diff --git a/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json b/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json index 735745d18a6..5e3d719ec85 100644 --- a/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json +++ b/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w47-3vvr-m9hm", - "modified": "2022-04-30T00:02:23Z", + "modified": "2025-01-28T18:30:52Z", "published": "2022-04-30T00:02:23Z", "aliases": [ "CVE-2017-5030" diff --git a/advisories/unreviewed/2022/05/GHSA-453q-q3mp-9cq4/GHSA-453q-q3mp-9cq4.json b/advisories/unreviewed/2022/05/GHSA-453q-q3mp-9cq4/GHSA-453q-q3mp-9cq4.json index 37f375eff6d..87130d26740 100644 --- a/advisories/unreviewed/2022/05/GHSA-453q-q3mp-9cq4/GHSA-453q-q3mp-9cq4.json +++ b/advisories/unreviewed/2022/05/GHSA-453q-q3mp-9cq4/GHSA-453q-q3mp-9cq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-453q-q3mp-9cq4", - "modified": "2022-05-14T02:19:45Z", + "modified": "2025-01-28T18:30:53Z", "published": "2022-05-14T02:19:45Z", "aliases": [ "CVE-2017-7494" diff --git a/advisories/unreviewed/2022/05/GHSA-964h-jjmp-xf6h/GHSA-964h-jjmp-xf6h.json b/advisories/unreviewed/2022/05/GHSA-964h-jjmp-xf6h/GHSA-964h-jjmp-xf6h.json index 5b414130d5a..c82dba08891 100644 --- a/advisories/unreviewed/2022/05/GHSA-964h-jjmp-xf6h/GHSA-964h-jjmp-xf6h.json +++ b/advisories/unreviewed/2022/05/GHSA-964h-jjmp-xf6h/GHSA-964h-jjmp-xf6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-964h-jjmp-xf6h", - "modified": "2022-05-24T17:47:14Z", + "modified": "2025-01-28T18:30:53Z", "published": "2022-05-24T17:47:14Z", "aliases": [ "CVE-2021-21731" ], "details": "A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the data. This affects: ZXCLOUD iRAI All versions up to KVM-ProductV6.03.04", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-rfrg-rcwf-93m5/GHSA-rfrg-rcwf-93m5.json b/advisories/unreviewed/2022/05/GHSA-rfrg-rcwf-93m5/GHSA-rfrg-rcwf-93m5.json index 0ec79f3e620..dd411a5f2d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfrg-rcwf-93m5/GHSA-rfrg-rcwf-93m5.json +++ b/advisories/unreviewed/2022/05/GHSA-rfrg-rcwf-93m5/GHSA-rfrg-rcwf-93m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfrg-rcwf-93m5", - "modified": "2022-05-14T01:09:51Z", + "modified": "2025-01-28T18:30:51Z", "published": "2022-05-14T01:09:51Z", "aliases": [ "CVE-2016-1555" diff --git a/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json b/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json index 02682f2f575..b56ddf8c7cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json +++ b/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v6j9-wwcx-4984", - "modified": "2022-05-13T01:28:19Z", + "modified": "2025-01-28T18:30:52Z", "published": "2022-05-13T01:28:19Z", "aliases": [ "CVE-2017-5689" diff --git a/advisories/unreviewed/2022/05/GHSA-xjjj-92c2-q84f/GHSA-xjjj-92c2-q84f.json b/advisories/unreviewed/2022/05/GHSA-xjjj-92c2-q84f/GHSA-xjjj-92c2-q84f.json index 5feb05ec8a2..d46cb4d8a64 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjjj-92c2-q84f/GHSA-xjjj-92c2-q84f.json +++ b/advisories/unreviewed/2022/05/GHSA-xjjj-92c2-q84f/GHSA-xjjj-92c2-q84f.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-p6jp-vhc2-xhh9/GHSA-p6jp-vhc2-xhh9.json b/advisories/unreviewed/2023/02/GHSA-p6jp-vhc2-xhh9/GHSA-p6jp-vhc2-xhh9.json index 1ec9f4628a4..26b861f8ebd 100644 --- a/advisories/unreviewed/2023/02/GHSA-p6jp-vhc2-xhh9/GHSA-p6jp-vhc2-xhh9.json +++ b/advisories/unreviewed/2023/02/GHSA-p6jp-vhc2-xhh9/GHSA-p6jp-vhc2-xhh9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-6q7w-3rwf-fh47/GHSA-6q7w-3rwf-fh47.json b/advisories/unreviewed/2023/05/GHSA-6q7w-3rwf-fh47/GHSA-6q7w-3rwf-fh47.json index 208fc608f35..9f030d18d9b 100644 --- a/advisories/unreviewed/2023/05/GHSA-6q7w-3rwf-fh47/GHSA-6q7w-3rwf-fh47.json +++ b/advisories/unreviewed/2023/05/GHSA-6q7w-3rwf-fh47/GHSA-6q7w-3rwf-fh47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q7w-3rwf-fh47", - "modified": "2023-11-01T15:33:29Z", + "modified": "2025-01-28T18:31:19Z", "published": "2023-05-10T06:30:28Z", "aliases": [ "CVE-2023-32570" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://code.videolan.org/videolan/dav1d/-/tags/1.2.0" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXZ6CUNJFDJLCFOZHY2TIGMCAEITLCRP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B" diff --git a/advisories/unreviewed/2023/05/GHSA-pmq5-34w8-5c92/GHSA-pmq5-34w8-5c92.json b/advisories/unreviewed/2023/05/GHSA-pmq5-34w8-5c92/GHSA-pmq5-34w8-5c92.json index ca239d3a47e..62ee65b08f9 100644 --- a/advisories/unreviewed/2023/05/GHSA-pmq5-34w8-5c92/GHSA-pmq5-34w8-5c92.json +++ b/advisories/unreviewed/2023/05/GHSA-pmq5-34w8-5c92/GHSA-pmq5-34w8-5c92.