type": "WEB", + "url": "https://github.com/KKDT12138/CVE/blob/main/cve6.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553731" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json b/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json new file mode 100644 index 00000000000..e7da12110a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv4h-276c-jjqx", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-3783" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-product.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3783" + }, + { + "type": "WEB", + "url": "https://github.com/yaklang/IRifyScanResult/blob/main/Web-based%20Pharmacy%20Product%20Management%20System/upload_in_add-product.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305605" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305605" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553723" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T06:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json b/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json new file mode 100644 index 00000000000..98ec15e760e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j5qc-xcfm-cq6p/GHSA-j5qc-xcfm-cq6p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5qc-xcfm-cq6p", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-37860" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: fix NULL dereferences in ef100_process_design_param()\n\nSince cited commit, ef100_probe_main() and hence also\n ef100_check_design_params() run before efx->net_dev is created;\n consequently, we cannot netif_set_tso_max_size() or _segs() at this\n point.\nMove those netif calls to ef100_probe_netdev(), and also replace\n netif_err within the design params code with pci_err.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37860" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8241ecec1cdc6699ae197d52d58e76bddd995fa5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e56391011381d6d029da377a65ac314cb3d5def2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jhjh-hcm6-mrcc/GHSA-jhjh-hcm6-mrcc.json b/advisories/unreviewed/2025/04/GHSA-jhjh-hcm6-mrcc/GHSA-jhjh-hcm6-mrcc.json new file mode 100644 index 00000000000..bbe16fae335 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhjh-hcm6-mrcc/GHSA-jhjh-hcm6-mrcc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhjh-hcm6-mrcc", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-40014" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nobjtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq()\n\nIf speed_hz < AMD_SPI_MIN_HZ, amd_set_spi_freq() iterates over the\nentire amd_spi_freq array without breaking out early, causing 'i' to go\nbeyond the array bounds.\n\nFix that by stopping the loop when it gets to the last entry, so the low\nspeed_hz value gets clamped up to AMD_SPI_MIN_HZ.\n\nFixes the following warning with an UBSAN kernel:\n\n drivers/spi/spi-amd.o: error: objtool: amd_set_spi_freq() falls through to next function amd_spi_set_opcode()", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40014" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76e51db43fe4aaaebcc5ddda67b0807f7c9bdecc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f2c746e09a3746bf937bc708129dc8af61d8f19" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jmwp-442v-8qqq/GHSA-jmwp-442v-8qqq.json b/advisories/unreviewed/2025/04/GHSA-jmwp-442v-8qqq/GHSA-jmwp-442v-8qqq.json new file mode 100644 index 00000000000..f2b1bbf0ba2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jmwp-442v-8qqq/GHSA-jmwp-442v-8qqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmwp-442v-8qqq", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-39470" + ], + "details": "Path Traversal: '.../...//' vulnerability in ThimPress Ivy School allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39470" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/ivy-school/vulnerability/wordpress-ivy-school-1-6-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T05:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m6j5-92q7-225w/GHSA-m6j5-92q7-225w.json b/advisories/unreviewed/2025/04/GHSA-m6j5-92q7-225w/GHSA-m6j5-92q7-225w.json index f99dc151200..0972b511178 100644 --- a/advisories/unreviewed/2025/04/GHSA-m6j5-92q7-225w/GHSA-m6j5-92q7-225w.json +++ b/advisories/unreviewed/2025/04/GHSA-m6j5-92q7-225w/GHSA-m6j5-92q7-225w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m6j5-92q7-225w", - "modified": "2025-04-17T06:30:35Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T06:30:35Z", "aliases": [ "CVE-2024-13925" ], "details": "The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json b/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json index ca2aca51e43..92bb7280c82 100644 --- a/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json +++ b/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m746-cfp9-r2qh", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29461" ], "details": "An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p9hw-v7q7-gmh5/GHSA-p9hw-v7q7-gmh5.json b/advisories/unreviewed/2025/04/GHSA-p9hw-v7q7-gmh5/GHSA-p9hw-v7q7-gmh5.json index d38d2623d34..ccbc4ca2019 100644 --- a/advisories/unreviewed/2025/04/GHSA-p9hw-v7q7-gmh5/GHSA-p9hw-v7q7-gmh5.json +++ b/advisories/unreviewed/2025/04/GHSA-p9hw-v7q7-gmh5/GHSA-p9hw-v7q7-gmh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9hw-v7q7-gmh5", - "modified": "2025-04-03T09:32:16Z", + "modified": "2025-04-18T15:31:35Z", "published": "2025-04-03T09:32:16Z", "aliases": [ "CVE-2024-53868" ], "details": "Apache Traffic Server allows request smuggling if chunked messages are malformed. \n\n\n\n\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4.\n\nUsers are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-444" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T09:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json b/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json index 36b82024eb4..9b0f976e0d2 100644 --- a/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json +++ b/advisories/unreviewed/2025/04/GHSA-pc48-gfjf-qv7q/GHSA-pc48-gfjf-qv7q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pc48-gfjf-qv7q", - "modified": "2025-04-16T18:31:53Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-16T18:31:53Z", "aliases": [ "CVE-2024-40074" ], "details": "Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T17:15:49Z" diff --git a/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json b/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json new file mode 100644 index 00000000000..77968e3a82e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ph83-p4wj-c47p/GHSA-ph83-p4wj-c47p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph83-p4wj-c47p", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39755" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix cb7210 pcmcia Oops\n\nThe pcmcia_driver struct was still only using the old .name\ninitialization in the drv field. This led to a NULL pointer\nderef Oops in strcmp called from pcmcia_register_driver.\n\nInitialize the pcmcia_driver struct name field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39755" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ec50077d7f6647cb6ba3a2a20a6c26f51259c7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1baf6528bcfd6a86842093ff3f8ff8caf309c12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c82ae06f49e70d1c14ee9c76c392345856d050c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qchv-qqp6-v795/GHSA-qchv-qqp6-v795.json b/advisories/unreviewed/2025/04/GHSA-qchv-qqp6-v795/GHSA-qchv-qqp6-v795.json new file mode 100644 index 00000000000..d7acd42aa45 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qchv-qqp6-v795/GHSA-qchv-qqp6-v795.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qchv-qqp6-v795", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2024-49808" + ], + "details": "IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49808" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qv4f-mr6g-r994/GHSA-qv4f-mr6g-r994.json b/advisories/unreviewed/2025/04/GHSA-qv4f-mr6g-r994/GHSA-qv4f-mr6g-r994.json new file mode 100644 index 00000000000..580124ed40c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qv4f-mr6g-r994/GHSA-qv4f-mr6g-r994.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv4f-mr6g-r994", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38104" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV\n\nRLCG Register Access is a way for virtual functions to safely access GPU\nregisters in a virtualized environment., including TLB flushes and\nregister reads. When multiple threads or VFs try to access the same\nregisters simultaneously, it can lead to race conditions. By using the\nRLCG interface, the driver can serialize access to the registers. This\nmeans that only one thread can access the registers at a time,\npreventing conflicts and ensuring that operations are performed\ncorrectly. Additionally, when a low-priority task holds a mutex that a\nhigh-priority task needs, ie., If a thread holding a spinlock tries to\nacquire a mutex, it can lead to priority inversion. register access in\namdgpu_virt_rlcg_reg_rw especially in a fast code path is critical.