From 83f237212e0b0b8a77334ed3ddb04b8ae5e185c6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 22 May 2025 15:36:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8vcc-hrhr-q8hf.json | 9 ++- .../GHSA-99qr-vp84-f5fh.json | 9 ++- .../GHSA-239x-qr9g-j39q.json | 4 +- .../GHSA-2cv3-9jp8-rgg3.json | 11 +++- .../GHSA-37g6-48vw-mwpm.json | 10 +++- .../GHSA-3gr5-mvfp-p295.json | 11 +++- .../GHSA-4wg5-gh53-4jf5.json | 7 ++- .../GHSA-6h67-m47q-xj4p.json | 4 +- .../GHSA-75mx-hh4q-h54x.json | 10 +++- .../GHSA-7fvx-cw5x-7cm3.json | 6 +- .../GHSA-7jp8-whj2-j439.json | 10 +++- .../GHSA-8cf2-pgv8-hqvm.json | 3 +- .../GHSA-8p5p-w63v-mxqh.json | 4 +- .../GHSA-c9wp-mpwg-qr66.json | 4 +- .../GHSA-j9cg-v2v5-9p35.json | 11 +++- .../GHSA-m2pv-ff2q-qxxj.json | 6 +- .../GHSA-mmj5-42wx-3r4f.json | 4 +- .../GHSA-p7g7-h68c-47c2.json | 4 +- .../GHSA-pjw5-9wfg-rq3v.json | 9 ++- .../GHSA-q869-52p3-m2g6.json | 7 ++- .../GHSA-qc73-wjpr-m8fj.json | 6 +- .../GHSA-wff9-xm82-6wp2.json | 4 +- .../GHSA-xf3m-h4qp-mpv8.json | 2 +- .../GHSA-xmjv-jv6c-x229.json | 10 +++- .../GHSA-6fvm-vq2v-pwgq.json | 6 +- .../GHSA-2pv2-gg54-r8f4.json | 6 +- .../GHSA-8xc6-54p8-3p65.json | 6 +- .../GHSA-xq4p-6j59-jfv4.json | 23 ++++++-- .../GHSA-c6m8-29qv-7wq9.json | 10 +++- .../GHSA-v5h4-3gwf-6343.json | 14 ++++- .../GHSA-cvqv-vx57-8p4g.json | 2 +- .../GHSA-w83r-gj25-6vrc.json | 10 +++- .../GHSA-4xh3-3533-7mmv.json | 10 +++- .../GHSA-gjq7-3xfx-fg78.json | 5 +- .../GHSA-j2r5-qpjf-gcfc.json | 6 +- .../GHSA-q2w6-3cqh-h6qq.json | 10 +++- .../GHSA-2phg-f479-57pq.json | 6 +- .../GHSA-743f-m6p2-83h6.json | 6 +- .../GHSA-54fp-2qhf-47h6.json | 6 +- .../GHSA-9hrg-vg64-94qj.json | 6 +- .../GHSA-23cf-whmv-wf37.json | 10 +++- .../GHSA-2647-7h53-xfq5.json | 14 ++++- .../GHSA-g2g9-6hgr-7f52.json | 10 +++- .../GHSA-3p82-g7cx-7qrf.json | 56 +++++++++++++++++++ .../GHSA-4x77-62h7-m5pj.json | 40 +++++++++++++ .../GHSA-5c2w-vf3p-r6vw.json | 40 +++++++++++++ .../GHSA-5vj7-r55g-9xv7.json | 6 +- .../GHSA-62cm-c2h4-rg2m.json | 40 +++++++++++++ .../GHSA-63jr-j347-v237.json | 48 ++++++++++++++++ .../GHSA-662m-3r43-rvw4.json | 29 ++++++++++ .../GHSA-6hrx-7mgg-5cvp.json | 40 +++++++++++++ .../GHSA-6x78-fv59-ffxv.json | 52 +++++++++++++++++ .../GHSA-7rfw-87cg-pgwh.json | 40 +++++++++++++ .../GHSA-7vx5-gmqw-3wfc.json | 29 ++++++++++ .../GHSA-87v3-xghc-4m97.json | 52 +++++++++++++++++ .../GHSA-8xr7-6x2j-wgq9.json | 40 +++++++++++++ .../GHSA-9888-65w8-vw6m.json | 29 ++++++++++ .../GHSA-9h2c-gmfr-3w4c.json | 56 +++++++++++++++++++ .../GHSA-9vrq-hh79-6v9m.json | 36 ++++++++++++ .../GHSA-crr3-cvh5-8wfr.json | 40 +++++++++++++ .../GHSA-f333-vhwv-jvmx.json | 10 +++- .../GHSA-fhgm-mxgh-gfpj.json | 10 +++- .../GHSA-g6rf-7www-ggmp.json | 33 +++++++++++ .../GHSA-g8jq-rx5f-94q7.json | 40 +++++++++++++ .../GHSA-g93f-rhw4-8mj3.json | 40 +++++++++++++ .../GHSA-gfm6-h4jq-qp9r.json | 29 ++++++++++ .../GHSA-ggj2-v6c6-rgh4.json | 6 +- .../GHSA-gpxx-q8xc-r3mj.json | 36 ++++++++++++ .../GHSA-h279-pjhh-9hgj.json | 6 +- .../GHSA-hcrg-qr57-hr37.json | 40 +++++++++++++ .../GHSA-hf3p-gpvx-q597.json | 40 +++++++++++++ .../GHSA-j46h-hw72-jxqh.json | 40 +++++++++++++ .../GHSA-jqqw-x8w5-v4hh.json | 40 +++++++++++++ .../GHSA-jr34-3463-3cxq.json | 40 +++++++++++++ .../GHSA-mpm7-f6gv-ghwx.json | 56 +++++++++++++++++++ .../GHSA-prr2-m2fh-3hv6.json | 40 +++++++++++++ .../GHSA-q524-5rg8-2j6p.json | 40 +++++++++++++ .../GHSA-r3m4-8xwf-9fpp.json | 40 +++++++++++++ .../GHSA-r873-27qv-5m3w.json | 40 +++++++++++++ .../GHSA-v8qh-5c5w-48pp.json | 40 +++++++++++++ .../GHSA-v9g5-36x8-7xmx.json | 40 +++++++++++++ .../GHSA-vj38-xwp2-x5gc.json | 15 +++-- .../GHSA-vppg-gg96-53c9.json | 11 +++- .../GHSA-w939-6x76-94vc.json | 18 +++++- .../GHSA-xgvh-xrwg-wg4p.json | 56 +++++++++++++++++++ .../GHSA-xwrv-8p5w-52hj.json | 15 +++-- 86 files changed, 1757 insertions(+), 68 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4x77-62h7-m5pj/GHSA-4x77-62h7-m5pj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-63jr-j347-v237/GHSA-63jr-j347-v237.json create mode 100644 advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6x78-fv59-ffxv/GHSA-6x78-fv59-ffxv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7rfw-87cg-pgwh/GHSA-7rfw-87cg-pgwh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7vx5-gmqw-3wfc/GHSA-7vx5-gmqw-3wfc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-87v3-xghc-4m97/GHSA-87v3-xghc-4m97.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9888-65w8-vw6m/GHSA-9888-65w8-vw6m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9vrq-hh79-6v9m/GHSA-9vrq-hh79-6v9m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-crr3-cvh5-8wfr/GHSA-crr3-cvh5-8wfr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g93f-rhw4-8mj3/GHSA-g93f-rhw4-8mj3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gpxx-q8xc-r3mj/GHSA-gpxx-q8xc-r3mj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hf3p-gpvx-q597/GHSA-hf3p-gpvx-q597.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r3m4-8xwf-9fpp/GHSA-r3m4-8xwf-9fpp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r873-27qv-5m3w/GHSA-r873-27qv-5m3w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xgvh-xrwg-wg4p/GHSA-xgvh-xrwg-wg4p.json diff --git a/advisories/unreviewed/2022/01/GHSA-8vcc-hrhr-q8hf/GHSA-8vcc-hrhr-q8hf.json b/advisories/unreviewed/2022/01/GHSA-8vcc-hrhr-q8hf/GHSA-8vcc-hrhr-q8hf.json index fd911f4093e..0372791dac0 100644 --- a/advisories/unreviewed/2022/01/GHSA-8vcc-hrhr-q8hf/GHSA-8vcc-hrhr-q8hf.json +++ b/advisories/unreviewed/2022/01/GHSA-8vcc-hrhr-q8hf/GHSA-8vcc-hrhr-q8hf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vcc-hrhr-q8hf", - "modified": "2022-01-12T00:01:52Z", + "modified": "2025-05-22T15:34:37Z", "published": "2022-01-03T00:00:59Z", "aliases": [ "CVE-2022-0080" ], "details": "mruby is vulnerable to Heap-based Buffer Overflow", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/01/GHSA-99qr-vp84-f5fh/GHSA-99qr-vp84-f5fh.json b/advisories/unreviewed/2022/01/GHSA-99qr-vp84-f5fh/GHSA-99qr-vp84-f5fh.json index 21b006c53bc..cc81329f40e 100644 --- a/advisories/unreviewed/2022/01/GHSA-99qr-vp84-f5fh/GHSA-99qr-vp84-f5fh.json +++ b/advisories/unreviewed/2022/01/GHSA-99qr-vp84-f5fh/GHSA-99qr-vp84-f5fh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99qr-vp84-f5fh", - "modified": "2022-01-13T00:01:41Z", + "modified": "2025-05-22T15:34:37Z", "published": "2022-01-04T00:00:56Z", "aliases": [ "CVE-2021-30337" ], "details": "Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json index b61307d802a..165a1436dcb 100644 --- a/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json +++ b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-2cv3-9jp8-rgg3/GHSA-2cv3-9jp8-rgg3.json b/advisories/unreviewed/2022/09/GHSA-2cv3-9jp8-rgg3/GHSA-2cv3-9jp8-rgg3.json index 458891372f2..04175d44569 100644 --- a/advisories/unreviewed/2022/09/GHSA-2cv3-9jp8-rgg3/GHSA-2cv3-9jp8-rgg3.json +++ b/advisories/unreviewed/2022/09/GHSA-2cv3-9jp8-rgg3/GHSA-2cv3-9jp8-rgg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cv3-9jp8-rgg3", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-22T15:34:43Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3045" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1339648" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060077" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-37g6-48vw-mwpm/GHSA-37g6-48vw-mwpm.json b/advisories/unreviewed/2022/09/GHSA-37g6-48vw-mwpm/GHSA-37g6-48vw-mwpm.json index 586e634cb59..278c9c4e032 100644 --- a/advisories/unreviewed/2022/09/GHSA-37g6-48vw-mwpm/GHSA-37g6-48vw-mwpm.json +++ b/advisories/unreviewed/2022/09/GHSA-37g6-48vw-mwpm/GHSA-37g6-48vw-mwpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37g6-48vw-mwpm", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2855" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1345042" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060309" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-3gr5-mvfp-p295/GHSA-3gr5-mvfp-p295.json b/advisories/unreviewed/2022/09/GHSA-3gr5-mvfp-p295/GHSA-3gr5-mvfp-p295.json index 698029548c7..ebcdbc9524d 100644 --- a/advisories/unreviewed/2022/09/GHSA-3gr5-mvfp-p295/GHSA-3gr5-mvfp-p295.json +++ b/advisories/unreviewed/2022/09/GHSA-3gr5-mvfp-p295/GHSA-3gr5-mvfp-p295.