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json b/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json index df1851bfc81..932e44fe873 100644 --- a/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json +++ b/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v972-h57q-v8pw", - "modified": "2024-02-11T06:30:25Z", + "modified": "2025-01-28T18:31:20Z", "published": "2023-05-16T00:30:17Z", "aliases": [ "CVE-2023-2700" diff --git a/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json b/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json index f1ac883ac55..badd11dcbe6 100644 --- a/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json +++ b/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23h8-4q9g-xc4f", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23131" diff --git a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json index 5353556e3e5..acdade719de 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json +++ b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rqc-6cwc-8fr7", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T03:30:36Z", "aliases": [ "CVE-2024-23127" diff --git a/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json b/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json index 635e261f0f3..adfe733fe9d 100644 --- a/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json +++ b/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-533q-6g64-xmc7", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23129" diff --git a/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json b/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json index 5ae83adf390..442cbb3e26e 100644 --- a/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json +++ b/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-783m-f4c2-pgqr", - "modified": "2024-02-22T15:30:39Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T15:30:39Z", "aliases": [ "CVE-2024-1563" ], "details": "An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T15:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json b/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json index dbd3201ac03..4ef566d0df4 100644 --- a/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json +++ b/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr4j-vgg6-426q", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23130" diff --git a/advisories/unreviewed/2024/02/GHSA-gjq6-76gc-q75p/GHSA-gjq6-76gc-q75p.json b/advisories/unreviewed/2024/02/GHSA-gjq6-76gc-q75p/GHSA-gjq6-76gc-q75p.json index 25b8e5e27d1..a9ccdeb0d52 100644 --- a/advisories/unreviewed/2024/02/GHSA-gjq6-76gc-q75p/GHSA-gjq6-76gc-q75p.json +++ b/advisories/unreviewed/2024/02/GHSA-gjq6-76gc-q75p/GHSA-gjq6-76gc-q75p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjq6-76gc-q75p", - "modified": "2024-02-23T12:30:31Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-23T12:30:31Z", "aliases": [ "CVE-2024-1590" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json index 373a8fda17d..f7ffa8f6914 100644 --- a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json +++ b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9rx-4p5p-q33x", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-01-28T18:31:20Z", "published": "2024-02-22T00:31:01Z", "aliases": [ "CVE-2024-0446" diff --git a/advisories/unreviewed/2024/02/GHSA-vq79-hxjc-77c4/GHSA-vq79-hxjc-77c4.json b/advisories/unreviewed/2024/02/GHSA-vq79-hxjc-77c4/GHSA-vq79-hxjc-77c4.json index 510c7848358..df4294603ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-vq79-hxjc-77c4/GHSA-vq79-hxjc-77c4.json +++ b/advisories/unreviewed/2024/02/GHSA-vq79-hxjc-77c4/GHSA-vq79-hxjc-77c4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6pw4-99gp-9gj7/GHSA-6pw4-99gp-9gj7.json b/advisories/unreviewed/2024/03/GHSA-6pw4-99gp-9gj7/GHSA-6pw4-99gp-9gj7.json index ae5667ac8c1..abf3f76be19 100644 --- a/advisories/unreviewed/2024/03/GHSA-6pw4-99gp-9gj7/GHSA-6pw4-99gp-9gj7.json +++ b/advisories/unreviewed/2024/03/GHSA-6pw4-99gp-9gj7/GHSA-6pw4-99gp-9gj7.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json index 88adeacf96f..6c8b608af7c 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json +++ b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pm9h-cgmx-g7vq/GHSA-pm9h-cgmx-g7vq.json b/advisories/unreviewed/2024/04/GHSA-pm9h-cgmx-g7vq/GHSA-pm9h-cgmx-g7vq.json index da37a601df8..d490d6b86c5 100644 --- a/advisories/unreviewed/2024/04/GHSA-pm9h-cgmx-g7vq/GHSA-pm9h-cgmx-g7vq.json +++ b/advisories/unreviewed/2024/04/GHSA-pm9h-cgmx-g7vq/GHSA-pm9h-cgmx-g7vq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json b/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json index 8b8808841fb..67448a7beb0 100644 --- a/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json +++ b/advisories/unreviewed/2024/04/GHSA-w6xp-gc2w-28hx/GHSA-w6xp-gc2w-28hx.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5qp4-g8f2-222m/GHSA-5qp4-g8f2-222m.json b/advisories/unreviewed/2024/05/GHSA-5qp4-g8f2-222m/GHSA-5qp4-g8f2-222m.json index 2ebf195ff67..3d8bf59754e 100644 --- a/advisories/unreviewed/2024/05/GHSA-5qp4-g8f2-222m/GHSA-5qp4-g8f2-222m.json +++ b/advisories/unreviewed/2024/05/GHSA-5qp4-g8f2-222m/GHSA-5qp4-g8f2-222m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-gf9p-76p3-4hqw/GHSA-gf9p-76p3-4hqw.json b/advisories/unreviewed/2024/05/GHSA-gf9p-76p3-4hqw/GHSA-gf9p-76p3-4hqw.json index 9aa7e5895fc..b2293076c2b 100644 --- a/advisories/unreviewed/2024/05/GHSA-gf9p-76p3-4hqw/GHSA-gf9p-76p3-4hqw.json +++ b/advisories/unreviewed/2024/05/GHSA-gf9p-76p3-4hqw/GHSA-gf9p-76p3-4hqw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gqvv-5f2f-89ff/GHSA-gqvv-5f2f-89ff.json b/advisories/unreviewed/2024/05/GHSA-gqvv-5f2f-89ff/GHSA-gqvv-5f2f-89ff.json index d6c933d4982..9385c3656b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-gqvv-5f2f-89ff/GHSA-gqvv-5f2f-89ff.json +++ b/advisories/unreviewed/2024/05/GHSA-gqvv-5f2f-89ff/GHSA-gqvv-5f2f-89ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqvv-5f2f-89ff", - "modified": "2024-05-16T12:30:22Z", + "modified": "2025-01-28T18:31:22Z", "published": "2024-05-16T12:30:22Z", "aliases": [ "CVE-2024-4288" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hc52-2x79-qjwh/GHSA-hc52-2x79-qjwh.json b/advisories/unreviewed/2024/05/GHSA-hc52-2x79-qjwh/GHSA-hc52-2x79-qjwh.json index 6eff36652b9..7df14d05b1c 100644 --- a/advisories/unreviewed/2024/05/GHSA-hc52-2x79-qjwh/GHSA-hc52-2x79-qjwh.json +++ b/advisories/unreviewed/2024/05/GHSA-hc52-2x79-qjwh/GHSA-hc52-2x79-qjwh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m47f-2rm6-hhj4/GHSA-m47f-2rm6-hhj4.json b/advisories/unreviewed/2024/05/GHSA-m47f-2rm6-hhj4/GHSA-m47f-2rm6-hhj4.json index e7b9797b526..c593b31343b 100644 --- a/advisories/unreviewed/2024/05/GHSA-m47f-2rm6-hhj4/GHSA-m47f-2rm6-hhj4.json +++ b/advisories/unreviewed/2024/05/GHSA-m47f-2rm6-hhj4/GHSA-m47f-2rm6-hhj4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json b/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json index aa93e1e30f2..a16613cddf8 100644 --- a/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json +++ b/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122", "CWE-295" ], diff --git a/advisories/unreviewed/2024/05/GHSA-mmh4-cvwv-5vmm/GHSA-mmh4-cvwv-5vmm.json b/advisories/unreviewed/2024/05/GHSA-mmh4-cvwv-5vmm/GHSA-mmh4-cvwv-5vmm.json index 348749dea36..a0b9e984882 100644 --- a/advisories/unreviewed/2024/05/GHSA-mmh4-cvwv-5vmm/GHSA-mmh4-cvwv-5vmm.json +++ b/advisories/unreviewed/2024/05/GHSA-mmh4-cvwv-5vmm/GHSA-mmh4-cvwv-5vmm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-203" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-r45f-4gg8-w8cc/GHSA-r45f-4gg8-w8cc.json b/advisories/unreviewed/2024/05/GHSA-r45f-4gg8-w8cc/GHSA-r45f-4gg8-w8cc.json index e6d476f8800..f80a1ff358a 100644 --- a/advisories/unreviewed/2024/05/GHSA-r45f-4gg8-w8cc/GHSA-r45f-4gg8-w8cc.json +++ b/advisories/unreviewed/2024/05/GHSA-r45f-4gg8-w8cc/GHSA-r45f-4gg8-w8cc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json index 50f79d7ec95..5c2c9374c0f 100644 --- a/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json +++ b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-r6w5-xcrq-hc6g/GHSA-r6w5-xcrq-hc6g.json b/advisories/unreviewed/2024/10/GHSA-r6w5-xcrq-hc6g/GHSA-r6w5-xcrq-hc6g.json index f71ef00d417..d68839a3927 100644 --- a/advisories/unreviewed/2024/10/GHSA-r6w5-xcrq-hc6g/GHSA-r6w5-xcrq-hc6g.json +++ b/advisories/unreviewed/2024/10/GHSA-r6w5-xcrq-hc6g/GHSA-r6w5-xcrq-hc6g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json b/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json index 217e0c9b862..79539198da7 100644 --- a/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json +++ b/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25gv-4h88-97v2", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54520" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json b/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json index ca3fea67e88..de01c0229b5 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json +++ b/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gv2-58w9-6q94", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24149" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to disclosure of user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json b/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json index 94e844cd4d7..0b1cb714d80 100644 --- a/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json +++ b/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2mcv-q3q8-h36j", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24139" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json index f7deddeb599..52cd2e4f0a1 100644 --- a/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json +++ b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2w2w-c8f9-2jq3", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24109" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-32pm-63j6-22qc/GHSA-32pm-63j6-22qc.json b/advisories/unreviewed/2025/01/GHSA-32pm-63j6-22qc/GHSA-32pm-63j6-22qc.json index 8183dad6ef1..050d1cb6e39 100644 --- a/advisories/unreviewed/2025/01/GHSA-32pm-63j6-22qc/GHSA-32pm-63j6-22qc.json +++ b/advisories/unreviewed/2025/01/GHSA-32pm-63j6-22qc/GHSA-32pm-63j6-22qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-32pm-63j6-22qc", - "modified": "2025-01-28T03:31:13Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T03:31:13Z", "aliases": [ "CVE-2022-3365" ], "details": "Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-327" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T01:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-37v4-cwgp-x353/GHSA-37v4-cwgp-x353.json b/advisories/unreviewed/2025/01/GHSA-37v4-cwgp-x353/GHSA-37v4-cwgp-x353.json index 2fc365e5b03..e1b9c530394 100644 --- a/advisories/unreviewed/2025/01/GHSA-37v4-cwgp-x353/GHSA-37v4-cwgp-x353.json +++ b/advisories/unreviewed/2025/01/GHSA-37v4-cwgp-x353/GHSA-37v4-cwgp-x353.