\n\nThe call stack shows that the function amdgpu_virt_rlcg_reg_rw is being\ncalled, which attempts to acquire the mutex. This function is invoked\nfrom amdgpu_sriov_wreg, which in turn is called from\ngmc_v11_0_flush_gpu_tlb.\n\nThe [ BUG: Invalid wait context ] indicates that a thread is trying to\nacquire a mutex while it is in a context that does not allow it to sleep\n(like holding a spinlock).\n\nFixes the below:\n\n[ 253.013423] =============================\n[ 253.013434] [ BUG: Invalid wait context ]\n[ 253.013446] 6.12.0-amdstaging-drm-next-lol-050225 #14 Tainted: G U OE\n[ 253.013464] -----------------------------\n[ 253.013475] kworker/0:1/10 is trying to lock:\n[ 253.013487] ffff9f30542e3cf8 (&adev->virt.rlcg_reg_lock){+.+.}-{3:3}, at: amdgpu_virt_rlcg_reg_rw+0xf6/0x330 [amdgpu]\n[ 253.013815] other info that might help us debug this:\n[ 253.013827] context-{4:4}\n[ 253.013835] 3 locks held by kworker/0:1/10:\n[ 253.013847] #0: ffff9f3040050f58 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x3f5/0x680\n[ 253.013877] #1: ffffb789c008be40 ((work_completion)(&wfc.work)){+.+.}-{0:0}, at: process_one_work+0x1d6/0x680\n[ 253.013905] #2: ffff9f3054281838 (&adev->gmc.invalidate_lock){+.+.}-{2:2}, at: gmc_v11_0_flush_gpu_tlb+0x198/0x4f0 [amdgpu]\n[ 253.014154] stack backtrace:\n[ 253.014164] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Tainted: G U OE 6.12.0-amdstaging-drm-next-lol-050225 #14\n[ 253.014189] Tainted: [U]=USER, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n[ 253.014203] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 11/18/2024\n[ 253.014224] Workqueue: events work_for_cpu_fn\n[ 253.014241] Call Trace:\n[ 253.014250] \n[ 253.014260] dump_stack_lvl+0x9b/0xf0\n[ 253.014275] dump_stack+0x10/0x20\n[ 253.014287] __lock_acquire+0xa47/0x2810\n[ 253.014303] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 253.014321] lock_acquire+0xd1/0x300\n[ 253.014333] ? amdgpu_virt_rlcg_reg_rw+0xf6/0x330 [amdgpu]\n[ 253.014562] ? __lock_acquire+0xa6b/0x2810\n[ 253.014578] __mutex_lock+0x85/0xe20\n[ 253.014591] ? amdgpu_virt_rlcg_reg_rw+0xf6/0x330 [amdgpu]\n[ 253.014782] ? sched_clock_noinstr+0x9/0x10\n[ 253.014795] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 253.014808] ? local_clock_noinstr+0xe/0xc0\n[ 253.014822] ? amdgpu_virt_rlcg_reg_rw+0xf6/0x330 [amdgpu]\n[ 253.015012] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 253.015029] mutex_lock_nested+0x1b/0x30\n[ 253.015044] ? mutex_lock_nested+0x1b/0x30\n[ 253.015057] amdgpu_virt_rlcg_reg_rw+0xf6/0x330 [amdgpu]\n[ 253.015249] amdgpu_sriov_wreg+0xc5/0xd0 [amdgpu]\n[ 253.015435] gmc_v11_0_flush_gpu_tlb+0x44b/0x4f0 [amdgpu]\n[ 253.015667] gfx_v11_0_hw_init+0x499/0x29c0 [amdgpu]\n[ 253.015901] ? __pfx_smu_v13_0_update_pcie_parameters+0x10/0x10 [amdgpu]\n[ 253.016159] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 253.016173] ? smu_hw_init+0x18d/0x300 [amdgpu]\n[ 253.016403] amdgpu_device_init+0x29ad/0x36a0 [amdgpu]\n[ 253.016614] amdgpu_driver_load_kms+0x1a/0xc0 [amdgpu]\n[ 253.0170\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38104" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c0378830e42c98acd69e0289882c8637d92f285" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c1741a0c176ae11675a64cb7f2dd21d72db6b91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc0297f3198bd60108ccbd167ee5d9fa4af31ed0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json b/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json index 0a44e5fbb0c..dd55f362f3b 100644 --- a/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json +++ b/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvww-5m45-9x54", - "modified": "2025-04-17T18:31:23Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T18:31:23Z", "aliases": [ "CVE-2025-25455" ], "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json b/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json index 24268872196..7f2fc5b4fe7 100644 --- a/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json +++ b/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg9h-f5v4-xwfp", - "modified": "2025-04-17T18:31:14Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-17T18:31:14Z", "aliases": [ "CVE-2025-25457" ], "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T16:15:34Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rh6v-853j-mqjh/GHSA-rh6v-853j-mqjh.json b/advisories/unreviewed/2025/04/GHSA-rh6v-853j-mqjh/GHSA-rh6v-853j-mqjh.json new file mode 100644 index 00000000000..37da85d3375 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rh6v-853j-mqjh/GHSA-rh6v-853j-mqjh.