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gr5-mvfp-p295", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2857" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1338135" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060030" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -34,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-4wg5-gh53-4jf5/GHSA-4wg5-gh53-4jf5.json b/advisories/unreviewed/2022/09/GHSA-4wg5-gh53-4jf5/GHSA-4wg5-gh53-4jf5.json index 47b701ef306..90ec1caecd0 100644 --- a/advisories/unreviewed/2022/09/GHSA-4wg5-gh53-4jf5/GHSA-4wg5-gh53-4jf5.json +++ b/advisories/unreviewed/2022/09/GHSA-4wg5-gh53-4jf5/GHSA-4wg5-gh53-4jf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wg5-gh53-4jf5", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3047" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1342586" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-602", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json b/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json index 12a210ff8d6..f5c0413b4d0 100644 --- a/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json +++ b/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-75mx-hh4q-h54x/GHSA-75mx-hh4q-h54x.json b/advisories/unreviewed/2022/09/GHSA-75mx-hh4q-h54x/GHSA-75mx-hh4q-h54x.json index e108e920385..0d75f398883 100644 --- a/advisories/unreviewed/2022/09/GHSA-75mx-hh4q-h54x/GHSA-75mx-hh4q-h54x.json +++ b/advisories/unreviewed/2022/09/GHSA-75mx-hh4q-h54x/GHSA-75mx-hh4q-h54x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75mx-hh4q-h54x", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2852" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1349322" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060468" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-7fvx-cw5x-7cm3/GHSA-7fvx-cw5x-7cm3.json b/advisories/unreviewed/2022/09/GHSA-7fvx-cw5x-7cm3/GHSA-7fvx-cw5x-7cm3.json index aa24b8b2f30..16cebd51157 100644 --- a/advisories/unreviewed/2022/09/GHSA-7fvx-cw5x-7cm3/GHSA-7fvx-cw5x-7cm3.json +++ b/advisories/unreviewed/2022/09/GHSA-7fvx-cw5x-7cm3/GHSA-7fvx-cw5x-7cm3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fvx-cw5x-7cm3", - "modified": "2022-09-29T00:00:21Z", + "modified": "2025-05-22T15:34:43Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-40784" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40784" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc" + }, { "type": "WEB", "url": "https://hackmd.io/@_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc" diff --git a/advisories/unreviewed/2022/09/GHSA-7jp8-whj2-j439/GHSA-7jp8-whj2-j439.json b/advisories/unreviewed/2022/09/GHSA-7jp8-whj2-j439/GHSA-7jp8-whj2-j439.json index 952ffc98246..5304e42a338 100644 --- a/advisories/unreviewed/2022/09/GHSA-7jp8-whj2-j439/GHSA-7jp8-whj2-j439.json +++ b/advisories/unreviewed/2022/09/GHSA-7jp8-whj2-j439/GHSA-7jp8-whj2-j439.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jp8-whj2-j439", - "modified": "2022-09-28T00:00:26Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3046" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1346245" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060350" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-8cf2-pgv8-hqvm/GHSA-8cf2-pgv8-hqvm.json b/advisories/unreviewed/2022/09/GHSA-8cf2-pgv8-hqvm/GHSA-8cf2-pgv8-hqvm.json index 8cabb996540..7d9290ad593 100644 --- a/advisories/unreviewed/2022/09/GHSA-8cf2-pgv8-hqvm/GHSA-8cf2-pgv8-hqvm.json +++ b/advisories/unreviewed/2022/09/GHSA-8cf2-pgv8-hqvm/GHSA-8cf2-pgv8-hqvm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-352" + "CWE-352", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json b/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json index 99020fe614f..71c50860f00 100644 --- a/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json +++ b/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json b/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json index 713b817616d..7c89639cf75 100644 --- a/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json +++ b/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-j9cg-v2v5-9p35/GHSA-j9cg-v2v5-9p35.json b/advisories/unreviewed/2022/09/GHSA-j9cg-v2v5-9p35/GHSA-j9cg-v2v5-9p35.json index 2b352531599..77ae489c604 100644 --- a/advisories/unreviewed/2022/09/GHSA-j9cg-v2v5-9p35/GHSA-j9cg-v2v5-9p35.json +++ b/advisories/unreviewed/2022/09/GHSA-j9cg-v2v5-9p35/GHSA-j9cg-v2v5-9p35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j9cg-v2v5-9p35", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-3044" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1051198" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40051481" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -38,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-693", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-m2pv-ff2q-qxxj/GHSA-m2pv-ff2q-qxxj.json b/advisories/unreviewed/2022/09/GHSA-m2pv-ff2q-qxxj/GHSA-m2pv-ff2q-qxxj.json index f300af6acf9..a3fdca7a095 100644 --- a/advisories/unreviewed/2022/09/GHSA-m2pv-ff2q-qxxj/GHSA-m2pv-ff2q-qxxj.json +++ b/advisories/unreviewed/2022/09/GHSA-m2pv-ff2q-qxxj/GHSA-m2pv-ff2q-qxxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2pv-ff2q-qxxj", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-22T15:34:43Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-3195" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1358381" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060728" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json index 0b79b230c0b..a32dc315387 100644 --- a/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json +++ b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json index 188d92009c8..547199766ff 100644 --- a/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json +++ b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-pjw5-9wfg-rq3v/GHSA-pjw5-9wfg-rq3v.json b/advisories/unreviewed/2022/09/GHSA-pjw5-9wfg-rq3v/GHSA-pjw5-9wfg-rq3v.json index 0c26ebc248b..53d99111952 100644 --- a/advisories/unreviewed/2022/09/GHSA-pjw5-9wfg-rq3v/GHSA-pjw5-9wfg-rq3v.json +++ b/advisories/unreviewed/2022/09/GHSA-pjw5-9wfg-rq3v/GHSA-pjw5-9wfg-rq3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjw5-9wfg-rq3v", - "modified": "2022-09-29T00:00:27Z", + "modified": "2025-05-22T15:34:41Z", "published": "2022-09-27T00:00:20Z", "aliases": [ "CVE-2022-40785" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40785" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc" + }, { "type": "WEB", "url": "https://hackmd.io/@_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-q869-52p3-m2g6/GHSA-q869-52p3-m2g6.json b/advisories/unreviewed/2022/09/GHSA-q869-52p3-m2g6/GHSA-q869-52p3-m2g6.json index 03fe2da7996..6958b739983 100644 --- a/advisories/unreviewed/2022/09/GHSA-q869-52p3-m2g6/GHSA-q869-52p3-m2g6.json +++ b/advisories/unreviewed/2022/09/GHSA-q869-52p3-m2g6/GHSA-q869-52p3-m2g6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q869-52p3-m2g6", - "modified": "2022-09-29T00:00:22Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2854" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://crbug.com/1337538" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" @@ -34,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json index 25b3bda173c..67d4cefeb4d 100644 --- a/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json +++ b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc73-wjpr-m8fj", - "modified": "2022-09-28T00:00:19Z", + "modified": "2025-05-22T15:34:39Z", "published": "2022-09-25T00:00:17Z", "aliases": [ "CVE-2022-32848" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json index 313daa0c462..ffe3863fef3 100644 --- a/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json +++ b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-xf3m-h4qp-mpv8/GHSA-xf3m-h4qp-mpv8.json b/advisories/unreviewed/2022/09/GHSA-xf3m-h4qp-mpv8/GHSA-xf3m-h4qp-mpv8.json index c80502c6538..eb154906807 100644 --- a/advisories/unreviewed/2022/09/GHSA-xf3m-h4qp-mpv8/GHSA-xf3m-h4qp-mpv8.json +++ b/advisories/unreviewed/2022/09/GHSA-xf3m-h4qp-mpv8/GHSA-xf3m-h4qp-mpv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xf3m-h4qp-mpv8", - "modified": "2022-10-01T00:00:22Z", + "modified": "2025-05-22T15:34:43Z", "published": "2022-09-28T00:00:16Z", "aliases": [ "CVE-2022-41604" diff --git a/advisories/unreviewed/2022/09/GHSA-xmjv-jv6c-x229/GHSA-xmjv-jv6c-x229.json b/advisories/unreviewed/2022/09/GHSA-xmjv-jv6c-x229/GHSA-xmjv-jv6c-x229.json index e423dd38af4..80273bc0cca 100644 --- a/advisories/unreviewed/2022/09/GHSA-xmjv-jv6c-x229/GHSA-xmjv-jv6c-x229.json +++ b/advisories/unreviewed/2022/09/GHSA-xmjv-jv6c-x229/GHSA-xmjv-jv6c-x229.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmjv-jv6c-x229", - "modified": "2022-09-29T00:00:23Z", + "modified": "2025-05-22T15:34:42Z", "published": "2022-09-27T00:00:19Z", "aliases": [ "CVE-2022-2853" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://crbug.com/1350097" }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060491" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE" diff --git a/advisories/unreviewed/2024/03/GHSA-6fvm-vq2v-pwgq/GHSA-6fvm-vq2v-pwgq.json b/advisories/unreviewed/2024/03/GHSA-6fvm-vq2v-pwgq/GHSA-6fvm-vq2v-pwgq.json index 1635ff2fd8c..b0cc65416fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-6fvm-vq2v-pwgq/GHSA-6fvm-vq2v-pwgq.json +++ b/advisories/unreviewed/2024/03/GHSA-6fvm-vq2v-pwgq/GHSA-6fvm-vq2v-pwgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fvm-vq2v-pwgq", - "modified": "2025-02-14T18:30:46Z", + "modified": "2025-05-22T15:34:43Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26618" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/dc7eb8755797ed41a0d1b5c0c39df3c8f401b3d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6421555dbd7cb3d4d70b69f33f998aaeca1e3b5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json index ac0ae4a5d14..96ddafe2905 100644 --- a/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json +++ b/advisories/unreviewed/2024/04/GHSA-2pv2-gg54-r8f4/GHSA-2pv2-gg54-r8f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pv2-gg54-r8f4", - "modified": "2025-03-18T18:30:41Z", + "modified": "2025-05-22T15:34:44Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26783" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/d6159bd4c00594249e305bfe02304c67c506264e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5ec1c24e71dbf144677a975d6ba91043c2193db" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json b/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json index 701a90eb584..720518e498c 100644 --- a/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json +++ b/advisories/unreviewed/2024/04/GHSA-8xc6-54p8-3p65/GHSA-8xc6-54p8-3p65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xc6-54p8-3p65", - "modified": "2025-03-28T00:31:27Z", + "modified": "2025-05-22T15:34:44Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26807" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/03f1573c9587029730ca68503f5062105b122f61" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c914aac9522f6e93822c18dff233d3e92399c81" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/32ce3bb57b6b402de2aec1012511e7ac4e7449dc" diff --git a/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json b/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json index 53f2140f08c..0137e56da96 100644 --- a/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json +++ b/advisories/unreviewed/2024/05/GHSA-xq4p-6j59-jfv4/GHSA-xq4p-6j59-jfv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq4p-6j59-jfv4", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-05-22T15:34:44Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2024-35790" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group\n\nThe DisplayPort driver's sysfs nodes may be present to the userspace before\ntypec_altmode_set_drvdata() completes in dp_altmode_probe. This means that\na sysfs read can trigger a NULL pointer error by deferencing dp->hpd in\nhpd_show or dp->lock in pin_assignment_show, as dev_get_drvdata() returns\nNULL in those cases.\n\nRemove manual sysfs node creation in favor of adding attribute group as\ndefault for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is\nnot used here otherwise the path to the sysfs nodes is no longer compliant\nwith the ABI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,11 +30,21 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/4a22aeac24d0d5f26ba741408e8b5a4be6dc5dc0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9794ffd9d0c39ee070fbd733f862bbe89b28ba33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1c5ddaef506e3517dce338c08a60663b1521920" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T13:15:58Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json b/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json index 1f785c569b7..5d4261d40c4 100644 --- a/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json +++ b/advisories/unreviewed/2024/08/GHSA-c6m8-29qv-7wq9/GHSA-c6m8-29qv-7wq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6m8-29qv-7wq9", - "modified": "2024-10-29T18:30:35Z", + "modified": "2025-05-22T15:34:45Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43840" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43840" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/077149478497b2f00ff4fd9da2c892defa6418d8" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/19d3c179a37730caf600a97fed3794feac2b197b" @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/6d218fcc707d6b2c3616b6cd24b948fd4825cfec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9664e6ff040798a46cdc5d401064f55b8676c83" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-v5h4-3gwf-6343/GHSA-v5h4-3gwf-6343.json b/advisories/unreviewed/2024/09/GHSA-v5h4-3gwf-6343/GHSA-v5h4-3gwf-6343.json index 40d949172bb..03098ebc73d 100644 --- a/advisories/unreviewed/2024/09/GHSA-v5h4-3gwf-6343/GHSA-v5h4-3gwf-6343.json +++ b/advisories/unreviewed/2024/09/GHSA-v5h4-3gwf-6343/GHSA-v5h4-3gwf-6343.