diff --git a/advisories/github-reviewed/2025/05/GHSA-8x27-jwjr-8545/GHSA-8x27-jwjr-8545.json b/advisories/github-reviewed/2025/05/GHSA-8x27-jwjr-8545/GHSA-8x27-jwjr-8545.json index 0fffa2e9478..7c0431dcc9f 100644 --- a/advisories/github-reviewed/2025/05/GHSA-8x27-jwjr-8545/GHSA-8x27-jwjr-8545.json +++ b/advisories/github-reviewed/2025/05/GHSA-8x27-jwjr-8545/GHSA-8x27-jwjr-8545.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x27-jwjr-8545", - "modified": "2025-05-05T21:53:44Z", + "modified": "2025-05-26T18:30:24Z", "published": "2025-05-01T13:59:51Z", "aliases": [ "CVE-2025-46337" @@ -59,6 +59,10 @@ "type": "PACKAGE", "url": "https://github.com/ADOdb/ADOdb" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00029.html" + }, { "type": "WEB", "url": "https://xaliom.blogspot.com/2025/05/from-sast-to-cve-2025-46337.html" diff --git a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json index 27250450af6..4506a5e56de 100644 --- a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json +++ b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9fv-h47r-823f", - "modified": "2025-04-19T03:31:27Z", + "modified": "2025-05-26T18:30:24Z", "published": "2025-01-20T15:31:22Z", "aliases": [ "CVE-2024-13176" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html" + }, { "type": "WEB", "url": "https://openssl-library.org/news/secadv/20250120.txt" diff --git a/advisories/unreviewed/2025/05/GHSA-84g7-x869-xfgv/GHSA-84g7-x869-xfgv.json b/advisories/unreviewed/2025/05/GHSA-84g7-x869-xfgv/GHSA-84g7-x869-xfgv.json new file mode 100644 index 00000000000..6b36bf36906 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-84g7-x869-xfgv/GHSA-84g7-x869-xfgv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84g7-x869-xfgv", + "modified": "2025-05-26T18:30:25Z", + "published": "2025-05-26T18:30:25Z", + "aliases": [ + "CVE-2025-23395" + ], + "details": "Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23395" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23395" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/05/12/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-271" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2cq-wg23-g8qw/GHSA-g2cq-wg23-g8qw.json b/advisories/unreviewed/2025/05/GHSA-g2cq-wg23-g8qw/GHSA-g2cq-wg23-g8qw.json index 1134bea2db0..4ba60ca9b56 100644 --- a/advisories/unreviewed/2025/05/GHSA-g2cq-wg23-g8qw/GHSA-g2cq-wg23-g8qw.json +++ b/advisories/unreviewed/2025/05/GHSA-g2cq-wg23-g8qw/GHSA-g2cq-wg23-g8qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2cq-wg23-g8qw", - "modified": "2025-05-26T15:30:34Z", + "modified": "2025-05-26T18:30:25Z", "published": "2025-05-26T15:30:34Z", "aliases": [ "CVE-2025-46803" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2025/05/12/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json b/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json new file mode 100644 index 00000000000..8db92076a07 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5xr-h2vq-97x6", + "modified": "2025-05-26T18:30:25Z", + "published": "2025-05-26T18:30:25Z", + "aliases": [ + "CVE-2025-23394" + ], + "details": "A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23394" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23394" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json b/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json new file mode 100644 index 00000000000..81ddf91f471 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh76-vmrr-w867", + "modified": "2025-05-26T18:30:25Z", + "published": "2025-05-26T18:30:25Z", + "aliases": [ + "CVE-2025-46802" + ], + "details": "For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46802" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46802" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/05/12/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T16:15:20Z" + } +} \ No newline at end of file