From 89bbcbbae8156b728f665cf25d426362e48522e9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Feb 2025 00:33:35 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-h379-w93w-2822.json | 4 +- .../GHSA-7h6w-cw39-chrh.json | 1 + .../GHSA-8xpm-gr22-c94j.json | 3 +- .../GHSA-cw8j-9ggg-f37g.json | 3 +- .../GHSA-fp26-r9x4-5gw4.json | 15 +++++-- .../GHSA-3w7r-v4fr-r43w.json | 6 ++- .../GHSA-75gg-px33-62vq.json | 6 ++- .../GHSA-cggf-qwgw-w7pq.json | 3 +- .../GHSA-fc9r-7hhq-7wqj.json | 11 +++-- .../GHSA-r88j-hwqm-286v.json | 6 ++- .../GHSA-22qj-6c22-mwj2.json | 15 +++++-- .../GHSA-4mr4-7v9j-jvf7.json | 44 +++++++++++++++++++ .../GHSA-6ggq-69xw-3g87.json | 15 +++++-- .../GHSA-6h98-c266-q7cr.json | 36 +++++++++++++++ .../GHSA-6vpc-jmr8-rh6f.json | 29 ++++++++++++ .../GHSA-6wpf-j472-fr56.json | 40 +++++++++++++++++ .../GHSA-72px-4jm6-9942.json | 29 ++++++++++++ .../GHSA-7vx3-5mq4-mccg.json | 40 +++++++++++++++++ .../GHSA-7wpm-58fr-6p69.json | 15 +++++-- .../GHSA-7xf9-6rpx-2c4r.json | 35 +++++++++++++++ .../GHSA-99fv-v434-wh6f.json | 33 ++++++++++++++ .../GHSA-9mx7-6mvp-m4h2.json | 44 +++++++++++++++++++ .../GHSA-9r56-r7r5-55vj.json | 15 +++++-- .../GHSA-cwqg-xrj3-rv38.json | 6 ++- .../GHSA-fwf2-5x9w-mqc9.json | 36 +++++++++++++++ .../GHSA-g42f-c6cx-89cg.json | 36 +++++++++++++++ .../GHSA-h2rf-rp8h-fq2p.json | 36 +++++++++++++++ .../GHSA-h8pj-rh9p-5jjx.json | 29 ++++++++++++ .../GHSA-hmq6-3hm7-3h78.json | 33 ++++++++++++++ .../GHSA-mp93-634q-pm27.json | 40 +++++++++++++++++ .../GHSA-prq3-r4gw-34vp.json | 29 ++++++++++++ .../GHSA-pvg7-v23v-r848.json | 44 +++++++++++++++++++ .../GHSA-pw24-vxq6-ghrm.json | 33 ++++++++++++++ .../GHSA-qh26-pvc5-g99h.json | 29 ++++++++++++ .../GHSA-r5jh-73fq-2vv9.json | 29 ++++++++++++ .../GHSA-r7wq-w97f-v622.json | 40 +++++++++++++++++ .../GHSA-rfr5-8xxx-p68v.json | 15 +++++-- .../GHSA-rgg5-26hx-fph3.json | 36 +++++++++++++++ .../GHSA-x27f-ggf7-mf74.json | 40 +++++++++++++++++ .../GHSA-x682-hgrr-h4qw.json | 36 +++++++++++++++ .../GHSA-xg2h-7cxj-3gvh.json | 29 ++++++++++++ 41 files changed, 989 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-4mr4-7v9j-jvf7/GHSA-4mr4-7v9j-jvf7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6h98-c266-q7cr/GHSA-6h98-c266-q7cr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6wpf-j472-fr56/GHSA-6wpf-j472-fr56.json create mode 100644 advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7vx3-5mq4-mccg/GHSA-7vx3-5mq4-mccg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9mx7-6mvp-m4h2/GHSA-9mx7-6mvp-m4h2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fwf2-5x9w-mqc9/GHSA-fwf2-5x9w-mqc9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g42f-c6cx-89cg/GHSA-g42f-c6cx-89cg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h2rf-rp8h-fq2p/GHSA-h2rf-rp8h-fq2p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mp93-634q-pm27/GHSA-mp93-634q-pm27.json create mode 100644 advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pvg7-v23v-r848/GHSA-pvg7-v23v-r848.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r7wq-w97f-v622/GHSA-r7wq-w97f-v622.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rgg5-26hx-fph3/GHSA-rgg5-26hx-fph3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x27f-ggf7-mf74/GHSA-x27f-ggf7-mf74.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x682-hgrr-h4qw/GHSA-x682-hgrr-h4qw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json diff --git a/advisories/unreviewed/2024/03/GHSA-h379-w93w-2822/GHSA-h379-w93w-2822.json b/advisories/unreviewed/2024/03/GHSA-h379-w93w-2822/GHSA-h379-w93w-2822.json index b4bf33b5775..fe94751109f 100644 --- a/advisories/unreviewed/2024/03/GHSA-h379-w93w-2822/GHSA-h379-w93w-2822.json +++ b/advisories/unreviewed/2024/03/GHSA-h379-w93w-2822/GHSA-h379-w93w-2822.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7h6w-cw39-chrh/GHSA-7h6w-cw39-chrh.json b/advisories/unreviewed/2024/05/GHSA-7h6w-cw39-chrh/GHSA-7h6w-cw39-chrh.json index c0457798f98..abaa93f0e04 100644 --- a/advisories/unreviewed/2024/05/GHSA-7h6w-cw39-chrh/GHSA-7h6w-cw39-chrh.json +++ b/advisories/unreviewed/2024/05/GHSA-7h6w-cw39-chrh/GHSA-7h6w-cw39-chrh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-8xpm-gr22-c94j/GHSA-8xpm-gr22-c94j.json b/advisories/unreviewed/2024/05/GHSA-8xpm-gr22-c94j/GHSA-8xpm-gr22-c94j.json index 31a764e93bd..0285041ca1b 100644 --- a/advisories/unreviewed/2024/05/GHSA-8xpm-gr22-c94j/GHSA-8xpm-gr22-c94j.json +++ b/advisories/unreviewed/2024/05/GHSA-8xpm-gr22-c94j/GHSA-8xpm-gr22-c94j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cw8j-9ggg-f37g/GHSA-cw8j-9ggg-f37g.json b/advisories/unreviewed/2024/05/GHSA-cw8j-9ggg-f37g/GHSA-cw8j-9ggg-f37g.json index 4ebe9f27f9d..ba966057539 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw8j-9ggg-f37g/GHSA-cw8j-9ggg-f37g.json +++ b/advisories/unreviewed/2024/05/GHSA-cw8j-9ggg-f37g/GHSA-cw8j-9ggg-f37g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-fp26-r9x4-5gw4/GHSA-fp26-r9x4-5gw4.json b/advisories/unreviewed/2024/05/GHSA-fp26-r9x4-5gw4/GHSA-fp26-r9x4-5gw4.json index 430998d5356..00fc7999892 100644 --- a/advisories/unreviewed/2024/05/GHSA-fp26-r9x4-5gw4/GHSA-fp26-r9x4-5gw4.json +++ b/advisories/unreviewed/2024/05/GHSA-fp26-r9x4-5gw4/GHSA-fp26-r9x4-5gw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fp26-r9x4-5gw4", - "modified": "2024-05-14T15:32:53Z", + "modified": "2025-02-12T00:32:11Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-28277" ], "details": "In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:14:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json index dea0b752068..311d3cf987e 100644 --- a/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json +++ b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w7r-v4fr-r43w", - "modified": "2024-08-13T18:31:15Z", + "modified": "2025-02-12T00:32:13Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31356" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json b/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json index f4707b34862..fbba0217074 100644 --- a/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json +++ b/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75gg-px33-62vq", - "modified": "2025-01-10T15:31:34Z", + "modified": "2025-02-12T00:32:14Z", "published": "2025-01-10T15:31:34Z", "aliases": [ "CVE-2024-57686" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Land%20record/Reflected%20Cross%20Site%20Scripting.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/lhRaMk7/notebook/blob/main/phar_rce" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-cggf-qwgw-w7pq/GHSA-cggf-qwgw-w7pq.json b/advisories/unreviewed/2025/01/GHSA-cggf-qwgw-w7pq/GHSA-cggf-qwgw-w7pq.json index 8eed8cae52e..9ceef8dec92 100644 --- a/advisories/unreviewed/2025/01/GHSA-cggf-qwgw-w7pq/GHSA-cggf-qwgw-w7pq.json +++ b/advisories/unreviewed/2025/01/GHSA-cggf-qwgw-w7pq/GHSA-cggf-qwgw-w7pq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-fc9r-7hhq-7wqj/GHSA-fc9r-7hhq-7wqj.json b/advisories/unreviewed/2025/01/GHSA-fc9r-7hhq-7wqj/GHSA-fc9r-7hhq-7wqj.json index 4ab4a82ad53..f834c36768f 100644 --- a/advisories/unreviewed/2025/01/GHSA-fc9r-7hhq-7wqj/GHSA-fc9r-7hhq-7wqj.json +++ b/advisories/unreviewed/2025/01/GHSA-fc9r-7hhq-7wqj/GHSA-fc9r-7hhq-7wqj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fc9r-7hhq-7wqj", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-02-12T00:32:13Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22389" ], "details": "An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When accessed by application users, these files can be used to execute malicious actions or compromise users' systems.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r88j-hwqm-286v/GHSA-r88j-hwqm-286v.json b/advisories/unreviewed/2025/01/GHSA-r88j-hwqm-286v/GHSA-r88j-hwqm-286v.json index 178e299f73c..807f0c006c3 100644 --- a/advisories/unreviewed/2025/01/GHSA-r88j-hwqm-286v/GHSA-r88j-hwqm-286v.json +++ b/advisories/unreviewed/2025/01/GHSA-r88j-hwqm-286v/GHSA-r88j-hwqm-286v.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r88j-hwqm-286v", - "modified": "2025-01-14T00:30:46Z", + "modified": "2025-02-12T00:32:14Z", "published": "2025-01-14T00:30:46Z", "aliases": [ "CVE-2024-11128" ], "details": "A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by the absence of Hardened Runtime or Library Validation signing. This issue affects Bitdefender Virus Scanner versions before 3.18.