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh6v-853j-mqjh", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39735" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix slab-out-of-bounds read in ea_get()\n\nDuring the \"size_check\" label in ea_get(), the code checks if the extended\nattribute list (xattr) size matches ea_size. If not, it logs\n\"ea_get: invalid extended attribute\" and calls print_hex_dump().\n\nHere, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds\nINT_MAX (2,147,483,647). Then ea_size is clamped:\n\n\tint size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));\n\nAlthough clamp_t aims to bound ea_size between 0 and 4110417968, the upper\nlimit is treated as an int, causing an overflow above 2^31 - 1. This leads\n\"size\" to wrap around and become negative (-184549328).\n\nThe \"size\" is then passed to print_hex_dump() (called \"len\" in\nprint_hex_dump()), it is passed as type size_t (an unsigned\ntype), this is then stored inside a variable called\n\"int remaining\", which is then assigned to \"int linelen\" which\nis then passed to hex_dump_to_buffer(). In print_hex_dump()\nthe for loop, iterates through 0 to len-1, where len is\n18446744073525002176, calling hex_dump_to_buffer()\non each iteration:\n\n\tfor (i = 0; i < len; i += rowsize) {\n\t\tlinelen = min(remaining, rowsize);\n\t\tremaining -= rowsize;\n\n\t\thex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize,\n\t\t\t\t linebuf, sizeof(linebuf), ascii);\n\n\t\t...\n\t}\n\nThe expected stopping condition (i < len) is effectively broken\nsince len is corrupted and very large. This eventually leads to\nthe \"ptr+i\" being passed to hex_dump_to_buffer() to get closer\nto the end of the actual bounds of \"ptr\", eventually an out of\nbounds access is done in hex_dump_to_buffer() in the following\nfor loop:\n\n\tfor (j = 0; j < len; j++) {\n\t\t\tif (linebuflen < lx + 2)\n\t\t\t\tgoto overflow2;\n\t\t\tch = ptr[j];\n\t\t...\n\t}\n\nTo fix this we should validate \"EALIST_SIZE(ea_buf->xattr)\"\nbefore it is utilised.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39735" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0beddc2a3f9b9cf7d8887973041e36c2d0fa3652" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16d3d36436492aa248b2d8045e75585ebcc2f34d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d6fd5b9c6acbc005e53d0211c7381f566babec1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46e2c031aa59ea65128991cbca474bd5c0c2ecdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50afcee7011155933d8d5e8832f52eeee018cfd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5263822558a8a7c0d0248d5679c2dcf4d5cda61f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78c9cbde8880ec02d864c166bcb4fe989ce1d95f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8c31808925b11393a6601f534bb63bac5366bab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdf480da5837c23b146c4743c18de97202fcab37" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rr66-qxh8-8qwq/GHSA-rr66-qxh8-8qwq.json b/advisories/unreviewed/2025/04/GHSA-rr66-qxh8-8qwq/GHSA-rr66-qxh8-8qwq.json new file mode 100644 index 00000000000..b26d4429ae0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rr66-qxh8-8qwq/GHSA-rr66-qxh8-8qwq.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr66-qxh8-8qwq", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-38575" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use aead_request_free to match aead_request_alloc\n\nUse aead_request_free() instead of kfree() to properly free memory\nallocated by aead_request_alloc(). This ensures sensitive crypto data\nis zeroed before being freed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38575" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1de7fec4d3012672e31eeb6679ea60f7ca010ef9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e341dbd5f5a6e5a558e67da80731dc38a7f758c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46caeae23035192b9cc41872c827f30d0233f16e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/571b342d4688801fc1f6a1934389dac09425dc93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6171063e9d046ffa46f51579b2ca4a43caef581a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6b594868268c3a7bfaeced912525cd2c445529a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aef10ccd74512c52e30c5ee19d0031850973e78d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rvm5-9pv9-2rrc/GHSA-rvm5-9pv9-2rrc.json