diff --git a/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json b/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json index 7eb50c1c754..2176caee1c7 100644 --- a/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json +++ b/advisories/unreviewed/2021/12/GHSA-2x2v-ccf2-cqcf/GHSA-2x2v-ccf2-cqcf.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-330", "CWE-384" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json b/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json index 94a9e16b37c..0bd17256229 100644 --- a/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json +++ b/advisories/unreviewed/2021/12/GHSA-96xv-6m77-v224/GHSA-96xv-6m77-v224.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96xv-6m77-v224", - "modified": "2021-12-16T00:02:59Z", + "modified": "2025-04-30T21:31:41Z", "published": "2021-12-14T00:01:12Z", "aliases": [ "CVE-2021-44153" ], "details": "An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo \"C:\\Windows\\System32\\calc.exe\" entry. An attacker can exploit this to run a malicious binary on startup, or when triggering the Reread/Restart Servers function on the webserver. (Exploitation does not require CVE-2018-15573, because the license file is meant to be changed in the application.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json b/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json index 9ef387db764..5fe7ed46aff 100644 --- a/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json +++ b/advisories/unreviewed/2021/12/GHSA-fvw8-6hqj-qw58/GHSA-fvw8-6hqj-qw58.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvw8-6hqj-qw58", - "modified": "2021-12-16T00:02:58Z", + "modified": "2025-04-30T21:31:41Z", "published": "2021-12-14T00:01:12Z", "aliases": [ "CVE-2021-44154" ], "details": "An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/04/GHSA-4g2v-6x25-vr7p/GHSA-4g2v-6x25-vr7p.json b/advisories/unreviewed/2022/04/GHSA-4g2v-6x25-vr7p/GHSA-4g2v-6x25-vr7p.json index 85b4f06d69a..8858a439bb3 100644 --- a/advisories/unreviewed/2022/04/GHSA-4g2v-6x25-vr7p/GHSA-4g2v-6x25-vr7p.json +++ b/advisories/unreviewed/2022/04/GHSA-4g2v-6x25-vr7p/GHSA-4g2v-6x25-vr7p.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-425", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-6h88-c442-5cvx/GHSA-6h88-c442-5cvx.json b/advisories/unreviewed/2022/05/GHSA-6h88-c442-5cvx/GHSA-6h88-c442-5cvx.json index 2d7773472b9..79163a6d16f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h88-c442-5cvx/GHSA-6h88-c442-5cvx.json +++ b/advisories/unreviewed/2022/05/GHSA-6h88-c442-5cvx/GHSA-6h88-c442-5cvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6h88-c442-5cvx", - "modified": "2024-03-21T03:33:31Z", + "modified": "2025-04-30T21:31:41Z", "published": "2022-05-14T02:02:06Z", "aliases": [ "CVE-2018-15574" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://bittherapy.net/rce-with-arbitrary-file-write-and-xss-in-reprise-license-manager" + }, + { + "type": "WEB", + "url": "https://reprisesoftware.com/docs/whats-new.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-2q5x-xfgf-96mf/GHSA-2q5x-xfgf-96mf.json b/advisories/unreviewed/2022/11/GHSA-2q5x-xfgf-96mf/GHSA-2q5x-xfgf-96mf.json index 63bf517f676..8383b915d06 100644 --- a/advisories/unreviewed/2022/11/GHSA-2q5x-xfgf-96mf/GHSA-2q5x-xfgf-96mf.json +++ b/advisories/unreviewed/2022/11/GHSA-2q5x-xfgf-96mf/GHSA-2q5x-xfgf-96mf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-j8q4-3cww-3fwm/GHSA-j8q4-3cww-3fwm.json b/advisories/unreviewed/2022/11/GHSA-j8q4-3cww-3fwm/GHSA-j8q4-3cww-3fwm.json index 005857d2c2c..a366ec48340 100644 --- a/advisories/unreviewed/2022/11/GHSA-j8q4-3cww-3fwm/GHSA-j8q4-3cww-3fwm.json +++ b/advisories/unreviewed/2022/11/GHSA-j8q4-3cww-3fwm/GHSA-j8q4-3cww-3fwm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-367" + "CWE-367", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-j9qg-3vhc-x483/GHSA-j9qg-3vhc-x483.json b/advisories/unreviewed/2022/11/GHSA-j9qg-3vhc-x483/GHSA-j9qg-3vhc-x483.json index 0dce8dc73ba..24f24b499b0 100644 --- a/advisories/unreviewed/2022/11/GHSA-j9qg-3vhc-x483/GHSA-j9qg-3vhc-x483.json +++ b/advisories/unreviewed/2022/11/GHSA-j9qg-3vhc-x483/GHSA-j9qg-3vhc-x483.