From 83c46ef46dbbaee9d75251b24e000126662e6e72 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Mar 2025 15:32:12 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cg4p-5qfm-pjjj.json | 39 +++++++++-- .../GHSA-q7jg-7ww6-99x3.json | 6 +- .../GHSA-cc6x-6938-549x.json | 2 +- .../GHSA-39h8-m6rh-4934.json | 2 +- .../GHSA-8v9g-m6c6-6756.json | 2 +- .../GHSA-mh2m-m37r-927m.json | 2 +- .../GHSA-v2q6-5m4m-pr58.json | 2 +- .../GHSA-wq4c-r2c3-fv9c.json | 6 +- .../GHSA-gvxc-64wh-vgv2.json | 4 +- .../GHSA-q8qv-35px-5j77.json | 4 +- .../GHSA-vmcx-j4f5-gfcv.json | 11 +++- .../GHSA-qm5f-3c7g-gj8r.json | 2 +- .../GHSA-v793-w449-37r3.json | 6 +- .../GHSA-4257-qx96-mgcq.json | 33 ++++++++++ .../GHSA-5rfm-vp96-44gv.json | 15 +++-- .../GHSA-6f67-378m-2772.json | 15 +++-- .../GHSA-6q3p-m444-94qp.json | 64 +++++++++++++++++++ .../GHSA-7mhp-jcj6-vjwp.json | 29 +++++++++ .../GHSA-82gg-jm8m-39w6.json | 15 +++-- .../GHSA-938x-rjx9-c9f3.json | 2 +- .../GHSA-989p-xhj8-3ff8.json | 29 +++++++++ .../GHSA-c9x5-m6c9-whj3.json | 56 ++++++++++++++++ .../GHSA-f9q9-85g5-cwgj.json | 15 +++-- .../GHSA-g38j-p66c-6qhp.json | 15 +++-- .../GHSA-gq4x-2qp9-2gvw.json | 64 +++++++++++++++++++ .../GHSA-hx56-4qgw-5q6r.json | 15 +++-- .../GHSA-jg9g-2m55-m7hp.json | 15 +++-- .../GHSA-q28f-p3wj-9rm8.json | 15 +++-- .../GHSA-r73f-2rxh-prfm.json | 36 +++++++++++ .../GHSA-w5h7-mw56-4v7x.json | 15 +++-- .../GHSA-wvxc-3fj4-37rg.json | 56 ++++++++++++++++ .../GHSA-x45p-6x9h-wr36.json | 56 ++++++++++++++++ .../GHSA-x7rr-8x5p-q75q.json | 36 +++++++++++ 33 files changed, 628 insertions(+), 56 deletions(-) rename advisories/{unreviewed => github-reviewed}/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json (57%) create mode 100644 advisories/unreviewed/2025/03/GHSA-4257-qx96-mgcq/GHSA-4257-qx96-mgcq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6q3p-m444-94qp/GHSA-6q3p-m444-94qp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7mhp-jcj6-vjwp/GHSA-7mhp-jcj6-vjwp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-989p-xhj8-3ff8/GHSA-989p-xhj8-3ff8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c9x5-m6c9-whj3/GHSA-c9x5-m6c9-whj3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gq4x-2qp9-2gvw/GHSA-gq4x-2qp9-2gvw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r73f-2rxh-prfm/GHSA-r73f-2rxh-prfm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wvxc-3fj4-37rg/GHSA-wvxc-3fj4-37rg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x7rr-8x5p-q75q/GHSA-x7rr-8x5p-q75q.json diff --git a/advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json b/advisories/github-reviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json similarity index 57% rename from advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json rename to advisories/github-reviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json index cc5a4e09df1..071f89f6052 100644 --- a/advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json +++ b/advisories/github-reviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json @@ -1,24 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-cg4p-5qfm-pjjj", - "modified": "2025-03-20T12:32:40Z", + "modified": "2025-03-21T15:30:34Z", "published": "2025-03-20T12:32:40Z", "aliases": [ "CVE-2024-10713" ], + "summary": "HyperLPR Denial of Service vulnerability", "details": "A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to the end of multipart boundaries, regardless of the character used. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive resource consumption and a complete denial of service for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "hyperlpr3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.0" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10713" }, + { + "type": "WEB", + "url": "https://github.com/szad670401/HyperLPR/blob/9307450f7b7915be18f23a539ec05b41fe6629f4/Prj-Python/hyperlpr3/command/serve.py#L95" + }, + { + "type": "PACKAGE", + "url": "https://github.com/szad670401/hyperlpr" + }, { "type": "WEB", "url": "https://huntr.com/bounties/d5404069-95b3-40e0-a7a4-c3a183d861b0" @@ -29,8 +58,8 @@ "CWE-400" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T15:30:34Z", "nvd_published_at": "2025-03-20T10:15:18Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json b/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json index 688fbf79c9f..bae27517acd 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json +++ b/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7jg-7ww6-99x3", - "modified": "2025-03-20T15:30:23Z", + "modified": "2025-03-21T15:31:07Z", "published": "2022-05-24T16:56:04Z", "aliases": [ "CVE-2019-16261" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://blog.korelogic.com/blog/2019/08/19/unpatched_fringe_infrastructure_bits" }, + { + "type": "WEB", + "url": "https://gist.github.com/Shlucus/ab762d6b148f2d2d046c956526a80ddc" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2025/Mar/1" diff --git a/advisories/unreviewed/2022/09/GHSA-cc6x-6938-549x/GHSA-cc6x-6938-549x.json b/advisories/unreviewed/2022/09/GHSA-cc6x-6938-549x/GHSA-cc6x-6938-549x.json index 4dd2af35d3b..112b9217a60 100644 --- a/advisories/unreviewed/2022/09/GHSA-cc6x-6938-549x/GHSA-cc6x-6938-549x.json +++ b/advisories/unreviewed/2022/09/GHSA-cc6x-6938-549x/GHSA-cc6x-6938-549x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc6x-6938-549x", - "modified": "2022-09-18T00:00:35Z", + "modified": "2025-03-21T15:31:08Z", "published": "2022-09-14T00:00:42Z", "aliases": [ "CVE-2022-38329" diff --git a/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json b/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json index c2edc04f1de..d8712b31e62 100644 --- a/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json +++ b/advisories/unreviewed/2023/02/GHSA-39h8-m6rh-4934/GHSA-39h8-m6rh-4934.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-39h8-m6rh-4934", - "modified": "2023-02-24T18:30:27Z", + "modified": "2025-03-21T15:31:08Z", "published": "2023-02-13T03:30:28Z", "aliases": [ "CVE-2023-22362" diff --git a/advisories/unreviewed/2023/02/GHSA-8v9g-m6c6-6756/GHSA-8v9g-m6c6-6756.json b/advisories/unreviewed/2023/02/GHSA-8v9g-m6c6-6756/GHSA-8v9g-m6c6-6756.json index 5842a824f82..4987663c956 100644 --- a/advisories/unreviewed/2023/02/GHSA-8v9g-m6c6-6756/GHSA-8v9g-m6c6-6756.json +++ b/advisories/unreviewed/2023/02/GHSA-8v9g-m6c6-6756/GHSA-8v9g-m6c6-6756.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8v9g-m6c6-6756", - "modified": "2023-02-27T15:30:22Z", + "modified": "2025-03-21T15:31:08Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22349" diff --git a/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json b/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json index 0d44baff02c..6e54ab36e9a 100644 --- a/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json +++ b/advisories/unreviewed/2023/02/GHSA-mh2m-m37r-927m/GHSA-mh2m-m37r-927m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh2m-m37r-927m", - "modified": "2023-02-24T18:30:28Z", + "modified": "2025-03-21T15:31:08Z", "published": "2023-02-13T06:30:59Z", "aliases": [ "CVE-2022-48323" diff --git a/advisories/unreviewed/2023/02/GHSA-v2q6-5m4m-pr58/GHSA-v2q6-5m4m-pr58.json b/advisories/unreviewed/2023/02/GHSA-v2q6-5m4m-pr58/GHSA-v2q6-5m4m-pr58.json index c076546bb3e..154407111c6 100644 --- a/advisories/unreviewed/2023/02/GHSA-v2q6-5m4m-pr58/GHSA-v2q6-5m4m-pr58.json +++ b/advisories/unreviewed/2023/02/GHSA-v2q6-5m4m-pr58/GHSA-v2q6-5m4m-pr58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v2q6-5m4m-pr58", - "modified": "2023-02-23T18:31:06Z", + "modified": "2025-03-21T15:31:09Z", "published": "2023-02-13T21:31:04Z", "aliases": [ "CVE-2023-25719" diff --git a/advisories/unreviewed/2023/02/GHSA-wq4c-r2c3-fv9c/GHSA-wq4c-r2c3-fv9c.json b/advisories/unreviewed/2023/02/GHSA-wq4c-r2c3-fv9c/GHSA-wq4c-r2c3-fv9c.json index d475c892db7..f07d7f84fe6 100644 --- a/advisories/unreviewed/2023/02/GHSA-wq4c-r2c3-fv9c/GHSA-wq4c-r2c3-fv9c.json +++ b/advisories/unreviewed/2023/02/GHSA-wq4c-r2c3-fv9c/GHSA-wq4c-r2c3-fv9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq4c-r2c3-fv9c", - "modified": "2023-02-15T18:30:21Z", + "modified": "2025-03-21T15:31:10Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0804" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00026.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FBF3UUFSB6NB3NFTQSKOOIZGXJP3T34Z" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FBF3UUFSB6NB3NFTQSKOOIZGXJP3T34Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json b/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json index a4dbe4c1b33..5adf4602522 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json +++ b/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json b/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json index 66a56d0ac2e..213f5d4e2ec 100644 --- a/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json +++ b/advisories/unreviewed/2024/04/GHSA-q8qv-35px-5j77/GHSA-q8qv-35px-5j77.