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json b/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json index 73a39e157ca..16ea0ced210 100644 --- a/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json +++ b/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3cjj-grfr-qr35", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24122" ], "details": "A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3f6r-qh9c-x6mm/GHSA-3f6r-qh9c-x6mm.json b/advisories/unreviewed/2025/01/GHSA-3f6r-qh9c-x6mm/GHSA-3f6r-qh9c-x6mm.json index 15edfe98f58..4d6b054103c 100644 --- a/advisories/unreviewed/2025/01/GHSA-3f6r-qh9c-x6mm/GHSA-3f6r-qh9c-x6mm.json +++ b/advisories/unreviewed/2025/01/GHSA-3f6r-qh9c-x6mm/GHSA-3f6r-qh9c-x6mm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3f6r-qh9c-x6mm", - "modified": "2025-01-28T03:31:14Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T03:31:14Z", "aliases": [ "CVE-2024-45341" ], "details": "A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T02:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json b/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json index 5cb2dfb7f5d..2b7981a2de5 100644 --- a/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json +++ b/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vgp-qmq6-gqh6", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54468" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json index 435a7e07ad9..8edfcec6ab0 100644 --- a/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json +++ b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-429g-77c6-6p2v", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24174" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json index b7e336177e7..de209afc596 100644 --- a/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json +++ b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48xq-vmgv-hxqw", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24158" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json b/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json index b8bd30df7c2..d54efee02f8 100644 --- a/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json +++ b/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4grh-x943-5h7q", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24123" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4pc8-mg94-p837/GHSA-4pc8-mg94-p837.json b/advisories/unreviewed/2025/01/GHSA-4pc8-mg94-p837/GHSA-4pc8-mg94-p837.json index 955ef84beab..7178b44a666 100644 --- a/advisories/unreviewed/2025/01/GHSA-4pc8-mg94-p837/GHSA-4pc8-mg94-p837.json +++ b/advisories/unreviewed/2025/01/GHSA-4pc8-mg94-p837/GHSA-4pc8-mg94-p837.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4pc8-mg94-p837", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-50665" ], "details": "gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json b/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json new file mode 100644 index 00000000000..d2bc3e69c08 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-555q-7wq3-w6ch", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-0781" + ], + "details": "An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0781" + }, + { + "type": "WEB", + "url": "https://gitlab.com/flightgear/flightgear/-/commit/ad37afce28083fad7f79467b3ffdead753584358" + }, + { + "type": "WEB", + "url": "https://gitlab.com/flightgear/flightgear/-/issues/3025" + }, + { + "type": "WEB", + "url": "https://gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-58fx-7v9q-3g56/GHSA-58fx-7v9q-3g56.json b/advisories/unreviewed/2025/01/GHSA-58fx-7v9q-3g56/GHSA-58fx-7v9q-3g56.json new file mode 100644 index 00000000000..fb43e80673e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-58fx-7v9q-3g56/GHSA-58fx-7v9q-3g56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58fx-7v9q-3g56", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2024-13484" + ], + "details": "A flaw was found in ArgoCD. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13484" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-13484" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2269376" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json index e7e91274f82..927e8b2f39f 100644 --- a/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json +++ b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5g74-fw23-w3jp", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54550" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An app may be able to view autocompleted contact information from Messages and Mail in system logs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json b/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json index 64c24fe08d5..9517655016e 100644 --- a/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json +++ b/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5p4f-8x2w-47pr", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24176" ], "details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json b/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json index 324d14db5c3..ec2a258f7bc 100644 --- a/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json +++ b/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5r86-xcpg-678m", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54499" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json b/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json index f025a20279b..0e380cc7d02 100644 --- a/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json +++ b/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-634j-pq2q-xq7j", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54537" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to read and write files outside of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json b/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json index 08341e3dfcf..1db035c0a25 100644 --- a/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json +++ b/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6jw8-gwr2-hm7v", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24115" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read files outside of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json b/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json index f040d3825e9..aedb3aeb493 100644 --- a/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json +++ b/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v56-83j9-4gmj", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24138" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious application may be able to leak sensitive user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json b/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json index 999398da5a8..3f1321f92fd 100644 --- a/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json +++ b/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7h23-57pg-3hwc", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24085" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json b/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json index ae78979e02b..a3a2c89c20d 100644 --- a/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json +++ b/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hx3-pw88-4928", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24163" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json index a41a2e39045..e92e2052681 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json +++ b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jj7-mxgf-79rv", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24162" ], "details": "This issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7wrw-r4p8-38rx/GHSA-7wrw-r4p8-38rx.json b/advisories/unreviewed/2025/01/GHSA-7wrw-r4p8-38rx/GHSA-7wrw-r4p8-38rx.json index 00fd63b1e28..71ce2e07135 100644 --- a/advisories/unreviewed/2025/01/GHSA-7wrw-r4p8-38rx/GHSA-7wrw-r4p8-38rx.json +++ b/advisories/unreviewed/2025/01/GHSA-7wrw-r4p8-38rx/GHSA-7wrw-r4p8-38rx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wrw-r4p8-38rx", - "modified": "2025-01-28T03:31:14Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T03:31:14Z", "aliases": [ "CVE-2024-45336" ], "details": "The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T02:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json b/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json index ac29c5e3ee9..496025bf5e5 100644 --- a/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json +++ b/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96fg-3259-537g", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24118" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-98qx-rgjq-qp7m/GHSA-98qx-rgjq-qp7m.json b/advisories/unreviewed/2025/01/GHSA-98qx-rgjq-qp7m/GHSA-98qx-rgjq-qp7m.json index 7892a89eae1..2e67bab3bba 100644 --- a/advisories/unreviewed/2025/01/GHSA-98qx-rgjq-qp7m/GHSA-98qx-rgjq-qp7m.json +++ b/advisories/unreviewed/2025/01/GHSA-98qx-rgjq-qp7m/GHSA-98qx-rgjq-qp7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98qx-rgjq-qp7m", - "modified": "2025-01-28T06:30:40Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T06:30:40Z", "aliases": [ "CVE-2024-12807" ], "details": "The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T06:15:31Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9qpp-c5wx-j99g/GHSA-9qpp-c5wx-j99g.json b/advisories/unreviewed/2025/01/GHSA-9qpp-c5wx-j99g/GHSA-9qpp-c5wx-j99g.json index d2e0a2e4544..dff64dbd52a 100644 --- a/advisories/unreviewed/2025/01/GHSA-9qpp-c5wx-j99g/GHSA-9qpp-c5wx-j99g.json +++ b/advisories/unreviewed/2025/01/GHSA-9qpp-c5wx-j99g/GHSA-9qpp-c5wx-j99g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9qpp-c5wx-j99g", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2023-46401" ], "details": "KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1236" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cf7w-246v-3mp8/GHSA-cf7w-246v-3mp8.json b/advisories/unreviewed/2025/01/GHSA-cf7w-246v-3mp8/GHSA-cf7w-246v-3mp8.json index a45a9265e87..950f1fe4613 100644 --- a/advisories/unreviewed/2025/01/GHSA-cf7w-246v-3mp8/GHSA-cf7w-246v-3mp8.json +++ b/advisories/unreviewed/2025/01/GHSA-cf7w-246v-3mp8/GHSA-cf7w-246v-3mp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cf7w-246v-3mp8", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-55194" ], "details": "OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json index a14544a4866..ca574ee390d 100644 --- a/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json +++ b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chv5-gcx2-vw99", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54475" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to determine a user’s current location.