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j9qg-3vhc-x483", - "modified": "2022-11-17T21:30:50Z", + "modified": "2025-04-30T21:31:44Z", "published": "2022-11-15T12:00:17Z", "aliases": [ "CVE-2022-40903" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-307" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-jjmh-h947-x6vh/GHSA-jjmh-h947-x6vh.json b/advisories/unreviewed/2022/11/GHSA-jjmh-h947-x6vh/GHSA-jjmh-h947-x6vh.json index 17f2f607c64..7cb45f2ae0a 100644 --- a/advisories/unreviewed/2022/11/GHSA-jjmh-h947-x6vh/GHSA-jjmh-h947-x6vh.json +++ b/advisories/unreviewed/2022/11/GHSA-jjmh-h947-x6vh/GHSA-jjmh-h947-x6vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jjmh-h947-x6vh", - "modified": "2022-11-17T06:30:20Z", + "modified": "2025-04-30T21:31:45Z", "published": "2022-11-15T12:00:16Z", "aliases": [ "CVE-2022-42984" diff --git a/advisories/unreviewed/2022/11/GHSA-wpp2-f4wp-vr8h/GHSA-wpp2-f4wp-vr8h.json b/advisories/unreviewed/2022/11/GHSA-wpp2-f4wp-vr8h/GHSA-wpp2-f4wp-vr8h.json index 94c81456e3a..cbf5f9019bc 100644 --- a/advisories/unreviewed/2022/11/GHSA-wpp2-f4wp-vr8h/GHSA-wpp2-f4wp-vr8h.json +++ b/advisories/unreviewed/2022/11/GHSA-wpp2-f4wp-vr8h/GHSA-wpp2-f4wp-vr8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpp2-f4wp-vr8h", - "modified": "2022-11-17T21:30:51Z", + "modified": "2025-04-30T21:31:42Z", "published": "2022-11-15T12:00:17Z", "aliases": [ "CVE-2022-3903" @@ -19,10 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3903" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA%40mail.gmail.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/CAB7eexLLApHJwZfMQ=X-PtRhw0BgO+5KcSMS05FNUYejJXqtSA@mail.gmail.com" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/E1obysd-009Grw-He%40www.linuxtv.org" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/E1obysd-009Grw-He@www.linuxtv.org" diff --git a/advisories/unreviewed/2023/09/GHSA-5f52-v49r-796w/GHSA-5f52-v49r-796w.json b/advisories/unreviewed/2023/09/GHSA-5f52-v49r-796w/GHSA-5f52-v49r-796w.json index 200ccd49e35..e7833c73cd9 100644 --- a/advisories/unreviewed/2023/09/GHSA-5f52-v49r-796w/GHSA-5f52-v49r-796w.json +++ b/advisories/unreviewed/2023/09/GHSA-5f52-v49r-796w/GHSA-5f52-v49r-796w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f52-v49r-796w", - "modified": "2024-09-16T14:37:21Z", + "modified": "2025-04-30T21:31:46Z", "published": "2023-09-18T18:30:28Z", "aliases": [ "CVE-2023-4806" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4806" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2024:2413" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:5453" diff --git a/advisories/unreviewed/2023/09/GHSA-qx6j-g797-jg9r/GHSA-qx6j-g797-jg9r.json b/advisories/unreviewed/2023/09/GHSA-qx6j-g797-jg9r/GHSA-qx6j-g797-jg9r.json index 257dba3e7a4..cd40b4f6e1f 100644 --- a/advisories/unreviewed/2023/09/GHSA-qx6j-g797-jg9r/GHSA-qx6j-g797-jg9r.json +++ b/advisories/unreviewed/2023/09/GHSA-qx6j-g797-jg9r/GHSA-qx6j-g797-jg9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qx6j-g797-jg9r", - "modified": "2024-09-16T14:37:21Z", + "modified": "2025-04-30T21:31:46Z", "published": "2023-09-13T00:30:18Z", "aliases": [ "CVE-2023-4813" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4813" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2024:2413" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:5453" diff --git a/advisories/unreviewed/2023/10/GHSA-cvp3-7vpw-ffh6/GHSA-cvp3-7vpw-ffh6.json b/advisories/unreviewed/2023/10/GHSA-cvp3-7vpw-ffh6/GHSA-cvp3-7vpw-ffh6.json index 1f2fd05574a..bcd8055a6e1 100644 --- a/advisories/unreviewed/2023/10/GHSA-cvp3-7vpw-ffh6/GHSA-cvp3-7vpw-ffh6.json +++ b/advisories/unreviewed/2023/10/GHSA-cvp3-7vpw-ffh6/GHSA-cvp3-7vpw-ffh6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvp3-7vpw-ffh6", - "modified": "2023-11-16T03:30:19Z", + "modified": "2025-04-30T21:31:46Z", "published": "2023-10-12T00:30:28Z", "aliases": [ "CVE-2023-5218" diff --git a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json index 9f15fd31f8b..09d7be205a1 100644 --- a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json +++ b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m77w-6vjw-wh2f", - "modified": "2024-02-22T21:30:28Z", + "modified": "2025-04-30T21:31:47Z", "published": "2023-10-03T18:30:23Z", "aliases": [ "CVE-2023-4911" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2023:5453" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2023:5454" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2023:5455" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2023:5476" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:0033" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/CVE-2023-4911" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2238352" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202310-03" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20231013-0006" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2023/dsa-5514" + "url": "https://www.qualys.com/cve-2023-4911" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://www.qualys.com/cve-2023-4911" + "url": "https://www.debian.org/security/2023/dsa-5514" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231013-0006" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202310-03" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2238352" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-4911" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0033" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5476" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5455" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5454" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:5453" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHBA-2024:2413" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/03/GHSA-xm2x-6377-gr78/GHSA-xm2x-6377-gr78.json b/advisories/unreviewed/2024/03/GHSA-xm2x-6377-gr78/GHSA-xm2x-6377-gr78.json index 3cd3f00548d..ff7df3c2946 100644 --- a/advisories/unreviewed/2024/03/GHSA-xm2x-6377-gr78/GHSA-xm2x-6377-gr78.json +++ b/advisories/unreviewed/2024/03/GHSA-xm2x-6377-gr78/GHSA-xm2x-6377-gr78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xm2x-6377-gr78", - "modified": "2024-03-22T00:31:15Z", + "modified": "2025-04-30T21:31:47Z", "published": "2024-03-22T00:31:15Z", "aliases": [ "CVE-2024-2777" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -30,10 +34,15 @@ { "type": "WEB", "url": "https://vuldb.com/?id.257611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.302430" } ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json index 85f4bab2eb1..d7add5e6f4e 100644 --- a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json +++ b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79wf-qgrg-2p6c", - "modified": "2025-04-05T00:30:26Z", + "modified": "2025-04-30T21:31:47Z", "published": "2024-10-27T06:30:47Z", "aliases": [ "CVE-2024-50602" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/915" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250404-0008" diff --git a/advisories/unreviewed/2025/04/GHSA-2ff4-cc78-4pg6/GHSA-2ff4-cc78-4pg6.json b/advisories/unreviewed/2025/04/GHSA-2ff4-cc78-4pg6/GHSA-2ff4-cc78-4pg6.json new file mode 100644 index 00000000000..5d136a33fbe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2ff4-cc78-4pg6/GHSA-2ff4-cc78-4pg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ff4-cc78-4pg6", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2022-27562" + ], + "details": "Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27562" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120722" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2rm2-cf7c-m25m/GHSA-2rm2-cf7c-m25m.json b/advisories/unreviewed/2025/04/GHSA-2rm2-cf7c-m25m/GHSA-2rm2-cf7c-m25m.json new file mode 100644 index 00000000000..ed34e2111da --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2rm2-cf7c-m25m/GHSA-2rm2-cf7c-m25m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rm2-cf7c-m25m", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2024-13943" + ], + "details": "Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the QCMAP_ConnectionManager component. An attacker can abuse the service to assign LAN addresses to the WWAN. An attacker can leverage this vulnerability to access network services that were only intended to be exposed to the internal LAN. Was ZDI-CAN-23199.