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-908" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json b/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json index 4b76d932492..ab2956953c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json +++ b/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmcx-j4f5-gfcv", - "modified": "2024-04-17T12:32:05Z", + "modified": "2025-03-21T15:31:10Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26896" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wfx: fix memory leak when starting AP\n\nKmemleak reported this error:\n\n unreferenced object 0xd73d1180 (size 184):\n comm \"wpa_supplicant\", pid 1559, jiffies 13006305 (age 964.245s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 1e 00 01 00 00 00 00 00 ................\n backtrace:\n [<5ca11420>] kmem_cache_alloc+0x20c/0x5ac\n [<127bdd74>] __alloc_skb+0x144/0x170\n [] __netdev_alloc_skb+0x50/0x180\n [<0f9fa1d5>] __ieee80211_beacon_get+0x290/0x4d4 [mac80211]\n [<7accd02d>] ieee80211_beacon_get_tim+0x54/0x18c [mac80211]\n [<41e25cc3>] wfx_start_ap+0xc8/0x234 [wfx]\n [<93a70356>] ieee80211_start_ap+0x404/0x6b4 [mac80211]\n [] nl80211_start_ap+0x76c/0x9e0 [cfg80211]\n [<47bd8b68>] genl_rcv_msg+0x198/0x378\n [<453ef796>] netlink_rcv_skb+0xd0/0x130\n [<6b7c977a>] genl_rcv+0x34/0x44\n [<66b2d04d>] netlink_unicast+0x1b4/0x258\n [] netlink_sendmsg+0x1e8/0x428\n [] ____sys_sendmsg+0x1e0/0x274\n [] ___sys_sendmsg+0x80/0xb4\n [<69954f45>] __sys_sendmsg+0x64/0xa8\n unreferenced object 0xce087000 (size 1024):\n comm \"wpa_supplicant\", pid 1559, jiffies 13006305 (age 964.246s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 10 00 07 40 00 00 00 00 00 00 00 00 00 00 00 00 ...@............\n backtrace:\n [<9a993714>] __kmalloc_track_caller+0x230/0x600\n [] kmalloc_reserve.constprop.0+0x30/0x74\n [] __alloc_skb+0xa0/0x170\n [] __netdev_alloc_skb+0x50/0x180\n [<0f9fa1d5>] __ieee80211_beacon_get+0x290/0x4d4 [mac80211]\n [<7accd02d>] ieee80211_beacon_get_tim+0x54/0x18c [mac80211]\n [<41e25cc3>] wfx_start_ap+0xc8/0x234 [wfx]\n [<93a70356>] ieee80211_start_ap+0x404/0x6b4 [mac80211]\n [] nl80211_start_ap+0x76c/0x9e0 [cfg80211]\n [<47bd8b68>] genl_rcv_msg+0x198/0x378\n [<453ef796>] netlink_rcv_skb+0xd0/0x130\n [<6b7c977a>] genl_rcv+0x34/0x44\n [<66b2d04d>] netlink_unicast+0x1b4/0x258\n [] netlink_sendmsg+0x1e8/0x428\n [] ____sys_sendmsg+0x1e0/0x274\n [] ___sys_sendmsg+0x80/0xb4\n\nHowever, since the kernel is build optimized, it seems the stack is not\naccurate. It appears the issue is related to wfx_set_mfp_ap(). The issue\nis obvious in this function: memory allocated by ieee80211_beacon_get()\nis never released. Fixing this leak makes kmemleak happy.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qm5f-3c7g-gj8r/GHSA-qm5f-3c7g-gj8r.json b/advisories/unreviewed/2025/02/GHSA-qm5f-3c7g-gj8r/GHSA-qm5f-3c7g-gj8r.json index 620be293142..a2639770a34 100644 --- a/advisories/unreviewed/2025/02/GHSA-qm5f-3c7g-gj8r/GHSA-qm5f-3c7g-gj8r.json +++ b/advisories/unreviewed/2025/02/GHSA-qm5f-3c7g-gj8r/GHSA-qm5f-3c7g-gj8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm5f-3c7g-gj8r", - "modified": "2025-02-27T06:30:53Z", + "modified": "2025-03-21T15:31:11Z", "published": "2025-02-27T06:30:53Z", "aliases": [ "CVE-2024-13647" diff --git a/advisories/unreviewed/2025/02/GHSA-v793-w449-37r3/GHSA-v793-w449-37r3.json b/advisories/unreviewed/2025/02/GHSA-v793-w449-37r3/GHSA-v793-w449-37r3.json index e3727bbf1d4..63e7e15f464 100644 --- a/advisories/unreviewed/2025/02/GHSA-v793-w449-37r3/GHSA-v793-w449-37r3.json +++ b/advisories/unreviewed/2025/02/GHSA-v793-w449-37r3/GHSA-v793-w449-37r3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v793-w449-37r3", - "modified": "2025-02-16T06:31:45Z", + "modified": "2025-03-21T15:31:11Z", "published": "2025-02-16T06:31:45Z", "aliases": [ "CVE-2024-57971" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/KnowageLabs/Knowage-Server/compare/v8.1.29...v8.1.30" }, + { + "type": "WEB", + "url": "https://github.com/darumaseye/CVEs/blob/ec2de9f7ecffde466e687745bfdfc672e86241d7/CVE-2024-57971.md" + }, { "type": "WEB", "url": "https://spagobi.readthedocs.io" diff --git a/advisories/unreviewed/2025/03/GHSA-4257-qx96-mgcq/GHSA-4257-qx96-mgcq.json b/advisories/unreviewed/2025/03/GHSA-4257-qx96-mgcq/GHSA-4257-qx96-mgcq.json new file mode 100644 index 00000000000..785e66e279d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4257-qx96-mgcq/GHSA-4257-qx96-mgcq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4257-qx96-mgcq", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2024-57490" + ], + "details": "Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through a logical flaw.