diff --git a/advisories/unreviewed/2022/05/GHSA-7377-5g8x-pp8m/GHSA-7377-5g8x-pp8m.json b/advisories/unreviewed/2022/05/GHSA-7377-5g8x-pp8m/GHSA-7377-5g8x-pp8m.json index 496cde38e14..208de9f75f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7377-5g8x-pp8m/GHSA-7377-5g8x-pp8m.json +++ b/advisories/unreviewed/2022/05/GHSA-7377-5g8x-pp8m/GHSA-7377-5g8x-pp8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7377-5g8x-pp8m", - "modified": "2022-05-14T03:50:03Z", + "modified": "2025-04-20T03:50:41Z", "published": "2022-05-14T03:50:03Z", "aliases": [ "CVE-2017-18006" diff --git a/advisories/unreviewed/2022/05/GHSA-f2x4-v4rc-rwrp/GHSA-f2x4-v4rc-rwrp.json b/advisories/unreviewed/2022/05/GHSA-f2x4-v4rc-rwrp/GHSA-f2x4-v4rc-rwrp.json index ce838bbc1a3..933b9585c83 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2x4-v4rc-rwrp/GHSA-f2x4-v4rc-rwrp.json +++ b/advisories/unreviewed/2022/05/GHSA-f2x4-v4rc-rwrp/GHSA-f2x4-v4rc-rwrp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2x4-v4rc-rwrp", - "modified": "2022-05-14T03:21:36Z", + "modified": "2025-04-20T03:50:40Z", "published": "2022-05-14T03:21:36Z", "aliases": [ "CVE-2017-17975" diff --git a/advisories/unreviewed/2022/05/GHSA-p7mr-jqmx-qq7x/GHSA-p7mr-jqmx-qq7x.json b/advisories/unreviewed/2022/05/GHSA-p7mr-jqmx-qq7x/GHSA-p7mr-jqmx-qq7x.json index 53334f7d0a3..1bc438b10c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7mr-jqmx-qq7x/GHSA-p7mr-jqmx-qq7x.json +++ b/advisories/unreviewed/2022/05/GHSA-p7mr-jqmx-qq7x/GHSA-p7mr-jqmx-qq7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7mr-jqmx-qq7x", - "modified": "2022-05-13T01:44:33Z", + "modified": "2025-04-20T03:50:41Z", "published": "2022-05-13T01:44:33Z", "aliases": [ "CVE-2017-18001" diff --git a/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json b/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json index 44d60ded7d2..7d4b3855cd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json +++ b/advisories/unreviewed/2022/05/GHSA-r4j5-63wj-7p3r/GHSA-r4j5-63wj-7p3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r4j5-63wj-7p3r", - "modified": "2022-05-14T02:48:49Z", + "modified": "2025-04-20T03:50:40Z", "published": "2022-05-14T02:48:49Z", "aliases": [ "CVE-2015-3302" diff --git a/advisories/unreviewed/2022/05/GHSA-rc73-pc24-f3rr/GHSA-rc73-pc24-f3rr.json b/advisories/unreviewed/2022/05/GHSA-rc73-pc24-f3rr/GHSA-rc73-pc24-f3rr.json index 46d2025570d..b4d8df0db6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc73-pc24-f3rr/GHSA-rc73-pc24-f3rr.json +++ b/advisories/unreviewed/2022/05/GHSA-rc73-pc24-f3rr/GHSA-rc73-pc24-f3rr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc73-pc24-f3rr", - "modified": "2022-05-14T01:29:45Z", + "modified": "2025-04-20T03:50:41Z", "published": "2022-05-14T01:29:45Z", "aliases": [ "CVE-2017-17997" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://code.wireshark.org/review/#/c/25063" }, + { + "type": "WEB", + "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=80a695869c9aef2fb473d9361da068022be7cb50" + }, { "type": "WEB", "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=80a695869c9aef2fb473d9361da068022be7cb50" diff --git a/advisories/unreviewed/2022/05/GHSA-xpw4-hqm8-rj97/GHSA-xpw4-hqm8-rj97.json b/advisories/unreviewed/2022/05/GHSA-xpw4-hqm8-rj97/GHSA-xpw4-hqm8-rj97.json index e18d073783c..37ca40604b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpw4-hqm8-rj97/GHSA-xpw4-hqm8-rj97.json +++ b/advisories/unreviewed/2022/05/GHSA-xpw4-hqm8-rj97/GHSA-xpw4-hqm8-rj97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpw4-hqm8-rj97", - "modified": "2022-05-13T01:30:27Z", + "modified": "2025-04-20T03:50:40Z", "published": "2022-05-13T01:30:27Z", "aliases": [ "CVE-2014-3630" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://groups.google.com/forum/#!topic/play-framework/WdbFvemsFDQ" }, + { + "type": "WEB", + "url": "https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ" + }, + { + "type": "WEB", + "url": "https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ" + }, { "type": "WEB", "url": "https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf" diff --git a/advisories/unreviewed/2025/04/GHSA-35m2-m3ch-fgh4/GHSA-35m2-m3ch-fgh4.json b/advisories/unreviewed/2025/04/GHSA-35m2-m3ch-fgh4/GHSA-35m2-m3ch-fgh4.json new file mode 100644 index 00000000000..e6bf1c8798e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35m2-m3ch-fgh4/GHSA-35m2-m3ch-fgh4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35m2-m3ch-fgh4", + "modified": "2025-04-20T03:50:41Z", + "published": "2025-04-20T03:50:41Z", + "aliases": [ + "CVE-2025-43920" + ], + "details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43920" + }, + { + "type": "WEB", + "url": "https://code.launchpad.net/~mailman-coders/mailman/2.1" + }, + { + "type": "WEB", + "url": "https://github.com/0NYX-MY7H/CVE-2025-43920" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-20T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-56r4-vj3r-h3vv/GHSA-56r4-vj3r-h3vv.json b/advisories/unreviewed/2025/04/GHSA-56r4-vj3r-h3vv/GHSA-56r4-vj3r-h3vv.json new file mode 100644 index 00000000000..6aaad1a0756 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-56r4-vj3r-h3vv/GHSA-56r4-vj3r-h3vv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56r4-vj3r-h3vv", + "modified": "2025-04-20T03:50:41Z", + "published": "2025-04-20T03:50:41Z", + "aliases": [ + "CVE-2025-43919" + ], + "details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43919" + }, + { + "type": "WEB", + "url": "https://code.launchpad.net/~mailman-coders/mailman/2.1" + }, + { + "type": "WEB", + "url": "https://github.com/0NYX-MY7H/CVE-2025-43919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-20T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-764p-g9xx-6qm8/GHSA-764p-g9xx-6qm8.json b/advisories/unreviewed/2025/04/GHSA-764p-g9xx-6qm8/GHSA-764p-g9xx-6qm8.json new file mode 100644 index 00000000000..b84161881ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-764p-g9xx-6qm8/GHSA-764p-g9xx-6qm8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-764p-g9xx-6qm8", + "modified": "2025-04-20T03:50:41Z", + "published": "2025-04-20T03:50:41Z", + "aliases": [ + "CVE-2025-43928" + ], + "details": "In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43928" + }, + { + "type": "WEB", + "url": "https://cfp.eh22.easterhegg.eu/eh22/talk/9UDXSE" + }, + { + "type": "WEB", + "url": "https://mint-secure.de/path-traversal-vulnerability-in-surveillance-software" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-20T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cch3-2vm3-v73j/GHSA-cch3-2vm3-v73j.json b/advisories/unreviewed/2025/04/GHSA-cch3-2vm3-v73j/GHSA-cch3-2vm3-v73j.json new file mode 100644 index 00000000000..b6d39eb5a50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cch3-2vm3-v73j/GHSA-cch3-2vm3-v73j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cch3-2vm3-v73j", + "modified": "2025-04-20T03:50:41Z", + "published": "2025-04-20T03:50:41Z", + "aliases": [ + "CVE-2025-43929" + ], + "details": "open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43929" + }, + { + "type": "WEB", + "url": "https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35" + }, + { + "type": "WEB", + "url": "https://ghostwriter.kde.org/documentation/#links" + }, + { + "type": "WEB", + "url": "https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-20T03:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ch5j-3wwr-pjvh/GHSA-ch5j-3wwr-pjvh.json b/advisories/unreviewed/2025/04/GHSA-ch5j-3wwr-pjvh/GHSA-ch5j-3wwr-pjvh.json new file mode 100644 index 00000000000..637e2057691 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ch5j-3wwr-pjvh/GHSA-ch5j-3wwr-pjvh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch5j-3wwr-pjvh", + "modified": "2025-04-20T03:50:41Z", + "published": "2025-04-20T03:50:41Z", + "aliases": [ + "CVE-2025-43921" + ], + "details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43921" + }, + { + "type": "WEB", + "url": "https://code.launchpad.net/~mailman-coders/mailman/2.1" + }, + { + "type": "WEB", + "url": "https://github.com/0NYX-MY7H/CVE-2025-43921" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-20T01:15:46Z" + } +} \ No newline at end of file