b/advisories/unreviewed/2025/04/GHSA-rvm5-9pv9-2rrc/GHSA-rvm5-9pv9-2rrc.json new file mode 100644 index 00000000000..a9ffe620957 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rvm5-9pv9-2rrc/GHSA-rvm5-9pv9-2rrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvm5-9pv9-2rrc", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2024-45651" + ], + "details": "IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 \n\ndoes not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45651" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json b/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json index ffc161ba3b9..011d98c9d7d 100644 --- a/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json +++ b/advisories/unreviewed/2025/04/GHSA-v38h-c3ff-rmhw/GHSA-v38h-c3ff-rmhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v38h-c3ff-rmhw", - "modified": "2025-04-16T21:30:59Z", + "modified": "2025-04-18T15:31:37Z", "published": "2025-04-16T21:30:59Z", "aliases": [ "CVE-2025-26153" ], "details": "A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T21:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vf7h-45fw-j88p/GHSA-vf7h-45fw-j88p.json b/advisories/unreviewed/2025/04/GHSA-vf7h-45fw-j88p/GHSA-vf7h-45fw-j88p.json new file mode 100644 index 00000000000..6f27e6edfbd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vf7h-45fw-j88p/GHSA-vf7h-45fw-j88p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf7h-45fw-j88p", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-40325" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: wait barrier before returning discard request with REQ_NOWAIT\n\nraid10_handle_discard should wait barrier before returning a discard bio\nwhich has REQ_NOWAIT. And there is no need to print warning calltrace\nif a discard bio has REQ_NOWAIT flag. Quality engineer usually checks\ndmesg and reports error if dmesg has warning/error calltrace.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40325" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31d3156efe909b53ba174861a3da880c688f5edc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3db4404435397a345431b45f57876a3df133f3b4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vwg7-hhf5-ff3g/GHSA-vwg7-hhf5-ff3g.json b/advisories/unreviewed/2025/04/GHSA-vwg7-hhf5-ff3g/GHSA-vwg7-hhf5-ff3g.json new file mode 100644 index 00000000000..500091040e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vwg7-hhf5-ff3g/GHSA-vwg7-hhf5-ff3g.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwg7-hhf5-ff3g", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-39989" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mce: use is_copy_from_user() to determine copy-from-user context\n\nPatch series \"mm/hwpoison: Fix regressions in memory failure handling\",\nv4.\n\n## 1. What am I trying to do:\n\nThis patchset resolves two critical regressions related to memory failure\nhandling that have appeared in the upstream kernel since version 5.17, as\ncompared to 5.10 LTS.\n\n - copyin case: poison found in user page while kernel copying from user space\n - instr case: poison found while instruction fetching in user space\n\n## 2. What is the expected outcome and why\n\n- For copyin case:\n\nKernel can recover from poison found where kernel is doing get_user() or\ncopy_from_user() if those places get an error return and the kernel return\n-EFAULT to the process instead of crashing. More specifily, MCE handler\nchecks the fixup handler type to decide whether an in kernel #MC can be\nrecovered. When EX_TYPE_UACCESS is found, the PC jumps to recovery code\nspecified in _ASM_EXTABLE_FAULT() and return a -EFAULT to user space.\n\n- For instr case:\n\nIf a poison found while instruction fetching in user space, full recovery\nis possible. User process takes #PF, Linux allocates a new page and fills\nby reading from storage.\n\n\n## 3. What actually happens and why\n\n- For copyin case: kernel panic since v5.17\n\nCommit 4c132d1d844a (\"x86/futex: Remove .fixup usage\") introduced a new\nextable fixup type, EX_TYPE_EFAULT_REG, and later patches updated the\nextable fixup type for copy-from-user operations, changing it from\nEX_TYPE_UACCESS to EX_TYPE_EFAULT_REG. It breaks previous EX_TYPE_UACCESS\nhandling when posion found in get_user() or copy_from_user().