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13943" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-262" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-47g8-g4qw-4hp3/GHSA-47g8-g4qw-4hp3.json b/advisories/unreviewed/2025/04/GHSA-47g8-g4qw-4hp3/GHSA-47g8-g4qw-4hp3.json new file mode 100644 index 00000000000..6693a2ddb7e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-47g8-g4qw-4hp3/GHSA-47g8-g4qw-4hp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47g8-g4qw-4hp3", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2024-6029" + ], + "details": "Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to exploit this vulnerability.\n \nThe specific flaw exists within the firewall service. The issue results from a failure to obtain the xtables lock. An attacker can leverage this vulnerability to bypass firewall rules. Was ZDI-CAN-23197.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6029" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4fq3-3crq-c8mm/GHSA-4fq3-3crq-c8mm.json b/advisories/unreviewed/2025/04/GHSA-4fq3-3crq-c8mm/GHSA-4fq3-3crq-c8mm.json index bcd78dd84c2..7f748f6218c 100644 --- a/advisories/unreviewed/2025/04/GHSA-4fq3-3crq-c8mm/GHSA-4fq3-3crq-c8mm.json +++ b/advisories/unreviewed/2025/04/GHSA-4fq3-3crq-c8mm/GHSA-4fq3-3crq-c8mm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-54jr-7228-3w94/GHSA-54jr-7228-3w94.json b/advisories/unreviewed/2025/04/GHSA-54jr-7228-3w94/GHSA-54jr-7228-3w94.json new file mode 100644 index 00000000000..07d86011c38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-54jr-7228-3w94/GHSA-54jr-7228-3w94.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54jr-7228-3w94", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2024-6031" + ], + "details": "Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability.\n \nThe specific flaw exists within the parsing of responses from AT commands. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23198.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6031" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-261" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json b/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json new file mode 100644 index 00000000000..6457f66c2e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66mc-jppc-fm4m", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2025-2170" + ], + "details": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2170" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0008" + }, + { + "type": "WEB", + "url": "http://10.210.34.9/vuln-detail/SNWLID-2025-0008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T19:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7cm3-qp9p-mc2h/GHSA-7cm3-qp9p-mc2h.json b/advisories/unreviewed/2025/04/GHSA-7cm3-qp9p-mc2h/GHSA-7cm3-qp9p-mc2h.json new file mode 100644 index 00000000000..3bd3f5dcf53 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7cm3-qp9p-mc2h/GHSA-7cm3-qp9p-mc2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cm3-qp9p-mc2h", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2024-6032" + ], + "details": "Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to exploit this vulnerability.\n \nThe specific flaw exists within the ql_atfwd process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code on the target modem in the context of root. Was ZDI-CAN-23201.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6032" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8429-j533-fq73/GHSA-8429-j533-fq73.json b/advisories/unreviewed/2025/04/GHSA-8429-j533-fq73/GHSA-8429-j533-fq73.json new file mode 100644 index 00000000000..af415402b8d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8429-j533-fq73/GHSA-8429-j533-fq73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8429-j533-fq73", + "modified": "2025-04-30T21:31:49Z", + "published": "2025-04-30T21:31:49Z", + "aliases": [ + "CVE-2024-6030" + ], + "details": "Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on the target system in order to exploit this vulnerability.\n \nThe specific flaw exists within the oFono process. The process allows an attacker to modify interfaces. An attacker can leverage this vulnerability to bypass the iptables network sandbox. Was ZDI-CAN-23200.