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5h4-3gwf-6343", - "modified": "2024-09-30T15:30:44Z", + "modified": "2025-05-22T15:34:45Z", "published": "2024-09-18T09:30:36Z", "aliases": [ "CVE-2024-46751" @@ -19,10 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46751" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18eb53a2734ff61b9a72c4fef5db7b38cb48ae16" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/28cb13f29faf6290597b24b728dc3100c019356f" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cfec712a439c5c5f5c718c5c669ee41a898f776" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d64807ded1b6054f066e03d8add6d920f3db9e5d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ef9a8b73c8b60b27d9db4787e624a3438ffe8428" diff --git a/advisories/unreviewed/2024/10/GHSA-cvqv-vx57-8p4g/GHSA-cvqv-vx57-8p4g.json b/advisories/unreviewed/2024/10/GHSA-cvqv-vx57-8p4g/GHSA-cvqv-vx57-8p4g.json index b8e3d7547e2..9232ec634da 100644 --- a/advisories/unreviewed/2024/10/GHSA-cvqv-vx57-8p4g/GHSA-cvqv-vx57-8p4g.json +++ b/advisories/unreviewed/2024/10/GHSA-cvqv-vx57-8p4g/GHSA-cvqv-vx57-8p4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvqv-vx57-8p4g", - "modified": "2024-10-05T09:30:28Z", + "modified": "2025-05-22T15:34:45Z", "published": "2024-10-05T09:30:28Z", "aliases": [ "CVE-2024-8486" diff --git a/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json b/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json index 4c936beb631..7df1ffe3330 100644 --- a/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json +++ b/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w83r-gj25-6vrc", - "modified": "2024-11-19T18:30:54Z", + "modified": "2025-05-22T15:34:45Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50203" @@ -23,9 +23,17 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7db1a2121f3c7903b8e397392beec563c3d00950" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e80f366ebfdfafc685fe83a84c34f7ef01cbe88" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a552e2ef5fd1a6c78267cd4ec5a9b49aa11bbb1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f521c2a0c0c4585f36d912bf62c852b88682c4f2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json b/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json index 17d01c46073..57379cb07ef 100644 --- a/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json +++ b/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xh3-3533-7mmv", - "modified": "2025-01-06T21:30:50Z", + "modified": "2025-05-22T15:34:46Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56655" @@ -30,6 +30,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/b04df3da1b5c6f6dc7cdccc37941740c078c4043" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0f013bebf94fe7ae75e5a53be2f2bd1cc1841e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8d8f53e1858178882b881b8c09f94ef0e83bf76" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-gjq7-3xfx-fg78/GHSA-gjq7-3xfx-fg78.json b/advisories/unreviewed/2024/12/GHSA-gjq7-3xfx-fg78/GHSA-gjq7-3xfx-fg78.json index 8f847531ee8..bcfc7949412 100644 --- a/advisories/unreviewed/2024/12/GHSA-gjq7-3xfx-fg78/GHSA-gjq7-3xfx-fg78.json +++ b/advisories/unreviewed/2024/12/GHSA-gjq7-3xfx-fg78/GHSA-gjq7-3xfx-fg78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjq7-3xfx-fg78", - "modified": "2024-12-13T09:31:13Z", + "modified": "2025-05-22T15:34:45Z", "published": "2024-12-13T09:31:13Z", "aliases": [ "CVE-2024-12042" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json index e120efa7068..773310b9ed8 100644 --- a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json +++ b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2r5-qpjf-gcfc", - "modified": "2025-03-29T00:31:33Z", + "modified": "2025-05-22T15:34:46Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53209" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/84353386762a0a16dd444ead76c012e167d89b41" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7fd784d7c6a1bd927a23e0d06f09a776ee3889b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/bf54a7660fc8d2166f41ff1d67a643b15d8b2250" diff --git a/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json b/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json index a2cfc19125d..7660d7041b3 100644 --- a/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json +++ b/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q2w6-3cqh-h6qq", - "modified": "2025-04-25T12:30:26Z", + "modified": "2025-05-22T15:34:46Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53203" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/56971710cd541f2f05160a84b3183477d34a1be9" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e15fd96c0b701c53f9006bcc836eaeb35a05a023" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e44189455c62469eb91d383ce9103d54c1f807a3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e56aac6e5a25630645607b6856d4b2a17b2311a5" diff --git a/advisories/unreviewed/2025/01/GHSA-2phg-f479-57pq/GHSA-2phg-f479-57pq.json b/advisories/unreviewed/2025/01/GHSA-2phg-f479-57pq/GHSA-2phg-f479-57pq.json index 4633d5f5e09..2003a2025d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-2phg-f479-57pq/GHSA-2phg-f479-57pq.json +++ b/advisories/unreviewed/2025/01/GHSA-2phg-f479-57pq/GHSA-2phg-f479-57pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2phg-f479-57pq", - "modified": "2025-01-19T12:31:25Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-01-19T12:31:25Z", "aliases": [ "CVE-2025-21645" @@ -18,6 +18,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/5cc621085e2b7a9b1905a98f8e5a86bb4aea2016" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab47d72b736e78d3c2370b26e0bfc46eb0918391" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b25778c87a6bce40c31e92364f08aa6240309e25" diff --git a/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json b/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json index 407d1d3209e..45a8882e2a2 100644 --- a/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json +++ b/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-743f-m6p2-83h6", - "modified": "2025-01-21T15:31:03Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-01-21T15:31:03Z", "aliases": [ "CVE-2024-57945" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57945" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92f08673d3f1893191323572f60e3c62f2e57c2f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a4a7ac3d266008018f05fae53060fcb331151a14" diff --git a/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json b/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json index c089429d79c..01052d1249a 100644 --- a/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json +++ b/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54fp-2qhf-47h6", - "modified": "2025-02-27T21:32:13Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-02-27T21:32:13Z", "aliases": [ "CVE-2022-49168" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49168" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7170875083254b51fcc5d67f96640977083f481e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8cbc3001a3264d998d6b6db3e23f935c158abd4d" diff --git a/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json b/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json index 90801612818..0de61258784 100644 --- a/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json +++ b/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hrg-vg64-94qj", - "modified": "2025-02-27T21:32:10Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-02-27T21:32:10Z", "aliases": [ "CVE-2022-49063" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49063" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/618df75f2e30c7838a3e010ca32cd4893ec9fe33" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/d08d2fb6d99d82da1c63aba5c0d1c6f237e150f3" diff --git a/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json b/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json index a85475cdb49..3e408319f62 100644 --- a/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json +++ b/advisories/unreviewed/2025/04/GHSA-23cf-whmv-wf37/GHSA-23cf-whmv-wf37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23cf-whmv-wf37", - "modified": "2025-04-16T15:34:44Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-04-16T15:34:44Z", "aliases": [ "CVE-2025-22102" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/6749cf49eff7ce6dadcb603c5c8db70b28079a5d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0a736d9857cadd87ae48b151d787e28954ea831" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d22496de5049d9b8f5b6d8623682a56b3c3d7e18" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json b/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json index dc90f32916f..fdb55752fe1 100644 --- a/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json +++ b/advisories/unreviewed/2025/04/GHSA-2647-7h53-xfq5/GHSA-2647-7h53-xfq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2647-7h53-xfq5", - "modified": "2025-05-06T18:30:36Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-04-16T15:34:41Z", "aliases": [ "CVE-2025-22062" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/10206302af856791fbcc27a33ed3c3eb09b2793d" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/386507cb6fb7cdef598ddcb3f0fa37e6ca9e789d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65ccb2793da7401772a3ffe85355c831b313c59f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3598f53211ba1025485306de2733bdd241311a3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/d3d7675d77622f6ca1aae14c51f80027b36283f8" diff --git a/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json b/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json index b82ee4e0c04..216407e2b1b 100644 --- a/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json +++ b/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2g9-6hgr-7f52", - "modified": "2025-04-01T18:30:52Z", + "modified": "2025-05-22T15:34:46Z", "published": "2025-04-01T18:30:52Z", "aliases": [ "CVE-2025-21931" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21931" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3926b572fd073491bde13ec42ee08ac1b337bf4d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/576a2f4c437c19bec7d05d05b5990f178d2b0f40" @@ -22,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/629dfc6ba5431056701d4e44830f3409b989955a" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93df6da64b004f75d307ed08d3f0f1020280d339" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/af288a426c3e3552b62595c6138ec6371a17dbba" diff --git a/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json b/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json new file mode 100644 index 00000000000..7c024c81f7a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3p82-g7cx-7qrf/GHSA-3p82-g7cx-7qrf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p82-g7cx-7qrf", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-5078" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5078" + }, + { + "type": "WEB", + "url": "https://github.com/GeniusWang23/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581432" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x77-62h7-m5pj/GHSA-4x77-62h7-m5pj.json b/advisories/unreviewed/2025/05/GHSA-4x77-62h7-m5pj/GHSA-4x77-62h7-m5pj.json new file mode 100644 index 00000000000..2d5d0127065 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4x77-62h7-m5pj/GHSA-4x77-62h7-m5pj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x77-62h7-m5pj", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-0679" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0679" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2952536" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/514751" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json b/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json new file mode 100644 index 00000000000..b4729f81c06 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5c2w-vf3p-r6vw/GHSA-5c2w-vf3p-r6vw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c2w-vf3p-r6vw", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3940" + ], + "details": "Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3940" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1173" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5vj7-r55g-9xv7/GHSA-5vj7-r55g-9xv7.json b/advisories/unreviewed/2025/05/GHSA-5vj7-r55g-9xv7/GHSA-5vj7-r55g-9xv7.json index 04eef325562..b493c21c55e 100644 --- a/advisories/unreviewed/2025/05/GHSA-5vj7-r55g-9xv7/GHSA-5vj7-r55g-9xv7.json +++ b/advisories/unreviewed/2025/05/GHSA-5vj7-r55g-9xv7/GHSA-5vj7-r55g-9xv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vj7-r55g-9xv7", - "modified": "2025-05-20T18:30:56Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-20T18:30:56Z", "aliases": [ "CVE-2025-37957" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/e9b28bc65fd3a56755ba503258024608292b4ab1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec24e62a1dd3540ee696314422040180040c1e4a" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json b/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json new file mode 100644 index 00000000000..e5b1240d6a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-62cm-c2h4-rg2m/GHSA-62cm-c2h4-rg2m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62cm-c2h4-rg2m", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3942" + ], + "details": "Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3942" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + }, + { + "type": "WEB", + "url": "https://www.tridium.com/us/en/product-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-63jr-j347-v237/GHSA-63jr-j347-v237.json b/advisories/unreviewed/2025/05/GHSA-63jr-j347-v237/GHSA-63jr-j347-v237.json new file mode 100644 index 00000000000..6f1aa667b73 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-63jr-j347-v237/GHSA-63jr-j347-v237.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63jr-j347-v237", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2023-47466" + ], + "details": "TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47466" + }, + { + "type": "WEB", + "url": "https://github.com/taglib/taglib/issues/1163" + }, + { + "type": "WEB", + "url": "https://github.com/taglib/taglib/pull/1164" + }, + { + "type": "WEB", + "url": "https://github.com/taglib/taglib/commit/dfa33bec0806cbb45785accb8cc6c2048a7d40cf" + }, + { + "type": "WEB", + "url": "https://github.com/taglib/taglib/compare/v1.13.1...v2.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json b/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json new file mode 100644 index 00000000000..df928e83ecd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-662m-3r43-rvw4/GHSA-662m-3r43-rvw4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-662m-3r43-rvw4", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-32815" + ], + "details": "An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32815" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2025-32815" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json b/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json new file mode 100644 index 00000000000..0284170f079 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6hrx-7mgg-5cvp/GHSA-6hrx-7mgg-5cvp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hrx-7mgg-5cvp", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3939" + ], + "details": "Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3939" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6x78-fv59-ffxv/GHSA-6x78-fv59-ffxv.json b/advisories/unreviewed/2025/05/GHSA-6x78-fv59-ffxv/GHSA-6x78-fv59-ffxv.json new file mode 100644 index 00000000000..1637c0607f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6x78-fv59-ffxv/GHSA-6x78-fv59-ffxv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x78-fv59-ffxv", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-5076" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5076" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-9829d8aeaf006c1a3474f4cbcc27d3dd30b5e2053444fd36b805b785f65b2e3e.