\n\n- For instr case: user process is killed by a SIGBUS signal due to #CMCI\n and #MCE race\n\nWhen an uncorrected memory error is consumed there is a race between the\nCMCI from the memory controller reporting an uncorrected error with a UCNA\nsignature, and the core reporting and SRAR signature machine check when\nthe data is about to be consumed.\n\n### Background: why *UN*corrected errors tied to *C*MCI in Intel platform [1]\n\nPrior to Icelake memory controllers reported patrol scrub events that\ndetected a previously unseen uncorrected error in memory by signaling a\nbroadcast machine check with an SRAO (Software Recoverable Action\nOptional) signature in the machine check bank. This was overkill because\nit's not an urgent problem that no core is on the verge of consuming that\nbad data. It's also found that multi SRAO UCE may cause nested MCE\ninterrupts and finally become an IERR.\n\nHence, Intel downgrades the machine check bank signature of patrol scrub\nfrom SRAO to UCNA (Uncorrected, No Action required), and signal changed to\n#CMCI. Just to add to the confusion, Linux does take an action (in\nuc_decode_notifier()) to try to offline the page despite the UC*NA*\nsignature name.\n\n### Background: why #CMCI and #MCE race when poison is consuming in\n Intel platform [1]\n\nHaving decided that CMCI/UCNA is the best action for patrol scrub errors,\nthe memory controller uses it for reads too. But the memory controller is\nexecuting asynchronously from the core, and can't tell the difference\nbetween a \"real\" read and a speculative read. So it will do CMCI/UCNA if\nan error is found in any read.\n\nThus:\n\n1) Core is clever and thinks address A is needed soon, issues a\n speculative read.\n\n2) Core finds it is going to use address A soon after sending the read\n request\n\n3) The CMCI from the memory controller is in a race with MCE from the\n core that will soon try to retire the load from address A.\n\nQuite often (because speculation has got better) the CMCI from the memory\ncontroller is delivered before the core is committed to the instruction\nreading address A, so the interrupt is taken, and Linux offlines the page\n(marking it as poison).\n\n\n## Why user process is killed for instr case\n\nCommit 046545a661af (\"mm/hwpoison: fix error page recovered but reported\n\"not\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b8388e97ba6a8c033f9a8b5565af41af07f9345" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a15bb8303b6b104e78028b6c68f76a0d4562134" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e3d8169c0950a0b3cd5105f6403a78350dcac80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/449413da90a337f343cc5a73070cbd68e92e8a54" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json b/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json new file mode 100644 index 00000000000..fe4b006a135 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w7jc-wqpw-qxqq/GHSA-w7jc-wqpw-qxqq.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7jc-wqpw-qxqq", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-37785" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix OOB read when checking dotdot dir\n\nMounting a corrupted filesystem with directory which contains '.' dir\nentry with rec_len == block size results in out-of-bounds read (later\non, when the corrupted directory is removed).\n\next4_empty_dir() assumes every ext4 directory contains at least '.'\nand '..' as directory entries in the first data block. It first loads\nthe '.' dir entry, performs sanity checks by calling ext4_check_dir_entry()\nand then uses its rec_len member to compute the location of '..' dir\nentry (in ext4_next_entry). It assumes the '..' dir entry fits into the\nsame data block.\n\nIf the rec_len of '.' is precisely one block (4KB), it slips through the\nsanity checks (it is considered the last directory entry in the data\nblock) and leaves \"struct ext4_dir_entry_2 *de\" point exactly past the\nmemory slot allocated to the data block. The following call to\next4_check_dir_entry() on new value of de then dereferences this pointer\nwhich results in out-of-bounds mem access.\n\nFix this by extending __ext4_check_dir_entry() to check for '.' dir\nentries that reach the end of data block. Make sure to ignore the phony\ndir entries for checksum (by checking name_len for non-zero).\n\nNote: This is reported by KASAN as use-after-free in case another\nstructure was recently freed from the slot past the bound, but it is\nreally an OOB read.\n\nThis issue was found by syzkaller tool.