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57490" + }, + { + "type": "WEB", + "url": "https://gist.github.com/NaliangzzZ/44bfcc1d9c2cf275d2b6683ca9e20980" + }, + { + "type": "WEB", + "url": "https://www.ioffice.cn" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json b/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json index 165c551e844..9bfd565a401 100644 --- a/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json +++ b/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rfm-vp96-44gv", - "modified": "2025-03-18T15:30:49Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-18T15:30:49Z", "aliases": [ "CVE-2025-30113" ], "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:02Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json b/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json index ee23bb63e98..d89a5ba9bb3 100644 --- a/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json +++ b/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6f67-378m-2772", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2024-54559" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T20:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6q3p-m444-94qp/GHSA-6q3p-m444-94qp.json b/advisories/unreviewed/2025/03/GHSA-6q3p-m444-94qp/GHSA-6q3p-m444-94qp.json new file mode 100644 index 00000000000..255d7068c40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6q3p-m444-94qp/GHSA-6q3p-m444-94qp.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q3p-m444-94qp", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-2591" + ], + "details": "A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2591" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6009" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6009#issue-2877367021" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/pull/6047" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/pull/6047/commits/ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300574" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300574" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517781" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7mhp-jcj6-vjwp/GHSA-7mhp-jcj6-vjwp.json b/advisories/unreviewed/2025/03/GHSA-7mhp-jcj6-vjwp/GHSA-7mhp-jcj6-vjwp.json new file mode 100644 index 00000000000..a51270c7e94 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7mhp-jcj6-vjwp/GHSA-7mhp-jcj6-vjwp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mhp-jcj6-vjwp", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-29641" + ], + "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29641" + }, + { + "type": "WEB", + "url": "https://github.com/Pei4AN/CVE/issues/5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json b/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json index d36665f5ad9..9c34a107aa9 100644 --- a/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json +++ b/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-82gg-jm8m-39w6", - "modified": "2025-03-18T15:30:50Z", + "modified": "2025-03-21T15:31:14Z", "published": "2025-03-18T15:30:50Z", "aliases": [ "CVE-2025-30115" ], "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password (\"qwertyuiop\"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-259" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:02Z" diff --git a/advisories/unreviewed/2025/03/GHSA-938x-rjx9-c9f3/GHSA-938x-rjx9-c9f3.json b/advisories/unreviewed/2025/03/GHSA-938x-rjx9-c9f3/GHSA-938x-rjx9-c9f3.json index 86bb32e7fbf..d17759247bd 100644 --- a/advisories/unreviewed/2025/03/GHSA-938x-rjx9-c9f3/GHSA-938x-rjx9-c9f3.json +++ b/advisories/unreviewed/2025/03/GHSA-938x-rjx9-c9f3/GHSA-938x-rjx9-c9f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-938x-rjx9-c9f3", - "modified": "2025-03-14T09:34:06Z", + "modified": "2025-03-21T15:31:12Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2025-2221" diff --git a/advisories/unreviewed/2025/03/GHSA-989p-xhj8-3ff8/GHSA-989p-xhj8-3ff8.json