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6030" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfw8-mqxq-pp4x/GHSA-cfw8-mqxq-pp4x.json b/advisories/unreviewed/2025/04/GHSA-cfw8-mqxq-pp4x/GHSA-cfw8-mqxq-pp4x.json new file mode 100644 index 00000000000..f24ef0cd3c6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfw8-mqxq-pp4x/GHSA-cfw8-mqxq-pp4x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfw8-mqxq-pp4x", + "modified": "2025-04-30T21:31:48Z", + "published": "2025-04-30T21:31:48Z", + "aliases": [ + "CVE-2024-47784" + ], + "details": "Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI\nThis issue affects ANC software version 1.1.4 and earlier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47784" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=2CRT000006&LanguageCode=en&DocumentPartId=PDF&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f29q-2hxg-hw6x/GHSA-f29q-2hxg-hw6x.json b/advisories/unreviewed/2025/04/GHSA-f29q-2hxg-hw6x/GHSA-f29q-2hxg-hw6x.json index c0d4486282e..e96371e7126 100644 --- a/advisories/unreviewed/2025/04/GHSA-f29q-2hxg-hw6x/GHSA-f29q-2hxg-hw6x.json +++ b/advisories/unreviewed/2025/04/GHSA-f29q-2hxg-hw6x/GHSA-f29q-2hxg-hw6x.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-f9m5-54gv-845w/GHSA-f9m5-54gv-845w.json b/advisories/unreviewed/2025/04/GHSA-f9m5-54gv-845w/GHSA-f9m5-54gv-845w.json index f3bfa2f9146..6cb6e75fa9a 100644 --- a/advisories/unreviewed/2025/04/GHSA-f9m5-54gv-845w/GHSA-f9m5-54gv-845w.json +++ b/advisories/unreviewed/2025/04/GHSA-f9m5-54gv-845w/GHSA-f9m5-54gv-845w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json index ca50feb01ac..9fd3cb02851 100644 --- a/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json +++ b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h982-967r-m89p/GHSA-h982-967r-m89p.json b/advisories/unreviewed/2025/04/GHSA-h982-967r-m89p/GHSA-h982-967r-m89p.json new file mode 100644 index 00000000000..5b2f929a0d6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h982-967r-m89p/GHSA-h982-967r-m89p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h982-967r-m89p", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2025-2082" + ], + "details": "Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the VCSEC module. By manipulating the certificate response sent from the Tire Pressure Monitoring System (TPMS), an attacker can trigger an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the VCSEC module and send arbitrary messages to the vehicle CAN bus. Was ZDI-CAN-23800.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2082" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hvr3-hx5m-g63g/GHSA-hvr3-hx5m-g63g.json b/advisories/unreviewed/2025/04/GHSA-hvr3-hx5m-g63g/GHSA-hvr3-hx5m-g63g.json new file mode 100644 index 00000000000..503e2ad65a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hvr3-hx5m-g63g/GHSA-hvr3-hx5m-g63g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvr3-hx5m-g63g", + "modified": "2025-04-30T21:31:48Z", + "published": "2025-04-30T21:31:48Z", + "aliases": [ + "CVE-2024-9877" + ], + "details": ": Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9877" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=2CRT000006&LanguageCode=en&DocumentPartId=PDF&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json b/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json new file mode 100644 index 00000000000..2537f474d45 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg9f-xcjm-xm8p", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2025-24132" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24132" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122403" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T21:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pfvg-rvxx-jfrg/GHSA-pfvg-rvxx-jfrg.json b/advisories/unreviewed/2025/04/GHSA-pfvg-rvxx-jfrg/GHSA-pfvg-rvxx-jfrg.json new file mode 100644 index 00000000000..83782af3d46 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pfvg-rvxx-jfrg/GHSA-pfvg-rvxx-jfrg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfvg-rvxx-jfrg", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2025-4136" + ], + "details": "A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560782" + }, + { + "type": "WEB", + "url": "https://www.cnblogs.com/aibot/p/18830909" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pq3g-wwm5-c33r/GHSA-pq3g-wwm5-c33r.json b/advisories/unreviewed/2025/04/GHSA-pq3g-wwm5-c33r/GHSA-pq3g-wwm5-c33r.json index ebd4cbe2a48..398466e2a55 100644 --- a/advisories/unreviewed/2025/04/GHSA-pq3g-wwm5-c33r/GHSA-pq3g-wwm5-c33r.json +++ b/advisories/unreviewed/2025/04/GHSA-pq3g-wwm5-c33r/GHSA-pq3g-wwm5-c33r.