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json b/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json index e2eb4670dcd..a68107b0aa5 100644 --- a/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json +++ b/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj6v-hrvw-6rqm", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54547" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json b/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json index c34a9e2d394..d4ac7151252 100644 --- a/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json +++ b/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjpm-qgq4-2252", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24092" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cqc8-8583-c382/GHSA-cqc8-8583-c382.json b/advisories/unreviewed/2025/01/GHSA-cqc8-8583-c382/GHSA-cqc8-8583-c382.json new file mode 100644 index 00000000000..3e2a113cda5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cqc8-8583-c382/GHSA-cqc8-8583-c382.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc8-8583-c382", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-23053" + ], + "details": "A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23053" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json b/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json index e84e883e309..f2287b068ce 100644 --- a/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json +++ b/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f725-67x4-3v5h", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24124" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fg8c-8f5r-r5m9/GHSA-fg8c-8f5r-r5m9.json b/advisories/unreviewed/2025/01/GHSA-fg8c-8f5r-r5m9/GHSA-fg8c-8f5r-r5m9.json new file mode 100644 index 00000000000..eb8be49e1d3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fg8c-8f5r-r5m9/GHSA-fg8c-8f5r-r5m9.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg8c-8f5r-r5m9", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-23054" + ], + "details": "A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23054" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json b/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json index 02ff6f85e9a..7414e59f286 100644 --- a/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json +++ b/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h45h-fpr9-hqvw", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24135" ], "details": "This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json b/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json index 615f7492406..d68739db9da 100644 --- a/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json +++ b/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hrpq-69mg-72v6", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54530" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, visionOS 2.2, iOS 18.2 and iPadOS 18.2. Password autofill may fill in passwords after failing authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hx7v-449x-8wpm/GHSA-hx7v-449x-8wpm.json b/advisories/unreviewed/2025/01/GHSA-hx7v-449x-8wpm/GHSA-hx7v-449x-8wpm.json new file mode 100644 index 00000000000..cd7276025a3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hx7v-449x-8wpm/GHSA-hx7v-449x-8wpm.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx7v-449x-8wpm", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-23055" + ], + "details": "A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23055" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json index 209546dca98..359412ef4d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json +++ b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhf5-fj8j-2h29", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24108" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json b/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json new file mode 100644 index 00000000000..791dfd0af67 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jrx3-7w53-466r/GHSA-jrx3-7w53-466r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrx3-7w53-466r", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2017-13317" + ], + "details": "In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13317" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json b/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json index b4e57fc2082..fef002b6b90 100644 --- a/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json +++ b/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4rq-mf69-pwg7", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-50664" ], "details": "gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m9gq-w7jg-mrwv/GHSA-m9gq-w7jg-mrwv.json b/advisories/unreviewed/2025/01/GHSA-m9gq-w7jg-mrwv/GHSA-m9gq-w7jg-mrwv.json new file mode 100644 index 00000000000..df0304ad984 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m9gq-w7jg-mrwv/GHSA-m9gq-w7jg-mrwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gq-w7jg-mrwv", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-23385" + ], + "details": "In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23385" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-114" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mcv5-jrjw-4vgm/GHSA-mcv5-jrjw-4vgm.json