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/02/GHSA-22qj-6c22-mwj2/GHSA-22qj-6c22-mwj2.json b/advisories/unreviewed/2025/02/GHSA-22qj-6c22-mwj2/GHSA-22qj-6c22-mwj2.json index 9f15dbbae26..53517fa8389 100644 --- a/advisories/unreviewed/2025/02/GHSA-22qj-6c22-mwj2/GHSA-22qj-6c22-mwj2.json +++ b/advisories/unreviewed/2025/02/GHSA-22qj-6c22-mwj2/GHSA-22qj-6c22-mwj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-22qj-6c22-mwj2", - "modified": "2025-02-06T21:32:09Z", + "modified": "2025-02-12T00:32:15Z", "published": "2025-02-06T21:32:09Z", "aliases": [ "CVE-2024-57426" ], "details": "NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T20:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4mr4-7v9j-jvf7/GHSA-4mr4-7v9j-jvf7.json b/advisories/unreviewed/2025/02/GHSA-4mr4-7v9j-jvf7/GHSA-4mr4-7v9j-jvf7.json new file mode 100644 index 00000000000..38b8eaf766b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4mr4-7v9j-jvf7/GHSA-4mr4-7v9j-jvf7.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mr4-7v9j-jvf7", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-31342" + ], + "details": "Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31342" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6ggq-69xw-3g87/GHSA-6ggq-69xw-3g87.json b/advisories/unreviewed/2025/02/GHSA-6ggq-69xw-3g87/GHSA-6ggq-69xw-3g87.json index 3ec8603fef7..d6a77bf23c7 100644 --- a/advisories/unreviewed/2025/02/GHSA-6ggq-69xw-3g87/GHSA-6ggq-69xw-3g87.json +++ b/advisories/unreviewed/2025/02/GHSA-6ggq-69xw-3g87/GHSA-6ggq-69xw-3g87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6ggq-69xw-3g87", - "modified": "2025-02-06T21:32:09Z", + "modified": "2025-02-12T00:32:15Z", "published": "2025-02-06T21:32:09Z", "aliases": [ "CVE-2025-23093" ], "details": "The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T20:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6h98-c266-q7cr/GHSA-6h98-c266-q7cr.json b/advisories/unreviewed/2025/02/GHSA-6h98-c266-q7cr/GHSA-6h98-c266-q7cr.json new file mode 100644 index 00000000000..36727ae83bc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6h98-c266-q7cr/GHSA-6h98-c266-q7cr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h98-c266-q7cr", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-21971" + ], + "details": "Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an operating system crash, potentially leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21971" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6008.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json b/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json new file mode 100644 index 00000000000..10d19ac8641 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vpc-jmr8-rh6f", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-57241" + ], + "details": "Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57241" + }, + { + "type": "WEB", + "url": "https://github.com/woshidaheike/dedecms-url-redirection" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6wpf-j472-fr56/GHSA-6wpf-j472-fr56.json b/advisories/unreviewed/2025/02/GHSA-6wpf-j472-fr56/GHSA-6wpf-j472-fr56.json new file mode 100644 index 00000000000..9fa992d57c6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6wpf-j472-fr56/GHSA-6wpf-j472-fr56.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wpf-j472-fr56", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-31331" + ], + "details": "Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31331" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json b/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json new file mode 100644 index 00000000000..e9dfb41f414 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72px-4jm6-9942", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-54772" + ], + "details": "An issue was discovered in the Winbox service of MikroTik RouterOS v6.43 through v7.16.1. A discrepancy in response times between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54772" + }, + { + "type": "WEB", + "url": "https://github.com/deauther890/CVE-2024-54772" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7vx3-5mq4-mccg/GHSA-7vx3-5mq4-mccg.json b/advisories/unreviewed/2025/02/GHSA-7vx3-5mq4-mccg/GHSA-7vx3-5mq4-mccg.json new file mode 100644 index 00000000000..a2704fceb4e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7vx3-5mq4-mccg/GHSA-7vx3-5mq4-mccg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vx3-5mq4-mccg", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-20582" + ], + "details": "Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest memory integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20582" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json b/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json index 8f2a1a545dd..d62536fea08 100644 --- a/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json +++ b/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wpm-58fr-6p69", - "modified": "2025-02-06T21:32:09Z", + "modified": "2025-02-12T00:32:15Z", "published": "2025-02-06T21:32:09Z", "aliases": [ "CVE-2025-22936" ], "details": "An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T20:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json b/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json new file mode 100644 index 00000000000..f68a46cf114 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xf9-6rpx-2c4r", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2022-3180" + ], + "details": "The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3180" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgateway/wpgateway-35-unauthenticated-privilege-escalation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json new file mode 100644 index 00000000000..56fb08f35b0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99fv-v434-wh6f", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-54916" + ], + "details": "An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54916" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1knf8-_fFUSLd3ZmbEpy0_OVzSN1UR1JR/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/SAHALLL/CVE-2024-54916" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9mx7-6mvp-m4h2/GHSA-9mx7-6mvp-m4h2.json b/advisories/unreviewed/2025/02/GHSA-9mx7-6mvp-m4h2/GHSA-9mx7-6mvp-m4h2.json new file mode 100644 index 00000000000..ef0fada490c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9mx7-6mvp-m4h2/GHSA-9mx7-6mvp-m4h2.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mx7-6mvp-m4h2", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-31343" + ], + "details": "Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31343" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json b/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json index 5029e490234..64258b9a7f0 100644 --- a/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json +++ b/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r56-r7r5-55vj", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-12T00:32:15Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-54909" ], "details": "A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cwqg-xrj3-rv38/GHSA-cwqg-xrj3-rv38.json b/advisories/unreviewed/2025/02/GHSA-cwqg-xrj3-rv38/GHSA-cwqg-xrj3-rv38.json index fae758172f8..0da434b6bc3 100644 --- a/advisories/unreviewed/2025/02/GHSA-cwqg-xrj3-rv38/GHSA-cwqg-xrj3-rv38.json +++ b/advisories/unreviewed/2025/02/GHSA-cwqg-xrj3-rv38/GHSA-cwqg-xrj3-rv38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwqg-xrj3-rv38", - "modified": "2025-02-11T09:30:33Z", + "modified": "2025-02-12T00:32:16Z", "published": "2025-02-11T09:30:33Z", "aliases": [ "CVE-2024-52612" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2025-1_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/cve-2024-52612" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-fwf2-5x9w-mqc9/GHSA-fwf2-5x9w-mqc9.json b/advisories/unreviewed/2025/02/GHSA-fwf2-5x9w-mqc9/GHSA-fwf2-5x9w-mqc9.json new file mode 100644 index 00000000000..c3390c6cd5c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fwf2-5x9w-mqc9/GHSA-fwf2-5x9w-mqc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwf2-5x9w-mqc9", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-0112" + ], + "details": "NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain permissions to a limited degree. A successful exploit of this vulnerability might lead to code execution, denial of service, data corruption, information disclosure, or escalation of privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0112" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5611" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g42f-c6cx-89cg/GHSA-g42f-c6cx-89cg.json b/advisories/unreviewed/2025/02/GHSA-g42f-c6cx-89cg/GHSA-g42f-c6cx-89cg.json new file mode 100644 index 00000000000..576e2396516 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g42f-c6cx-89cg/GHSA-g42f-c6cx-89cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g42f-c6cx-89cg", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2025-1240" + ], + "details": "WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of 7Z files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24986.