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309956" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309956" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581297" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rfw-87cg-pgwh/GHSA-7rfw-87cg-pgwh.json b/advisories/unreviewed/2025/05/GHSA-7rfw-87cg-pgwh/GHSA-7rfw-87cg-pgwh.json new file mode 100644 index 00000000000..d4c396a51cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7rfw-87cg-pgwh/GHSA-7rfw-87cg-pgwh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rfw-87cg-pgwh", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2024-12093" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12093" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2851261" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/507445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vx5-gmqw-3wfc/GHSA-7vx5-gmqw-3wfc.json b/advisories/unreviewed/2025/05/GHSA-7vx5-gmqw-3wfc/GHSA-7vx5-gmqw-3wfc.json new file mode 100644 index 00000000000..05d30b37b4d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vx5-gmqw-3wfc/GHSA-7vx5-gmqw-3wfc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vx5-gmqw-3wfc", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2024-54188" + ], + "details": "Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54188" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2024-54188" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-87v3-xghc-4m97/GHSA-87v3-xghc-4m97.json b/advisories/unreviewed/2025/05/GHSA-87v3-xghc-4m97/GHSA-87v3-xghc-4m97.json new file mode 100644 index 00000000000..47d14f1a851 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-87v3-xghc-4m97/GHSA-87v3-xghc-4m97.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87v3-xghc-4m97", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-5075" + ], + "details": "A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component DEBUG Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5075" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-5c08f30e4ae57f2e4b89fbe5a5d6c540e3c359e1e5b12a00d4a6257b1b9fc935.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309955" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309955" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json b/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json new file mode 100644 index 00000000000..221470ffce4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8xr7-6x2j-wgq9/GHSA-8xr7-6x2j-wgq9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xr7-6x2j-wgq9", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3944" + ], + "details": "Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3944" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9888-65w8-vw6m/GHSA-9888-65w8-vw6m.json b/advisories/unreviewed/2025/05/GHSA-9888-65w8-vw6m/GHSA-9888-65w8-vw6m.json new file mode 100644 index 00000000000..fbb700292b9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9888-65w8-vw6m/GHSA-9888-65w8-vw6m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9888-65w8-vw6m", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-32813" + ], + "details": "An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32813" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2025-32813" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json b/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json new file mode 100644 index 00000000000..c2907ddc325 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9h2c-gmfr-3w4c/GHSA-9h2c-gmfr-3w4c.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h2c-gmfr-3w4c", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-5077" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5077" + }, + { + "type": "WEB", + "url": "https://github.com/GeniusWang23/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581431" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9vrq-hh79-6v9m/GHSA-9vrq-hh79-6v9m.json b/advisories/unreviewed/2025/05/GHSA-9vrq-hh79-6v9m/GHSA-9vrq-hh79-6v9m.json new file mode 100644 index 00000000000..8af6a2653ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vrq-hh79-6v9m/GHSA-9vrq-hh79-6v9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vrq-hh79-6v9m", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-4979" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4979" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/524455" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crr3-cvh5-8wfr/GHSA-crr3-cvh5-8wfr.json b/advisories/unreviewed/2025/05/GHSA-crr3-cvh5-8wfr/GHSA-crr3-cvh5-8wfr.json new file mode 100644 index 00000000000..5f46d281458 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crr3-cvh5-8wfr/GHSA-crr3-cvh5-8wfr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crr3-cvh5-8wfr", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-2853" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2853" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/3015673" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/527218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json index e7dcecd4a85..2f9ac7d2a30 100644 --- a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json +++ b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f333-vhwv-jvmx", - "modified": "2025-05-19T18:30:41Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4919" @@ -34,6 +34,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-38" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-40" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-41" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json index 2aa4faf879c..b66d0d47567 100644 --- a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json +++ b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhgm-mxgh-gfpj", - "modified": "2025-05-21T18:33:26Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4918" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-38" }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-40" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-41" + }, { "type": "WEB", "url": "https://www.vicarius.io/vsociety/posts/cve-2025-4918-detect-firefox-out-of-bounds-write" diff --git a/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json b/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json new file mode 100644 index 00000000000..178baecd86f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g6rf-7www-ggmp/GHSA-g6rf-7www-ggmp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6rf-7www-ggmp", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-45471" + ], + "details": "Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45471" + }, + { + "type": "WEB", + "url": "https://github.com/lumigo-io/SAR-measure-cold-start/issues/32" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zolaer9527/549d5f466359829a3f1aaafebe7ecc3f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json b/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json new file mode 100644 index 00000000000..a715cd22186 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g8jq-rx5f-94q7/GHSA-g8jq-rx5f-94q7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8jq-rx5f-94q7", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3945" + ], + "details": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3945" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g93f-rhw4-8mj3/GHSA-g93f-rhw4-8mj3.json b/advisories/unreviewed/2025/05/GHSA-g93f-rhw4-8mj3/GHSA-g93f-rhw4-8mj3.json new file mode 100644 index 