b/advisories/unreviewed/2025/01/GHSA-mcv5-jrjw-4vgm/GHSA-mcv5-jrjw-4vgm.json index 46c1d14862d..1331363dcc5 100644 --- a/advisories/unreviewed/2025/01/GHSA-mcv5-jrjw-4vgm/GHSA-mcv5-jrjw-4vgm.json +++ b/advisories/unreviewed/2025/01/GHSA-mcv5-jrjw-4vgm/GHSA-mcv5-jrjw-4vgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mcv5-jrjw-4vgm", - "modified": "2025-01-28T06:30:40Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T06:30:40Z", "aliases": [ "CVE-2024-12723" ], "details": "The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T06:15:31Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mhm6-2hxr-6fv7/GHSA-mhm6-2hxr-6fv7.json b/advisories/unreviewed/2025/01/GHSA-mhm6-2hxr-6fv7/GHSA-mhm6-2hxr-6fv7.json new file mode 100644 index 00000000000..7d210ded2f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mhm6-2hxr-6fv7/GHSA-mhm6-2hxr-6fv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhm6-2hxr-6fv7", + "modified": "2025-01-28T18:31:27Z", + "published": "2025-01-28T18:31:27Z", + "aliases": [ + "CVE-2025-0659" + ], + "details": "A path\ntraversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character\nsequence in the body of the vulnerable endpoint, it is possible to overwrite\nfiles outside of the intended directory. A threat actor with admin privileges could\nleverage this vulnerability to overwrite reports including user projects.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0659" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1715.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json b/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json index f6f59708cb8..4a7842ade3a 100644 --- a/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json +++ b/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mjmw-w38h-7mcx", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24154" ], "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json b/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json new file mode 100644 index 00000000000..3bca3dba105 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p59h-7g7v-xp8x/GHSA-p59h-7g7v-xp8x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p59h-7g7v-xp8x", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2018-9378" + ], + "details": "In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9378" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json b/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json index dbacbee5104..529a484759c 100644 --- a/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json +++ b/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7qh-x2m6-6www", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24159" ], "details": "A validation issue was addressed with improved logic. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qgfq-x64c-2prw/GHSA-qgfq-x64c-2prw.json b/advisories/unreviewed/2025/01/GHSA-qgfq-x64c-2prw/GHSA-qgfq-x64c-2prw.json new file mode 100644 index 00000000000..ce9ddb9b1d3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qgfq-x64c-2prw/GHSA-qgfq-x64c-2prw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgfq-x64c-2prw", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:27Z", + "aliases": [ + "CVE-2025-0432" + ], + "details": "EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0432" + }, + { + "type": "WEB", + "url": "https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/ewon/manuals-and-guides---installation-guides/best-practices-for-a-secure-usage-of-the-ewon-solution-en.pdf?sfvrsn=37160847_4" + }, + { + "type": "WEB", + "url": "https://support.hms-networks.com/hc/en-us/articles/19393244940818-How-to-block-all-the-unused-Ewon-Flexy-Cosy131-services-on-the-LAN-WAN-and-or-VPN-interface" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-023-06" + }, + { + "type": "WEB", + "url": "https://www.hms-networks.com/cyber-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json b/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json index 7b450d37d77..24cbe6b380a 100644 --- a/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json +++ b/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhxj-xhp5-9g9c", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24160" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r4rm-r3rr-w99w/GHSA-r4rm-r3rr-w99w.json b/advisories/unreviewed/2025/01/GHSA-r4rm-r3rr-w99w/GHSA-r4rm-r3rr-w99w.json new file mode 100644 index 00000000000..073c0bf1326 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r4rm-r3rr-w99w/GHSA-r4rm-r3rr-w99w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4rm-r3rr-w99w", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2025-23056" + ], + "details": "A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23056" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json b/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json index 1262d43689a..2e96b749bd1 100644 --- a/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json +++ b/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf94-f4r9-6gxh", - "modified": "2025-01-10T00:30:36Z", + "modified": "2025-01-28T18:31:25Z", "published": "2025-01-09T00:31:34Z", "aliases": [ "CVE-2025-0282" @@ -27,9 +27,25 @@ "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283" }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/CVE-2025-0282" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282" + }, { "type": "WEB", "url": "https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-0282" + }, + { + "type": "WEB", + "url": "https://www.synacktiv.com/sites/default/files/2024-01/synacktiv-pulseconnectsecure-multiple-vulnerabilities.