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1240" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h2rf-rp8h-fq2p/GHSA-h2rf-rp8h-fq2p.json b/advisories/unreviewed/2025/02/GHSA-h2rf-rp8h-fq2p/GHSA-h2rf-rp8h-fq2p.json new file mode 100644 index 00000000000..3ff79eeb6e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h2rf-rp8h-fq2p/GHSA-h2rf-rp8h-fq2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2rf-rp8h-fq2p", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-0142" + ], + "details": "NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to code execution and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0142" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json b/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json new file mode 100644 index 00000000000..c50d428feb0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8pj-rh9p-5jjx", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-55212" + ], + "details": "DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55212" + }, + { + "type": "WEB", + "url": "https://www.invokesec.com/2025/01/13/a-real-world-example-of-blind-sqli" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json b/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json new file mode 100644 index 00000000000..8c877270b7f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmq6-3hm7-3h78", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2022-37660" + ], + "details": "In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37660" + }, + { + "type": "WEB", + "url": "https://link.springer.com/article/10.1007/s10207-025-00988-3" + }, + { + "type": "WEB", + "url": "https://w1.fi/cgit/hostap/commit/?id=15af83cf1846870873a011ed4d714732f01cd2e4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mp93-634q-pm27/GHSA-mp93-634q-pm27.json b/advisories/unreviewed/2025/02/GHSA-mp93-634q-pm27/GHSA-mp93-634q-pm27.json new file mode 100644 index 00000000000..24bd834e2b1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mp93-634q-pm27/GHSA-mp93-634q-pm27.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp93-634q-pm27", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-20581" + ], + "details": "Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss of guest memory integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20581" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json b/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json new file mode 100644 index 00000000000..da7135c4950 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prq3-r4gw-34vp", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-51324" + ], + "details": "An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51324" + }, + { + "type": "WEB", + "url": "https://github.com/magicsword-io/LOLDrivers/issues/204" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pvg7-v23v-r848/GHSA-pvg7-v23v-r848.json b/advisories/unreviewed/2025/02/GHSA-pvg7-v23v-r848/GHSA-pvg7-v23v-r848.json new file mode 100644 index 00000000000..fa162bfd60a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pvg7-v23v-r848/GHSA-pvg7-v23v-r848.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvg7-v23v-r848", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2023-31345" + ], + "details": "Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31345" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json new file mode 100644 index 00000000000..e24c0255ef1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw24-vxq6-ghrm", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-33469" + ], + "details": "An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33469" + }, + { + "type": "WEB", + "url": "https://github.com/blackbeard666/security-research/tree/main/CVE-2024-33469" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/981c1cb3-d1e7-4f5c-8a24-155662d33787" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json b/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json new file mode 100644 index 00000000000..bc2f50c4275 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh26-pvc5-g99h", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-44336" + ], + "details": "An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save it into publicly available storage.