00000000000..2324b1a0fca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g93f-rhw4-8mj3/GHSA-g93f-rhw4-8mj3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g93f-rhw4-8mj3", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-0993" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0993" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2967771" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/516927" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json b/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json new file mode 100644 index 00000000000..fda6dc10feb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gfm6-h4jq-qp9r/GHSA-gfm6-h4jq-qp9r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfm6-h4jq-qp9r", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-32814" + ], + "details": "An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32814" + }, + { + "type": "WEB", + "url": "https://support.infoblox.com/s/article/Infoblox-NetMRI-is-vulnerable-to-CVE-2025-32814" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ggj2-v6c6-rgh4/GHSA-ggj2-v6c6-rgh4.json b/advisories/unreviewed/2025/05/GHSA-ggj2-v6c6-rgh4/GHSA-ggj2-v6c6-rgh4.json index a12829d678c..c045c6416f9 100644 --- a/advisories/unreviewed/2025/05/GHSA-ggj2-v6c6-rgh4/GHSA-ggj2-v6c6-rgh4.json +++ b/advisories/unreviewed/2025/05/GHSA-ggj2-v6c6-rgh4/GHSA-ggj2-v6c6-rgh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggj2-v6c6-rgh4", - "modified": "2025-05-20T18:30:57Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-20T18:30:57Z", "aliases": [ "CVE-2025-37968" @@ -18,6 +18,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/2c95c8f0959d0a72575eabf2ff888f47ed6d8b77" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ca84f6a22d50bf8b31efe9eb05f9859947266d7" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f063a28002e3350088b4577c5640882bf4ea17ea" diff --git a/advisories/unreviewed/2025/05/GHSA-gpxx-q8xc-r3mj/GHSA-gpxx-q8xc-r3mj.json b/advisories/unreviewed/2025/05/GHSA-gpxx-q8xc-r3mj/GHSA-gpxx-q8xc-r3mj.json new file mode 100644 index 00000000000..ee88494baa5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gpxx-q8xc-r3mj/GHSA-gpxx-q8xc-r3mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpxx-q8xc-r3mj", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-32915" + ], + "details": "Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32915" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h279-pjhh-9hgj/GHSA-h279-pjhh-9hgj.json b/advisories/unreviewed/2025/05/GHSA-h279-pjhh-9hgj/GHSA-h279-pjhh-9hgj.json index 65a3fdd32e1..9113fa02887 100644 --- a/advisories/unreviewed/2025/05/GHSA-h279-pjhh-9hgj/GHSA-h279-pjhh-9hgj.json +++ b/advisories/unreviewed/2025/05/GHSA-h279-pjhh-9hgj/GHSA-h279-pjhh-9hgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h279-pjhh-9hgj", - "modified": "2025-05-20T18:30:56Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-20T18:30:56Z", "aliases": [ "CVE-2025-37960" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37960" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bcd29181bab8d508d2adfdbb132de8b1e088698" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/aa513e69e011a2b19fa22ce62ce35effbd5e0c81" diff --git a/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json b/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json new file mode 100644 index 00000000000..a8fafbe2688 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hcrg-qr57-hr37/GHSA-hcrg-qr57-hr37.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcrg-qr57-hr37", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:48Z", + "aliases": [ + "CVE-2025-3938" + ], + "details": "Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3938" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-325" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hf3p-gpvx-q597/GHSA-hf3p-gpvx-q597.json b/advisories/unreviewed/2025/05/GHSA-hf3p-gpvx-q597/GHSA-hf3p-gpvx-q597.json new file mode 100644 index 00000000000..2f9908e58f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hf3p-gpvx-q597/GHSA-hf3p-gpvx-q597.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf3p-gpvx-q597", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-5024" + ], + "details": "A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5024" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5024" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2367717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json b/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json new file mode 100644 index 00000000000..54b746d2d0f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j46h-hw72-jxqh/GHSA-j46h-hw72-jxqh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j46h-hw72-jxqh", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3943" + ], + "details": "Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3943" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json b/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json new file mode 100644 index 00000000000..8bbedfd617c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqqw-x8w5-v4hh/GHSA-jqqw-x8w5-v4hh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqqw-x8w5-v4hh", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-1110" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1110" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2972576" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/517693" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json b/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json new file mode 100644 index 00000000000..aa13e5de952 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jr34-3463-3cxq/GHSA-jr34-3463-3cxq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr34-3463-3cxq", + "modified": "2025-05-22T15:34:48Z", + "published": "2025-05-22T15:34:48Z", + "aliases": [ + "CVE-2025-3937" + ], + "details": "Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3937" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-916" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json b/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json new file mode 100644 index 00000000000..b0a59b151a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mpm7-f6gv-ghwx/GHSA-mpm7-f6gv-ghwx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpm7-f6gv-ghwx", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-5079" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/updateorder.php. The manipulation of the argument remark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5079" + }, + { + "type": "WEB", + "url": "https://github.com/dico-Z/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.581439" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json b/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json new file mode 100644 index 00000000000..c31a0b7e22b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prr2-m2fh-3hv6/GHSA-prr2-m2fh-3hv6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prr2-m2fh-3hv6", + "modified": "2025-05-22T15:34:48Z", + "published": "2025-05-22T15:34:48Z", + "aliases": [ + "CVE-2025-3936" + ], + "details": "Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3936" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json b/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json new file mode 100644 index 00000000000..b5caf654f59 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q524-5rg8-2j6p/GHSA-q524-5rg8-2j6p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q524-5rg8-2j6p", + "modified": "2025-05-22T15:34:49Z", + "published": "2025-05-22T15:34:49Z", + "aliases": [ + "CVE-2025-3941" + ], + "details": "Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3941" + }, + { + "type": "WEB", + "url": "https://docs.niagara-community.com/category/tech_bull" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-69" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r3m4-8xwf-9fpp/GHSA-r3m4-8xwf-9fpp.json