\n\nCall Trace:\n[ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710\n[ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375\n[ 38.595158]\n[ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1\n[ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n[ 38.595304] Call Trace:\n[ 38.595308] \n[ 38.595311] dump_stack_lvl+0xa7/0xd0\n[ 38.595325] print_address_description.constprop.0+0x2c/0x3f0\n[ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595349] print_report+0xaa/0x250\n[ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595368] ? kasan_addr_to_slab+0x9/0x90\n[ 38.595378] kasan_report+0xab/0xe0\n[ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710\n[ 38.595400] __ext4_check_dir_entry+0x67e/0x710\n[ 38.595410] ext4_empty_dir+0x465/0x990\n[ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10\n[ 38.595432] ext4_rmdir.part.0+0x29a/0xd10\n[ 38.595441] ? __dquot_initialize+0x2a7/0xbf0\n[ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10\n[ 38.595464] ? __pfx___dquot_initialize+0x10/0x10\n[ 38.595478] ? down_write+0xdb/0x140\n[ 38.595487] ? __pfx_down_write+0x10/0x10\n[ 38.595497] ext4_rmdir+0xee/0x140\n[ 38.595506] vfs_rmdir+0x209/0x670\n[ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190\n[ 38.595529] do_rmdir+0x363/0x3c0\n[ 38.595537] ? __pfx_do_rmdir+0x10/0x10\n[ 38.595544] ? strncpy_from_user+0x1ff/0x2e0\n[ 38.595561] __x64_sys_unlinkat+0xf0/0x130\n[ 38.595570] do_syscall_64+0x5b/0x180\n[ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37785" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52a5509ab19a5d3afe301165d9b5787bba34d842" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53bc45da8d8da92ec07877f5922b130562eb4b00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/89503e5eae64637d0fa2218912b54660effe7d93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac28c5684c1cdab650a7e5065b19e91577d37a4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b47584c556444cf7acb66b26a62cbc348eb92b78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7531a4f99c3887439d778afaf418d1a01a5f01b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5e206778e96e8667d3bde695ad372c296dc9353" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e47f472a664d70a3d104a6c2a035cdff55a719b4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w7x5-wj8r-qp32/GHSA-w7x5-wj8r-qp32.json b/advisories/unreviewed/2025/04/GHSA-w7x5-wj8r-qp32/GHSA-w7x5-wj8r-qp32.json new file mode 100644 index 00000000000..3e059cd8b12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w7x5-wj8r-qp32/GHSA-w7x5-wj8r-qp32.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7x5-wj8r-qp32", + "modified": "2025-04-18T15:31:38Z", + "published": "2025-04-18T15:31:38Z", + "aliases": [ + "CVE-2025-3785" + ], + "details": "A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.49 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3785" + }, + { + "type": "WEB", + "url": "https://github.com/ZOKEYE/CVE/blob/main/D-link.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.553547" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wvvm-3j2m-8rj3/GHSA-wvvm-3j2m-8rj3.json b/advisories/unreviewed/2025/04/GHSA-wvvm-3j2m-8rj3/GHSA-wvvm-3j2m-8rj3.json new file mode 100644 index 00000000000..62e0dbcee95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wvvm-3j2m-8rj3/GHSA-wvvm-3j2m-8rj3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvvm-3j2m-8rj3", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-42599" + ], + "details": "Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42599" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN22348866" + }, + { + "type": "WEB", + "url": "https://www.qualitia.com/jp/news/2025/04/18_1030.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T04:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xp3f-7vhv-p42p/GHSA-xp3f-7vhv-p42p.json b/advisories/unreviewed/2025/04/GHSA-xp3f-7vhv-p42p/GHSA-xp3f-7vhv-p42p.json new file mode 100644 index 00000000000..fab9cb13cd9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xp3f-7vhv-p42p/GHSA-xp3f-7vhv-p42p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp3f-7vhv-p42p", + "modified": "2025-04-18T15:31:37Z", + "published": "2025-04-18T15:31:37Z", + "aliases": [ + "CVE-2025-3598" + ], + "details": "The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3598" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woo-coupon-usage/tags/6.2.2/inc/functions/functions-all-time.php#L245" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2d6cf33c-ac40-4892-9345-64ebe61e6be6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T06:15:44Z" + } +} \ No newline at end of file