mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-2c3r-m2jh-rjmh GHSA-5h78-99vm-hr67 GHSA-7768-6597-437r GHSA-7fx6-2hh7-7q8r GHSA-87c6-wxwq-rjm3 GHSA-9g53-92w9-464m GHSA-c3q8-4394-xw76 GHSA-h26x-295r-3cj4 GHSA-mf9p-6469-jcwh GHSA-mw9f-cfv6-v3rg GHSA-wghf-qmx9-35pp GHSA-wv49-qgp8-wcjg GHSA-ww4p-f4jp-c2xm GHSA-xhmh-cq7j-qhjr GHSA-xxpx-f58m-683f
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2c3r-m2jh-rjmh",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29982"
|
||||
],
|
||||
"details": "Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29982"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-277"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5h78-99vm-hr67",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-27692"
|
||||
],
|
||||
"details": "Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27692"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-434"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7768-6597-437r",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3073"
|
||||
],
|
||||
"details": "Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3073"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/388680893"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7fx6-2hh7-7q8r",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3068"
|
||||
],
|
||||
"details": "Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3068"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/401823929"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-87c6-wxwq-rjm3",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-27693"
|
||||
],
|
||||
"details": "Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27693"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9g53-92w9-464m",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2779"
|
||||
],
|
||||
"details": "The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2779"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/browser/insert-headers-and-footers-script/tags/1.1.2/admin/class-rating-notice.php#L59"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75bc2295-bf9a-430f-92b7-d380eed6df11?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T02:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c3q8-4394-xw76",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3067"
|
||||
],
|
||||
"details": "Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3067"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/376491759"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h26x-295r-3cj4",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3074"
|
||||
],
|
||||
"details": "Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3074"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/392818696"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mf9p-6469-jcwh",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3071"
|
||||
],
|
||||
"details": "Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3071"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/40051596"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mw9f-cfv6-v3rg",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3066"
|
||||
],
|
||||
"details": "Use after free in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3066"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/405140652"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wghf-qmx9-35pp",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3072"
|
||||
],
|
||||
"details": "Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3072"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/362545037"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wv49-qgp8-wcjg",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29981"
|
||||
],
|
||||
"details": "Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29981"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-202"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ww4p-f4jp-c2xm",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3070"
|
||||
],
|
||||
"details": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3070"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/40086360"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xhmh-cq7j-qhjr",
|
||||
"modified": "2025-04-02T03:31:43Z",
|
||||
"published": "2025-04-02T03:31:43Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3069"
|
||||
],
|
||||
"details": "Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3069"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/40060076"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:38Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xxpx-f58m-683f",
|
||||
"modified": "2025-04-02T03:31:42Z",
|
||||
"published": "2025-04-02T03:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-27694"
|
||||
],
|
||||
"details": "Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27694"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-410"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-02T01:15:37Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user