b/advisories/unreviewed/2025/05/GHSA-r3m4-8xwf-9fpp/GHSA-r3m4-8xwf-9fpp.json new file mode 100644 index 00000000000..1832d251073 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r3m4-8xwf-9fpp/GHSA-r3m4-8xwf-9fpp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3m4-8xwf-9fpp", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-3111" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3111" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/3045424" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/533313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r873-27qv-5m3w/GHSA-r873-27qv-5m3w.json b/advisories/unreviewed/2025/05/GHSA-r873-27qv-5m3w/GHSA-r873-27qv-5m3w.json new file mode 100644 index 00000000000..14c5fca2090 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r873-27qv-5m3w/GHSA-r873-27qv-5m3w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r873-27qv-5m3w", + "modified": "2025-05-22T15:34:48Z", + "published": "2025-05-22T15:34:48Z", + "aliases": [ + "CVE-2025-2272" + ], + "details": "Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2272" + }, + { + "type": "WEB", + "url": "https://support.forcepoint.com/s/article/Security-Advisory-Privilege-Escalation-and-Arbitrary-code-execution-in-F1E-Endpoint" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json b/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json new file mode 100644 index 00000000000..e9e65666152 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8qh-5c5w-48pp/GHSA-v8qh-5c5w-48pp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8qh-5c5w-48pp", + "modified": "2025-05-22T15:34:50Z", + "published": "2025-05-22T15:34:50Z", + "aliases": [ + "CVE-2025-4575" + ], + "details": "Issue summary: Use of -addreject option with the openssl x509 application adds\na trusted use instead of a rejected use for a certificate.\n\nImpact summary: If a user intends to make a trusted certificate rejected for\na particular use it will be instead marked as trusted for that use.\n\nA copy & paste error during minor refactoring of the code introduced this\nissue in the OpenSSL 3.5 version. If, for example, a trusted CA certificate\nshould be trusted only for the purpose of authenticating TLS servers but not\nfor CMS signature verification and the CMS signature verification is intended\nto be marked as rejected with the -addreject option, the resulting CA\ncertificate will be trusted for CMS signature verification purpose instead.\n\nOnly users which use the trusted certificate format who use the openssl x509\ncommand line application to add rejected uses are affected by this issue.\nThe issues affecting only the command line application are considered to\nbe Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue.\n\nOpenSSL 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are also not affected by this\nissue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4575" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/e96d22446e633d117e6c9904cb15b4693e956eaa" + }, + { + "type": "WEB", + "url": "https://openssl-library.org/news/secadv/20250522.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T14:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json b/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json new file mode 100644 index 00000000000..25de93fe345 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v9g5-36x8-7xmx/GHSA-v9g5-36x8-7xmx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9g5-36x8-7xmx", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-0605" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0605" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2919391" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/514204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json b/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json index 3467f95bae5..dd3b0e95159 100644 --- a/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json +++ b/advisories/unreviewed/2025/05/GHSA-vj38-xwp2-x5gc/GHSA-vj38-xwp2-x5gc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vj38-xwp2-x5gc", - "modified": "2025-05-21T21:31:41Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-21T21:31:41Z", "aliases": [ "CVE-2025-44040" ], "details": "An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via the UserService.php and the checkFOrOldHash function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T21:16:03Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json b/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json index 3cbc01a4575..8eedf492a71 100644 --- a/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json +++ b/advisories/unreviewed/2025/05/GHSA-vppg-gg96-53c9/GHSA-vppg-gg96-53c9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vppg-gg96-53c9", - "modified": "2025-05-22T06:30:24Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-22T06:30:24Z", "aliases": [ "CVE-2025-4133" ], "details": "The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-22T06:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w939-6x76-94vc/GHSA-w939-6x76-94vc.json b/advisories/unreviewed/2025/05/GHSA-w939-6x76-94vc/GHSA-w939-6x76-94vc.json index b2831bcfd89..d9b3f932c27 100644 --- a/advisories/unreviewed/2025/05/GHSA-w939-6x76-94vc/GHSA-w939-6x76-94vc.json +++ b/advisories/unreviewed/2025/05/GHSA-w939-6x76-94vc/GHSA-w939-6x76-94vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w939-6x76-94vc", - "modified": "2025-05-20T18:30:57Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-20T18:30:57Z", "aliases": [ "CVE-2025-37967" @@ -18,9 +18,25 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/364618c89d4c57c85e5fc51a2446cd939bf57802" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5924b324468845fc795bd76f588f51d7ab4f202d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/61fc1a8e1e10cc784cab5829930838aaf1d37af5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/962ce9028ca6eb450d5c205238a3ee27de9d214d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f32451ca4cb7dc53f2a0e2e66b84d34162747eb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4bd982563c2fd41ec9ca6c517c392d759db801c" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-xgvh-xrwg-wg4p/GHSA-xgvh-xrwg-wg4p.json b/advisories/unreviewed/2025/05/GHSA-xgvh-xrwg-wg4p/GHSA-xgvh-xrwg-wg4p.json new file mode 100644 index 00000000000..1dfa06a5238 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xgvh-xrwg-wg4p/GHSA-xgvh-xrwg-wg4p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgvh-xrwg-wg4p", + "modified": "2025-05-22T15:34:51Z", + "published": "2025-05-22T15:34:51Z", + "aliases": [ + "CVE-2025-5080" + ], + "details": "A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5080" + }, + { + "type": "WEB", + "url": "https://github.com/xubeining/Cve_report/blob/main/Shenzhen%20Jixiang%20Tengda%20Technology%20Co.%2C%20Ltd.%20FH451%20has%20a%20Remote%20Code%20Execution%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.582059" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-22T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json b/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json index a0f8e56bc4f..5ac4db14b52 100644 --- a/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json +++ b/advisories/unreviewed/2025/05/GHSA-xwrv-8p5w-52hj/GHSA-xwrv-8p5w-52hj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwrv-8p5w-52hj", - "modified": "2025-05-21T21:31:41Z", + "modified": "2025-05-22T15:34:48Z", "published": "2025-05-21T21:31:41Z", "aliases": [ "CVE-2025-45753" ], "details": "A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-21T21:16:03Z"