Publish Advisories

GHSA-cfm9-vqrr-p3x8
GHSA-jmqg-7x7f-3xhr
GHSA-pff8-m8jx-77fj
This commit is contained in:
advisory-database[bot]
2025-03-24 12:32:39 +00:00
parent 4d161ed903
commit 874883d2b9
3 changed files with 114 additions and 0 deletions
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfm9-vqrr-p3x8",
"modified": "2025-03-24T12:30:29Z",
"published": "2025-03-24T12:30:29Z",
"aliases": [
"CVE-2025-2702"
],
"details": "A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd.ashx. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2702"
},
{
"type": "WEB",
"url": "https://github.com/Rain1er/report/blob/main/THNlcnBf/RCE_1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300719"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300719"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.516289"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-24T10:15:12Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jmqg-7x7f-3xhr",
"modified": "2025-03-24T12:30:29Z",
"published": "2025-03-24T12:30:29Z",
"aliases": [
"CVE-2025-0835"
],
"details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0835"
},
{
"type": "WEB",
"url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-24T12:15:13Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pff8-m8jx-77fj",
"modified": "2025-03-24T12:30:29Z",
"published": "2025-03-24T12:30:29Z",
"aliases": [
"CVE-2025-0478"
],
"details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages.\n\nUnder certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform, altering their behaviour.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0478"
},
{
"type": "WEB",
"url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-280"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-24T12:15:13Z"
}
}