b/advisories/unreviewed/2025/03/GHSA-989p-xhj8-3ff8/GHSA-989p-xhj8-3ff8.json new file mode 100644 index 00000000000..8e5f686a24f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-989p-xhj8-3ff8/GHSA-989p-xhj8-3ff8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-989p-xhj8-3ff8", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-29640" + ], + "details": "Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29640" + }, + { + "type": "WEB", + "url": "https://github.com/Pei4AN/CVE/issues/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c9x5-m6c9-whj3/GHSA-c9x5-m6c9-whj3.json b/advisories/unreviewed/2025/03/GHSA-c9x5-m6c9-whj3/GHSA-c9x5-m6c9-whj3.json new file mode 100644 index 00000000000..a5f3ac9b4ed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c9x5-m6c9-whj3/GHSA-c9x5-m6c9-whj3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9x5-m6c9-whj3", + "modified": "2025-03-21T15:31:14Z", + "published": "2025-03-21T15:31:14Z", + "aliases": [ + "CVE-2025-2590" + ], + "details": "A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function UpdateRecruitmentById of the file \\handler\\recruitment.go. The manipulation of the argument c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2590" + }, + { + "type": "WEB", + "url": "https://github.com/38279/1/issues/2" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300570" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300570" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517344" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json b/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json index ec77a2ac7e7..eccdd9adc9d 100644 --- a/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json +++ b/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9q9-85g5-cwgj", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2024-54525" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in visionOS 2.2, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T20:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json b/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json index 5b25de5f29d..0835ee5062a 100644 --- a/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json +++ b/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g38j-p66c-6qhp", - "modified": "2025-03-18T15:30:50Z", + "modified": "2025-03-21T15:31:14Z", "published": "2025-03-18T15:30:50Z", "aliases": [ "CVE-2025-30132" ], "details": "An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During analysis, it was found that this domain was not owned by IROAD, allowing an attacker to register it and potentially intercept sensitive device traffic. If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:03Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gq4x-2qp9-2gvw/GHSA-gq4x-2qp9-2gvw.json b/advisories/unreviewed/2025/03/GHSA-gq4x-2qp9-2gvw/GHSA-gq4x-2qp9-2gvw.json new file mode 100644 index 00000000000..83793f583a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gq4x-2qp9-2gvw/GHSA-gq4x-2qp9-2gvw.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq4x-2qp9-2gvw", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-2592" + ], + "details": "A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2592" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6010" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6010#issue-2877368110" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/pull/6052" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/commit/2690e354da0c681db000cfd892a55226788f2743" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300575" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300575" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517782" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json b/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json index 2abf049905a..9a9c39f22fa 100644 --- a/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json +++ b/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx56-4qgw-5q6r", - "modified": "2025-03-17T18:31:52Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-17T18:31:52Z", "aliases": [ "CVE-2025-25685" ], "details": "An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T17:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json b/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json index ea8a4a0692e..72ac678df42 100644 --- a/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json +++ b/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jg9g-2m55-m7hp", - "modified": "2025-03-18T15:30:50Z", + "modified": "2025-03-21T15:31:14Z", "published": "2025-03-18T15:30:50Z", "aliases": [ "CVE-2025-30122" ], "details": "An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:03Z" diff --git a/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json b/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json index f250eb6faac..9f20e7016fe 100644 --- a/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json +++ b/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q28f-p3wj-9rm8", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2024-54565" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T20:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r73f-2rxh-prfm/GHSA-r73f-2rxh-prfm.json b/advisories/unreviewed/2025/03/GHSA-r73f-2rxh-prfm/GHSA-r73f-2rxh-prfm.json new file mode 100644 index 00000000000..3cee294fd71 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r73f-2rxh-prfm/GHSA-r73f-2rxh-prfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r73f-2rxh-prfm", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2021-25635" + ], + "details": "An Improper Certificate Validation vulnerability in LibreOffice allowed \nan attacker to self sign an ODF document, with a signature untrusted by \nthe target, then modify it to change the signature algorithm to an \ninvalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a \nvalid signature issued by a trusted person\n\n\nThis issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25635" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2021-25635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json b/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json index 1230ac0e4bd..037dafaa9b0 100644 --- a/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json +++ b/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5h7-mw56-4v7x", - "modified": "2025-03-18T15:30:48Z", + "modified": "2025-03-21T15:31:13Z", "published": "2025-03-18T15:30:48Z", "aliases": [ "CVE-2024-44314" ], "details": "TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wvxc-3fj4-37rg/GHSA-wvxc-3fj4-37rg.json b/advisories/unreviewed/2025/03/GHSA-wvxc-3fj4-37rg/GHSA-wvxc-3fj4-37rg.json new file mode 100644 index 00000000000..cd04db64fb8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wvxc-3fj4-37rg/GHSA-wvxc-3fj4-37rg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvxc-3fj4-37rg", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-2593" + ], + "details": "A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/client/article/list. The manipulation of the argument orderBy leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2593" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/8" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300577" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300577" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517926" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json b/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json new file mode 100644 index 00000000000..4d98e5c3a87 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x45p-6x9h-wr36", + "modified": "2025-03-21T15:31:14Z", + "published": "2025-03-21T15:31:14Z", + "aliases": [ + "CVE-2025-2589" + ], + "details": "A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \\handler\\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2589" + }, + { + "type": "WEB", + "url": "https://github.com/38279/1/issues/1" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300569" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300569" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x7rr-8x5p-q75q/GHSA-x7rr-8x5p-q75q.json b/advisories/unreviewed/2025/03/GHSA-x7rr-8x5p-q75q/GHSA-x7rr-8x5p-q75q.json new file mode 100644 index 00000000000..6fb51c7f16f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x7rr-8x5p-q75q/GHSA-x7rr-8x5p-q75q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7rr-8x5p-q75q", + "modified": "2025-03-21T15:31:15Z", + "published": "2025-03-21T15:31:15Z", + "aliases": [ + "CVE-2025-24915" + ], + "details": "When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories.  This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24915" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2025-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T15:15:42Z" + } +} \ No newline at end of file