From 8e077ab32bdab61880beb499c7582b60d8749903 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Jan 2025 21:32:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7p9f-6x8j-gxxp.json | 6 +- .../GHSA-58gj-2v59-wxcq.json | 4 +- .../GHSA-5wgx-qvpv-2353.json | 3 +- .../GHSA-8x27-645q-g2rv.json | 2 +- .../GHSA-9wpj-h5jq-88p9.json | 2 +- .../GHSA-5cwq-39c4-23v7.json | 9 ++- .../GHSA-6w8r-pjm3-q7x7.json | 1 + .../GHSA-8489-vwcj-fxfr.json | 4 +- .../GHSA-9gh4-cwcx-xqjg.json | 17 ++++- .../GHSA-jxmm-frjr-grqr.json | 9 ++- .../GHSA-px4v-wj8p-cq36.json | 1 + .../GHSA-52hm-mmj8-wwc8.json | 1 + .../GHSA-xqmf-wf6x-2cx6.json | 4 +- .../GHSA-36r6-mm7x-rqmm.json | 3 +- .../GHSA-4j9h-4jxx-94f3.json | 4 +- .../GHSA-9f3f-73qq-2pqq.json | 3 +- .../GHSA-c8hj-7v4h-6ccv.json | 4 +- .../GHSA-cpgg-rjvm-32fx.json | 1 + .../GHSA-g88j-56qq-gwx6.json | 4 +- .../GHSA-g8w2-r832-c3p7.json | 6 +- .../GHSA-hgxr-69p3-v4mx.json | 4 +- .../GHSA-j4q3-cq76-4p2r.json | 4 +- .../GHSA-mjpq-657r-v8v7.json | 4 +- .../GHSA-qc7j-6rvc-fxhf.json | 1 + .../GHSA-rxv4-3q25-g562.json | 4 +- .../GHSA-v277-v42g-mwrm.json | 4 +- .../GHSA-v9c8-gcwh-7xvh.json | 4 +- .../GHSA-wq24-fr27-25xc.json | 4 +- .../GHSA-wr5q-q78q-xq5j.json | 4 +- .../GHSA-x8q4-jwf8-q3ff.json | 4 +- .../GHSA-28q8-f96p-q62j.json | 2 +- .../GHSA-r6x6-p549-4h98.json | 2 +- .../GHSA-wvhj-3792-hf6c.json | 3 +- .../GHSA-7hvr-6xmx-44vf.json | 2 +- .../GHSA-h732-87v7-7449.json | 3 +- .../GHSA-xvw3-fvp9-cwjw.json | 1 + .../GHSA-2pjx-wvcg-vhr8.json | 10 ++- .../GHSA-4wg5-m6pq-5x5g.json | 52 +++++++++++++++ .../GHSA-555q-7wq3-w6ch.json | 6 +- .../GHSA-8226-6jj5-9jvr.json | 40 ++++++++++++ .../GHSA-998c-6m77-6859.json | 52 +++++++++++++++ .../GHSA-c5qp-mx9f-m5c7.json | 64 +++++++++++++++++++ .../GHSA-mjq9-gqhq-gfvh.json | 40 ++++++++++++ .../GHSA-pgg6-pq85-wxjf.json | 40 ++++++++++++ .../GHSA-r2c5-m74g-gvx4.json | 40 ++++++++++++ 45 files changed, 447 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-4wg5-m6pq-5x5g/GHSA-4wg5-m6pq-5x5g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8226-6jj5-9jvr/GHSA-8226-6jj5-9jvr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-998c-6m77-6859/GHSA-998c-6m77-6859.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mjq9-gqhq-gfvh/GHSA-mjq9-gqhq-gfvh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pgg6-pq85-wxjf/GHSA-pgg6-pq85-wxjf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r2c5-m74g-gvx4/GHSA-r2c5-m74g-gvx4.json diff --git a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json index 91de0f4117a..721a4acac9a 100644 --- a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json +++ b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p9f-6x8j-gxxp", - "modified": "2024-12-17T21:30:34Z", + "modified": "2025-01-29T21:31:23Z", "published": "2024-11-26T21:50:30Z", "aliases": [ "CVE-2024-8676" @@ -94,6 +94,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHBA-2024:10826" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0648" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8676" diff --git a/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json b/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json index 45c72ca540f..30bb68e04dc 100644 --- a/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json +++ b/advisories/unreviewed/2022/02/GHSA-58gj-2v59-wxcq/GHSA-58gj-2v59-wxcq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-824" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json b/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json index 