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json b/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json index b8ac617b74b..91202b49526 100644 --- a/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json +++ b/advisories/unreviewed/2025/04/GHSA-qmf3-4g6f-3fjv/GHSA-qmf3-4g6f-3fjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmf3-4g6f-3fjv", - "modified": "2025-04-30T18:31:55Z", + "modified": "2025-04-30T21:31:48Z", "published": "2025-04-30T18:31:55Z", "aliases": [ "CVE-2025-24091" ], "details": "An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T18:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qvq2-c564-ccww/GHSA-qvq2-c564-ccww.json b/advisories/unreviewed/2025/04/GHSA-qvq2-c564-ccww/GHSA-qvq2-c564-ccww.json new file mode 100644 index 00000000000..886b48db185 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qvq2-c564-ccww/GHSA-qvq2-c564-ccww.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvq2-c564-ccww", + "modified": "2025-04-30T21:31:48Z", + "published": "2025-04-30T21:31:48Z", + "aliases": [ + "CVE-2024-9876" + ], + "details": ": Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9876" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=2CRT000006&LanguageCode=en&DocumentPartId=PDF&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-471" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhhx-3c3j-fp5h/GHSA-vhhx-3c3j-fp5h.json b/advisories/unreviewed/2025/04/GHSA-vhhx-3c3j-fp5h/GHSA-vhhx-3c3j-fp5h.json index 581ee19099a..41d05be0bac 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhhx-3c3j-fp5h/GHSA-vhhx-3c3j-fp5h.json +++ b/advisories/unreviewed/2025/04/GHSA-vhhx-3c3j-fp5h/GHSA-vhhx-3c3j-fp5h.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-w56q-jx3j-44rq/GHSA-w56q-jx3j-44rq.json b/advisories/unreviewed/2025/04/GHSA-w56q-jx3j-44rq/GHSA-w56q-jx3j-44rq.json new file mode 100644 index 00000000000..371d0702de2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w56q-jx3j-44rq/GHSA-w56q-jx3j-44rq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w56q-jx3j-44rq", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2025-4139" + ], + "details": "A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4139" + }, + { + "type": "WEB", + "url": "https://github.com/jylsec/vuldb/blob/main/Netgear/netgear_ex6120/Buffer_overflow-fwAcosCgiInbound-port_end/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306631" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306631" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560785" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T21:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wfj7-6gw7-5442/GHSA-wfj7-6gw7-5442.json b/advisories/unreviewed/2025/04/GHSA-wfj7-6gw7-5442/GHSA-wfj7-6gw7-5442.json new file mode 100644 index 00000000000..e4a273229db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wfj7-6gw7-5442/GHSA-wfj7-6gw7-5442.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfj7-6gw7-5442", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2022-42449" + ], + "details": "Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42449" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120722" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json b/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json new file mode 100644 index 00000000000..b6adff1806f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpg9-62c8-xpvc", + "modified": "2025-04-30T21:31:50Z", + "published": "2025-04-30T21:31:50Z", + "aliases": [ + "CVE-2025-30422" + ], + "details": "A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30422" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122403" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T21:15:54Z" + } +} \ No newline at end of file