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-v5qx-579h-rr6f/GHSA-v5qx-579h-rr6f.json b/advisories/unreviewed/2025/01/GHSA-v5qx-579h-rr6f/GHSA-v5qx-579h-rr6f.json index 9739d9f691e..b8ed2086c85 100644 --- a/advisories/unreviewed/2025/01/GHSA-v5qx-579h-rr6f/GHSA-v5qx-579h-rr6f.json +++ b/advisories/unreviewed/2025/01/GHSA-v5qx-579h-rr6f/GHSA-v5qx-579h-rr6f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v5qx-579h-rr6f", - "modified": "2025-01-28T03:31:14Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T03:31:14Z", "aliases": [ "CVE-2024-45340" ], "details": "Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T02:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v7qx-rccr-23xm/GHSA-v7qx-rccr-23xm.json b/advisories/unreviewed/2025/01/GHSA-v7qx-rccr-23xm/GHSA-v7qx-rccr-23xm.json index c0143e12c9f..b7055c8707f 100644 --- a/advisories/unreviewed/2025/01/GHSA-v7qx-rccr-23xm/GHSA-v7qx-rccr-23xm.json +++ b/advisories/unreviewed/2025/01/GHSA-v7qx-rccr-23xm/GHSA-v7qx-rccr-23xm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7qx-rccr-23xm", - "modified": "2025-01-28T03:31:14Z", + "modified": "2025-01-28T18:31:27Z", "published": "2025-01-28T03:31:14Z", "aliases": [ "CVE-2025-22865" ], "details": "Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T02:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vqf8-5rpg-55xx/GHSA-vqf8-5rpg-55xx.json b/advisories/unreviewed/2025/01/GHSA-vqf8-5rpg-55xx/GHSA-vqf8-5rpg-55xx.json new file mode 100644 index 00000000000..c6b078045c6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vqf8-5rpg-55xx/GHSA-vqf8-5rpg-55xx.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqf8-5rpg-55xx", + "modified": "2025-01-28T18:31:29Z", + "published": "2025-01-28T18:31:29Z", + "aliases": [ + "CVE-2025-23057" + ], + "details": "A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23057" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vqxv-7634-4c22/GHSA-vqxv-7634-4c22.json b/advisories/unreviewed/2025/01/GHSA-vqxv-7634-4c22/GHSA-vqxv-7634-4c22.json new file mode 100644 index 00000000000..30034998c31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vqxv-7634-4c22/GHSA-vqxv-7634-4c22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxv-7634-4c22", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2024-8401" + ], + "details": "CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)\nvulnerability exists when an authenticated attacker modifies folder names within the context of\nthe product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8401" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-254-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-254-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json b/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json index bbd68ee427f..74ce50e938f 100644 --- a/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json +++ b/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vv27-g57g-wgqp", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24134" ], "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json b/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json index 958c6b852e9..0f1b21f48a9 100644 --- a/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json +++ b/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vw88-wc28-c2h6", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24093" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3. An app may be able to access removable volumes without user consent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json b/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json new file mode 100644 index 00000000000..28d0ab0f932 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w7hg-77m4-rh58/GHSA-w7hg-77m4-rh58.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7hg-77m4-rh58", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2017-13318" + ], + "details": "In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13318" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json index d6289089abd..1bd05a6e0d9 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json +++ b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjxf-6r8p-9pvp", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T18:31:26Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24103" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json b/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json new file mode 100644 index 00000000000..e72754cf74a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wp75-3w5f-vg4w/GHSA-wp75-3w5f-vg4w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp75-3w5f-vg4w", + "modified": "2025-01-28T18:31:28Z", + "published": "2025-01-28T18:31:28Z", + "aliases": [ + "CVE-2018-9373" + ], + "details": "In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9373" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T17:15:08Z" + } +} \ No newline at end of file