999ce9d0867..ad585ea8f63 100644 --- a/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json +++ b/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/02/GHSA-8x27-645q-g2rv/GHSA-8x27-645q-g2rv.json b/advisories/unreviewed/2022/02/GHSA-8x27-645q-g2rv/GHSA-8x27-645q-g2rv.json index 3f8208cb1cf..6cbc3285c2b 100644 --- a/advisories/unreviewed/2022/02/GHSA-8x27-645q-g2rv/GHSA-8x27-645q-g2rv.json +++ b/advisories/unreviewed/2022/02/GHSA-8x27-645q-g2rv/GHSA-8x27-645q-g2rv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x27-645q-g2rv", - "modified": "2022-03-24T00:01:01Z", + "modified": "2025-01-29T21:31:19Z", "published": "2022-02-25T00:01:06Z", "aliases": [ "CVE-2022-23176" diff --git a/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json b/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json index f3cafe9ecd2..5dd0148ab59 100644 --- a/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json +++ b/advisories/unreviewed/2022/02/GHSA-9wpj-h5jq-88p9/GHSA-9wpj-h5jq-88p9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9wpj-h5jq-88p9", - "modified": "2022-03-17T00:05:29Z", + "modified": "2025-01-29T21:31:19Z", "published": "2022-02-19T00:01:03Z", "aliases": [ "CVE-2022-0543" diff --git a/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json b/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json index 5203e73562e..feb771728e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json +++ b/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cwq-39c4-23v7", - "modified": "2022-05-24T19:04:42Z", + "modified": "2025-01-29T21:31:21Z", "published": "2022-05-24T19:04:42Z", "aliases": [ "CVE-2020-11261" ], "details": "Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-6w8r-pjm3-q7x7/GHSA-6w8r-pjm3-q7x7.json b/advisories/unreviewed/2022/05/GHSA-6w8r-pjm3-q7x7/GHSA-6w8r-pjm3-q7x7.json index 255ce42cc46..e1c8d5f7a77 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w8r-pjm3-q7x7/GHSA-6w8r-pjm3-q7x7.json +++ b/advisories/unreviewed/2022/05/GHSA-6w8r-pjm3-q7x7/GHSA-6w8r-pjm3-q7x7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-120", "CWE-20" ], diff --git a/advisories/unreviewed/2022/05/GHSA-8489-vwcj-fxfr/GHSA-8489-vwcj-fxfr.json b/advisories/unreviewed/2022/05/GHSA-8489-vwcj-fxfr/GHSA-8489-vwcj-fxfr.json index 33decbc56f3..5c853322029 100644 --- a/advisories/unreviewed/2022/05/GHSA-8489-vwcj-fxfr/GHSA-8489-vwcj-fxfr.json +++ b/advisories/unreviewed/2022/05/GHSA-8489-vwcj-fxfr/GHSA-8489-vwcj-fxfr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json b/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json index c926b17defe..7ac08f6591a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json +++ b/advisories/unreviewed/2022/05/GHSA-9gh4-cwcx-xqjg/GHSA-9gh4-cwcx-xqjg.json @@ -1,23 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-9gh4-cwcx-xqjg", - "modified": "2022-05-24T17:37:39Z", + "modified": "2025-01-29T21:31:14Z", "published": "2022-05-24T17:37:39Z", "aliases": [ "CVE-2020-35241" ], "details": "FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each time any user will go to that blog page, the XSS triggers and the attacker can steal the cookie according to the crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35241" }, + { + "type": "WEB", + "url": "https://github.com/alpernae/vulnerability-research/tree/main/CVE-2020-35241" + }, { "type": "WEB", "url": "https://github.com/hemantsolo/CVE-Reference/blob/main/CVE-2020-35241.md" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/48826" + }, { "type": "WEB", "url": "https://www.flatpress.org/download" diff --git a/advisories/unreviewed/2022/05/GHSA-jxmm-frjr-grqr/GHSA-jxmm-frjr-grqr.json b/advisories/unreviewed/2022/05/GHSA-jxmm-frjr-grqr/GHSA-jxmm-frjr-grqr.json index 1d45059aadb..b947bad6923 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxmm-frjr-grqr/GHSA-jxmm-frjr-grqr.json +++ b/advisories/unreviewed/2022/05/GHSA-jxmm-frjr-grqr/GHSA-jxmm-frjr-grqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jxmm-frjr-grqr", - "modified": "2022-05-24T19:01:48Z", + "modified": "2025-01-29T21:31:14Z", "published": "2022-05-24T19:01:48Z", "aliases": [ "CVE-2021-1905" ], "details": "Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json b/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json index a170e3e2429..0f08eb6bbca 100644 --- a/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json +++ b/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-434", "CWE-78" ], diff --git a/advisories/unreviewed/2022/11/GHSA-52hm-mmj8-wwc8/GHSA-52hm-mmj8-wwc8.json b/advisories/unreviewed/2022/11/GHSA-52hm-mmj8-wwc8/GHSA-52hm-mmj8-wwc8.json index cd353ae7ac9..bda65ce3c66 100644 --- a/advisories/unreviewed/2022/11/GHSA-52hm-mmj8-wwc8/GHSA-52hm-mmj8-wwc8.json +++ b/advisories/unreviewed/2022/11/GHSA-52hm-mmj8-wwc8/GHSA-52hm-mmj8-wwc8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-xqmf-wf6x-2cx6/GHSA-xqmf-wf6x-2cx6.json b/advisories/unreviewed/2022/11/GHSA-xqmf-wf6x-2cx6/GHSA-xqmf-wf6x-2cx6.json index 91fc6240b20..4a6d4b30793 100644 --- a/advisories/unreviewed/2022/11/GHSA-xqmf-wf6x-2cx6/GHSA-xqmf-wf6x-2cx6.json +++ b/advisories/unreviewed/2022/11/GHSA-xqmf-wf6x-2cx6/GHSA-xqmf-wf6x-2cx6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json b/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json index a136b855cf2..e2545c1725e 100644 --- a/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json +++ b/advisories/unreviewed/2023/05/GHSA-36r6-mm7x-rqmm/GHSA-36r6-mm7x-rqmm.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-4j9h-4jxx-94f3/GHSA-4j9h-4jxx-94f3.json b/advisories/unreviewed/2023/05/GHSA-4j9h-4jxx-94f3/GHSA-4j9h-4jxx-94f3.json index 5cd0e5c9961..635bb13b496 100644 --- a/advisories/unreviewed/2023/05/GHSA-4j9h-4jxx-94f3/GHSA-4j9h-4jxx-94f3.json +++ b/advisories/unreviewed/2023/05/GHSA-4j9h-4jxx-94f3/GHSA-4j9h-4jxx-94f3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-9f3f-73qq-2pqq/GHSA-9f3f-73qq-2pqq.json b/advisories/unreviewed/2023/05/GHSA-9f3f-73qq-2pqq/GHSA-9f3f-73qq-2pqq.json index 8575193bcd2..bef6f92766e 100644 --- a/advisories/unreviewed/2023/05/GHSA-9f3f-73qq-2pqq/GHSA-9f3f-73qq-2pqq.json +++ b/advisories/unreviewed/2023/05/GHSA-9f3f-73qq-2pqq/GHSA-9f3f-73qq-2pqq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-c8hj-7v4h-6ccv/GHSA-c8hj-7v4h-6ccv.json b/advisories/unreviewed/2023/05/GHSA-c8hj-7v4h-6ccv/GHSA-c8hj-7v4h-6ccv.json index f42fd66b3c3..bae729f82c4 100644 --- a/advisories/unreviewed/2023/05/GHSA-c8hj-7v4h-6ccv/GHSA-c8hj-7v4h-6ccv.json +++ b/advisories/unreviewed/2023/05/GHSA-c8hj-7v4h-6ccv/GHSA-c8hj-7v4h-6ccv.