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44336" + }, + { + "type": "WEB", + "url": "https://github.com/blackbeard666/security-research/tree/main/CVE-2024-44336" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json b/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json new file mode 100644 index 00000000000..d4c07aabcd8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5jh-73fq-2vv9", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2024-57777" + ], + "details": "Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57777" + }, + { + "type": "WEB", + "url": "https://github.com/ffay/lanproxy/issues/192" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r7wq-w97f-v622/GHSA-r7wq-w97f-v622.json b/advisories/unreviewed/2025/02/GHSA-r7wq-w97f-v622/GHSA-r7wq-w97f-v622.json new file mode 100644 index 00000000000..61beb4fee0e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r7wq-w97f-v622/GHSA-r7wq-w97f-v622.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7wq-w97f-v622", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-20515" + ], + "details": "Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20515" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rfr5-8xxx-p68v/GHSA-rfr5-8xxx-p68v.json b/advisories/unreviewed/2025/02/GHSA-rfr5-8xxx-p68v/GHSA-rfr5-8xxx-p68v.json index 2753a801f36..3469a17a340 100644 --- a/advisories/unreviewed/2025/02/GHSA-rfr5-8xxx-p68v/GHSA-rfr5-8xxx-p68v.json +++ b/advisories/unreviewed/2025/02/GHSA-rfr5-8xxx-p68v/GHSA-rfr5-8xxx-p68v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rfr5-8xxx-p68v", - "modified": "2025-02-06T21:32:10Z", + "modified": "2025-02-12T00:32:15Z", "published": "2025-02-06T21:32:10Z", "aliases": [ "CVE-2025-23094" ], "details": "The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the same privilege level as the web access process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T21:15:23Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rgg5-26hx-fph3/GHSA-rgg5-26hx-fph3.json b/advisories/unreviewed/2025/02/GHSA-rgg5-26hx-fph3/GHSA-rgg5-26hx-fph3.json new file mode 100644 index 00000000000..1ef8bbab6d9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rgg5-26hx-fph3/GHSA-rgg5-26hx-fph3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgg5-26hx-fph3", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2023-20508" + ], + "details": "Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20508" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6008.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x27f-ggf7-mf74/GHSA-x27f-ggf7-mf74.json b/advisories/unreviewed/2025/02/GHSA-x27f-ggf7-mf74/GHSA-x27f-ggf7-mf74.json new file mode 100644 index 00000000000..44e1da3a631 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x27f-ggf7-mf74/GHSA-x27f-ggf7-mf74.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x27f-ggf7-mf74", + "modified": "2025-02-12T00:32:16Z", + "published": "2025-02-12T00:32:16Z", + "aliases": [ + "CVE-2023-31352" + ], + "details": "A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31352" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3009.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x682-hgrr-h4qw/GHSA-x682-hgrr-h4qw.json b/advisories/unreviewed/2025/02/GHSA-x682-hgrr-h4qw/GHSA-x682-hgrr-h4qw.json new file mode 100644 index 00000000000..c27df1f0bed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x682-hgrr-h4qw/GHSA-x682-hgrr-h4qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x682-hgrr-h4qw", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2020-3432" + ], + "details": "A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem.\n The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file. If the file is a critical systems file, the exploit could lead to a denial of service condition. To exploit this vulnerability, the attacker would need to have valid credentials on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3432" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-mac-dos-36s2y3Lv" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json b/advisories/unreviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json new file mode 100644 index 00000000000..9ae36ed8e50 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg2h-7cxj-3gvh", + "modified": "2025-02-12T00:32:17Z", + "published": "2025-02-12T00:32:17Z", + "aliases": [ + "CVE-2024-57000" + ], + "details": "An issue in Anyscale Inc Ray between v.2.9.3 and v.2.40.0 allows a remote attacker to execute arbitrary code via a crafted script.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57000" + }, + { + "type": "WEB", + "url": "https://github.com/honysyang/Ray.git" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T23:15:09Z" + } +} \ No newline at end of file