diff --git a/advisories/unreviewed/2025/03/GHSA-cfm9-vqrr-p3x8/GHSA-cfm9-vqrr-p3x8.json b/advisories/unreviewed/2025/03/GHSA-cfm9-vqrr-p3x8/GHSA-cfm9-vqrr-p3x8.json new file mode 100644 index 00000000000..64001f0cfff --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cfm9-vqrr-p3x8/GHSA-cfm9-vqrr-p3x8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfm9-vqrr-p3x8", + "modified": "2025-03-24T12:30:29Z", + "published": "2025-03-24T12:30:29Z", + "aliases": [ + "CVE-2025-2702" + ], + "details": "A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd.ashx. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2702" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/THNlcnBf/RCE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmqg-7x7f-3xhr/GHSA-jmqg-7x7f-3xhr.json b/advisories/unreviewed/2025/03/GHSA-jmqg-7x7f-3xhr/GHSA-jmqg-7x7f-3xhr.json new file mode 100644 index 00000000000..f7b9eac8a76 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmqg-7x7f-3xhr/GHSA-jmqg-7x7f-3xhr.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmqg-7x7f-3xhr", + "modified": "2025-03-24T12:30:29Z", + "published": "2025-03-24T12:30:29Z", + "aliases": [ + "CVE-2025-0835" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0835" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pff8-m8jx-77fj/GHSA-pff8-m8jx-77fj.json b/advisories/unreviewed/2025/03/GHSA-pff8-m8jx-77fj/GHSA-pff8-m8jx-77fj.json new file mode 100644 index 00000000000..59f77451c23 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pff8-m8jx-77fj/GHSA-pff8-m8jx-77fj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pff8-m8jx-77fj", + "modified": "2025-03-24T12:30:29Z", + "published": "2025-03-24T12:30:29Z", + "aliases": [ + "CVE-2025-0478" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages.\n\nUnder certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform, altering their behaviour.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0478" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T12:15:13Z" + } +} \ No newline at end of file