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json b/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json index bbef6c74cb5..098bb40f4b1 100644 --- a/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json +++ b/advisories/unreviewed/2023/05/GHSA-cpgg-rjvm-32fx/GHSA-cpgg-rjvm-32fx.json @@ -50,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-g88j-56qq-gwx6/GHSA-g88j-56qq-gwx6.json b/advisories/unreviewed/2023/05/GHSA-g88j-56qq-gwx6/GHSA-g88j-56qq-gwx6.json index 09caae085c8..f8ac58a73d2 100644 --- a/advisories/unreviewed/2023/05/GHSA-g88j-56qq-gwx6/GHSA-g88j-56qq-gwx6.json +++ b/advisories/unreviewed/2023/05/GHSA-g88j-56qq-gwx6/GHSA-g88j-56qq-gwx6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-g8w2-r832-c3p7/GHSA-g8w2-r832-c3p7.json b/advisories/unreviewed/2023/05/GHSA-g8w2-r832-c3p7/GHSA-g8w2-r832-c3p7.json index a70656c2c28..dec936c78fb 100644 --- a/advisories/unreviewed/2023/05/GHSA-g8w2-r832-c3p7/GHSA-g8w2-r832-c3p7.json +++ b/advisories/unreviewed/2023/05/GHSA-g8w2-r832-c3p7/GHSA-g8w2-r832-c3p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8w2-r832-c3p7", - "modified": "2023-11-03T21:30:18Z", + "modified": "2025-01-29T21:31:20Z", "published": "2023-05-05T15:30:59Z", "aliases": [ "CVE-2023-29941" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/llvm/llvm-project/issues/59988" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWCCXDZP7H2JNFULSZZWXGAZHZUPN5DS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWCCXDZP7H2JNFULSZZWXGAZHZUPN5DS" diff --git a/advisories/unreviewed/2023/05/GHSA-hgxr-69p3-v4mx/GHSA-hgxr-69p3-v4mx.json b/advisories/unreviewed/2023/05/GHSA-hgxr-69p3-v4mx/GHSA-hgxr-69p3-v4mx.json index 762a244ea48..d9243fb6708 100644 --- a/advisories/unreviewed/2023/05/GHSA-hgxr-69p3-v4mx/GHSA-hgxr-69p3-v4mx.json +++ b/advisories/unreviewed/2023/05/GHSA-hgxr-69p3-v4mx/GHSA-hgxr-69p3-v4mx.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json b/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json index b60d01b85f0..c27988f2cb2 100644 --- a/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json +++ b/advisories/unreviewed/2023/05/GHSA-j4q3-cq76-4p2r/GHSA-j4q3-cq76-4p2r.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-mjpq-657r-v8v7/GHSA-mjpq-657r-v8v7.json b/advisories/unreviewed/2023/05/GHSA-mjpq-657r-v8v7/GHSA-mjpq-657r-v8v7.json index 2c980bc9faa..61665192b6c 100644 --- a/advisories/unreviewed/2023/05/GHSA-mjpq-657r-v8v7/GHSA-mjpq-657r-v8v7.json +++ b/advisories/unreviewed/2023/05/GHSA-mjpq-657r-v8v7/GHSA-mjpq-657r-v8v7.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-qc7j-6rvc-fxhf/GHSA-qc7j-6rvc-fxhf.json b/advisories/unreviewed/2023/05/GHSA-qc7j-6rvc-fxhf/GHSA-qc7j-6rvc-fxhf.json index c2a0d3c10b1..4c9feb13400 100644 --- a/advisories/unreviewed/2023/05/GHSA-qc7j-6rvc-fxhf/GHSA-qc7j-6rvc-fxhf.json +++ b/advisories/unreviewed/2023/05/GHSA-qc7j-6rvc-fxhf/GHSA-qc7j-6rvc-fxhf.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-665" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json b/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json index 1495a8b9075..5d2d5ab4b90 100644 --- a/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json +++ b/advisories/unreviewed/2023/05/GHSA-rxv4-3q25-g562/GHSA-rxv4-3q25-g562.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-v277-v42g-mwrm/GHSA-v277-v42g-mwrm.json b/advisories/unreviewed/2023/05/GHSA-v277-v42g-mwrm/GHSA-v277-v42g-mwrm.json index 7f077033d8d..6f84bda7ccc 100644 --- a/advisories/unreviewed/2023/05/GHSA-v277-v42g-mwrm/GHSA-v277-v42g-mwrm.json +++ b/advisories/unreviewed/2023/05/GHSA-v277-v42g-mwrm/GHSA-v277-v42g-mwrm.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json b/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json index 9cf14c1718e..b022247ce82 100644 --- a/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json +++ b/advisories/unreviewed/2023/05/GHSA-v9c8-gcwh-7xvh/GHSA-v9c8-gcwh-7xvh.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json b/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json index e9edff45e59..d0445cac2b0 100644 --- a/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json +++ b/advisories/unreviewed/2023/05/GHSA-wq24-fr27-25xc/GHSA-wq24-fr27-25xc.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-wr5q-q78q-xq5j/GHSA-wr5q-q78q-xq5j.json b/advisories/unreviewed/2023/05/GHSA-wr5q-q78q-xq5j/GHSA-wr5q-q78q-xq5j.json index 78bd34ae3ea..82140f9bfc6 100644 --- a/advisories/unreviewed/2023/05/GHSA-wr5q-q78q-xq5j/GHSA-wr5q-q78q-xq5j.json +++ b/advisories/unreviewed/2023/05/GHSA-wr5q-q78q-xq5j/GHSA-wr5q-q78q-xq5j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json b/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json index cdd601f4d38..cdb108cc27b 100644 --- a/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json +++ b/advisories/unreviewed/2023/05/GHSA-x8q4-jwf8-q3ff/GHSA-x8q4-jwf8-q3ff.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-28q8-f96p-q62j/GHSA-28q8-f96p-q62j.json b/advisories/unreviewed/2024/11/GHSA-28q8-f96p-q62j/GHSA-28q8-f96p-q62j.json index 775f9b66cc6..2d74624af0c 100644 --- a/advisories/unreviewed/2024/11/GHSA-28q8-f96p-q62j/GHSA-28q8-f96p-q62j.json +++ b/advisories/unreviewed/2024/11/GHSA-28q8-f96p-q62j/GHSA-28q8-f96p-q62j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28q8-f96p-q62j", - "modified": "2024-11-09T03:30:44Z", + "modified": "2025-01-29T21:31:23Z", "published": "2024-11-09T03:30:44Z", "aliases": [ "CVE-2024-8960" diff --git a/advisories/unreviewed/2024/11/GHSA-r6x6-p549-4h98/GHSA-r6x6-p549-4h98.json b/advisories/unreviewed/2024/11/GHSA-r6x6-p549-4h98/GHSA-r6x6-p549-4h98.json index 9df8fbc0fe5..37c902d0c87 100644 --- a/advisories/unreviewed/2024/11/GHSA-r6x6-p549-4h98/GHSA-r6x6-p549-4h98.json +++ b/advisories/unreviewed/2024/11/GHSA-r6x6-p549-4h98/GHSA-r6x6-p549-4h98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6x6-p549-4h98", - "modified": "2024-11-09T03:30:44Z", + "modified": "2025-01-29T21:31:23Z", "published": "2024-11-09T03:30:44Z", "aliases": [ "CVE-2024-10779" diff --git a/advisories/unreviewed/2024/11/GHSA-wvhj-3792-hf6c/GHSA-wvhj-3792-hf6c.json b/advisories/unreviewed/2024/11/GHSA-wvhj-3792-hf6c/GHSA-wvhj-3792-hf6c.json index 4276bccd91e..ad8e95e8f7b 100644 --- a/advisories/unreviewed/2024/11/GHSA-wvhj-3792-hf6c/GHSA-wvhj-3792-hf6c.json +++ b/advisories/unreviewed/2024/11/GHSA-wvhj-3792-hf6c/GHSA-wvhj-3792-hf6c.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-7hvr-6xmx-44vf/GHSA-7hvr-6xmx-44vf.json b/advisories/unreviewed/2024/12/GHSA-7hvr-6xmx-44vf/GHSA-7hvr-6xmx-44vf.json index 535f5e36153..4da41544f50 100644 --- a/advisories/unreviewed/2024/12/GHSA-7hvr-6xmx-44vf/GHSA-7hvr-6xmx-44vf.json +++ b/advisories/unreviewed/2024/12/GHSA-7hvr-6xmx-44vf/GHSA-7hvr-6xmx-44vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hvr-6xmx-44vf", - "modified": "2024-12-23T06:30:45Z", + "modified": "2025-01-29T21:31:24Z", "published": "2024-12-23T06:30:45Z", "aliases": [ "CVE-2024-11230" diff --git a/advisories/unreviewed/2024/12/GHSA-h732-87v7-7449/GHSA-h732-87v7-7449.json b/advisories/unreviewed/2024/12/GHSA-h732-87v7-7449/GHSA-h732-87v7-7449.json index 28e6cb4b584..1ce28ea0f59 100644 --- a/advisories/unreviewed/2024/12/GHSA-h732-87v7-7449/GHSA-h732-87v7-7449.json +++ b/advisories/unreviewed/2024/12/GHSA-h732-87v7-7449/GHSA-h732-87v7-7449.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-378" + "CWE-378", + "CWE-668" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json b/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json index 3b3fcd0037b..0f32d234095 100644 --- a/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json +++ b/advisories/unreviewed/2024/12/GHSA-xvw3-fvp9-cwjw/GHSA-xvw3-fvp9-cwjw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-2pjx-wvcg-vhr8/GHSA-2pjx-wvcg-vhr8.json b/advisories/unreviewed/2025/01/GHSA-2pjx-wvcg-vhr8/GHSA-2pjx-wvcg-vhr8.json index 8a87e93aba5..60cbdd6645e 100644 --- a/advisories/unreviewed/2025/01/GHSA-2pjx-wvcg-vhr8/GHSA-2pjx-wvcg-vhr8.json +++ b/advisories/unreviewed/2025/01/GHSA-2pjx-wvcg-vhr8/GHSA-2pjx-wvcg-vhr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pjx-wvcg-vhr8", - "modified": "2025-01-25T06:30:24Z", + "modified": "2025-01-29T21:31:24Z", "published": "2025-01-25T06:30:24Z", "aliases": [ "CVE-2025-0411" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0411" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-0411-7-zip-mitigation-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-0411-detection-7-zip-vulnerability" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-045" diff --git a/advisories/unreviewed/2025/01/GHSA-4wg5-m6pq-5x5g/GHSA-4wg5-m6pq-5x5g.json b/advisories/unreviewed/2025/01/GHSA-4wg5-m6pq-5x5g/GHSA-4wg5-m6pq-5x5g.json new file mode 100644 index 00000000000..b7d311d0c47 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wg5-m6pq-5x5g/GHSA-4wg5-m6pq-5x5g.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wg5-m6pq-5x5g", + "modified": "2025-01-29T21:31:25Z", + "published": "2025-01-29T21:31:25Z", + "aliases": [ + "CVE-2025-0841" + ], + "details": "A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0841" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mcdruid/52383f40d11becb79ce4033cb46546eb" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293998" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293998" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json b/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json index d2bc3e69c08..e4c929c756b 100644 --- a/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json +++ b/advisories/unreviewed/2025/01/GHSA-555q-7wq3-w6ch/GHSA-555q-7wq3-w6ch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-555q-7wq3-w6ch", - "modified": "2025-01-28T18:31:28Z", + "modified": "2025-01-29T21:31:24Z", "published": "2025-01-28T18:31:28Z", "aliases": [ "CVE-2025-0781" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00028.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-8226-6jj5-9jvr/GHSA-8226-6jj5-9jvr.json b/advisories/unreviewed/2025/01/GHSA-8226-6jj5-9jvr/GHSA-8226-6jj5-9jvr.json new file mode 100644 index 00000000000..15dc12dcda4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8226-6jj5-9jvr/GHSA-8226-6jj5-9jvr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8226-6jj5-9jvr", + "modified": "2025-01-29T21:31:25Z", + "published": "2025-01-29T21:31:25Z", + "aliases": [ + "CVE-2025-20061" + ], + "details": "mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20061" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-023-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-998c-6m77-6859/GHSA-998c-6m77-6859.json b/advisories/unreviewed/2025/01/GHSA-998c-6m77-6859/GHSA-998c-6m77-6859.json new file mode 100644 index 00000000000..d3b5053b99e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-998c-6m77-6859/GHSA-998c-6m77-6859.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-998c-6m77-6859", + "modified": "2025-01-29T21:31:24Z", + "published": "2025-01-29T21:31:24Z", + "aliases": [ + "CVE-2024-10001" + ], + "details": "A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To execute the attack, the victim must be logged into GitHub and interact with the attacker controlled malicious webpage containing the hidden iframe. This vulnerability occurs due to an improper sequence of validation, where the origin check occurs after accepting the user-controlled identity property. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.11.16, 3.12.10, 3.13.5, 3.14.2, and 3.15.0. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10001" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.17" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.6" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.3" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json b/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json new file mode 100644 index 00000000000..0d54ed87cee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5qp-mx9f-m5c7", + "modified": "2025-01-29T21:31:24Z", + "published": "2025-01-29T21:31:24Z", + "aliases": [ + "CVE-2025-0840" + ], + "details": "A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0840" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15882" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32560" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485255" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mjq9-gqhq-gfvh/GHSA-mjq9-gqhq-gfvh.json b/advisories/unreviewed/2025/01/GHSA-mjq9-gqhq-gfvh/GHSA-mjq9-gqhq-gfvh.json new file mode 100644 index 00000000000..77105e2e3f4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mjq9-gqhq-gfvh/GHSA-mjq9-gqhq-gfvh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjq9-gqhq-gfvh", + "modified": "2025-01-29T21:31:25Z", + "published": "2025-01-29T21:31:25Z", + "aliases": [ + "CVE-2025-20014" + ], + "details": "mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20014" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-023-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pgg6-pq85-wxjf/GHSA-pgg6-pq85-wxjf.json b/advisories/unreviewed/2025/01/GHSA-pgg6-pq85-wxjf/GHSA-pgg6-pq85-wxjf.json new file mode 100644 index 00000000000..a55671100c6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pgg6-pq85-wxjf/GHSA-pgg6-pq85-wxjf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgg6-pq85-wxjf", + "modified": "2025-01-29T21:31:25Z", + "published": "2025-01-29T21:31:24Z", + "aliases": [ + "CVE-2024-48852" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.\n \n\nThis issue affects FLXEON through <= 9.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48852" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108470A5684&LanguageCode=en&DocumentPartId=PDF&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r2c5-m74g-gvx4/GHSA-r2c5-m74g-gvx4.json b/advisories/unreviewed/2025/01/GHSA-r2c5-m74g-gvx4/GHSA-r2c5-m74g-gvx4.json new file mode 100644 index 00000000000..dfa22355bdf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r2c5-m74g-gvx4/GHSA-r2c5-m74g-gvx4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2c5-m74g-gvx4", + "modified": "2025-01-29T21:31:24Z", + "published": "2025-01-29T21:31:24Z", + "aliases": [ + "CVE-2024-48849" + ], + "details": "Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48849" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108470A5684&LanguageCode=en&DocumentPartId=PDF&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1385" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T19:15:18Z" + } +} \ No newline at end of file