From 920893a95816f8733c7f11280c11de2d08eefb73 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Mar 2025 21:33:44 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3wpp-5prr-27h8.json | 2 +- .../GHSA-63p5-chvq-vhq6.json | 2 +- .../GHSA-974m-g68h-9gxx.json | 6 +++- .../GHSA-hhwq-8w3p-w65v.json | 6 +++- .../GHSA-hr8p-qwmc-vxmp.json | 2 +- .../GHSA-qvqh-m74g-fqcf.json | 2 +- .../GHSA-rf23-mj2w-9g24.json | 4 ++- .../GHSA-v7xw-hr75-rm43.json | 2 +- .../GHSA-w922-qg6g-84wc.json | 4 ++- .../GHSA-c89p-xpwc-c8c4.json | 14 +++++++- .../GHSA-q597-3v27-cmvx.json | 14 +++++++- .../GHSA-qrqf-2crr-jvqf.json | 14 +++++++- .../GHSA-jm67-cprv-v6wx.json | 2 +- .../GHSA-69q2-pwf5-cf5q.json | 4 +-- .../GHSA-ch5h-vgj6-vhx6.json | 4 +-- .../GHSA-m6hg-jwrh-92jj.json | 4 +-- .../GHSA-4r7g-qqxf-m6v8.json | 15 +++++--- .../GHSA-5v6r-j86q-gwmh.json | 15 +++++--- .../GHSA-6hjx-r579-83fp.json | 15 +++++--- .../GHSA-6w55-mvg6-h5h5.json | 15 +++++--- .../GHSA-6xr9-pvgc-m3pc.json | 15 +++++--- .../GHSA-9fg2-2f57-9p5h.json | 6 +++- .../GHSA-9q42-qq54-fwvj.json | 15 +++++--- .../GHSA-cp4j-vw64-wp3f.json | 15 +++++--- .../GHSA-f5v2-rhg6-jmg7.json | 6 +++- .../GHSA-g2f3-xcg7-rxp6.json | 11 ++++-- .../GHSA-hfgc-7c7c-g6r6.json | 11 ++++-- .../GHSA-p4x7-wjcj-5xfj.json | 15 +++++--- .../GHSA-pf6p-pjxv-jwqh.json | 15 +++++--- .../GHSA-pvp4-8q5g-43fg.json | 6 +++- .../GHSA-w5mv-5x6q-jgmp.json | 6 +++- .../GHSA-xqj4-x748-chwg.json | 15 +++++--- .../GHSA-2h2j-468c-9fxc.json | 29 +++++++++++++++ .../GHSA-2rhp-j953-ghxr.json | 15 +++++--- .../GHSA-33vr-4wpq-62wv.json | 15 +++++--- .../GHSA-3xq6-ch8v-2ghj.json | 15 +++++--- .../GHSA-4gjv-fwgw-f3qc.json | 29 +++++++++++++++ .../GHSA-6mpm-xvfm-qh84.json | 19 +++++++--- .../GHSA-6v75-2jr8-rwxg.json | 15 +++++--- .../GHSA-793v-gxfp-9q9h.json | 29 +++++++++++++++ .../GHSA-82qh-7crj-p5wh.json | 15 +++++--- .../GHSA-8hqq-hvx2-7hvc.json | 15 +++++--- .../GHSA-8xvr-2xvr-m437.json | 15 +++++--- .../GHSA-9cf6-w6g4-wf93.json | 15 +++++--- .../GHSA-c22c-c436-hqcq.json | 15 +++++--- .../GHSA-cg3h-9f75-2rjp.json | 29 +++++++++++++++ .../GHSA-cj4j-rhvm-wqq7.json | 15 +++++--- .../GHSA-f84w-xq57-rqf4.json | 15 +++++--- .../GHSA-fj56-7h2j-m3p3.json | 15 +++++--- .../GHSA-g2m6-q89m-g82f.json | 15 +++++--- .../GHSA-gp8f-w5c5-9274.json | 15 +++++--- .../GHSA-hc9m-j5rq-cphm.json | 15 +++++--- .../GHSA-hw9p-62g6-396j.json | 15 +++++--- .../GHSA-j3gx-p9r2-3cwr.json | 33 +++++++++++++++++ .../GHSA-jcv4-98x3-hrjw.json | 15 +++++--- .../GHSA-jp47-j92m-38q6.json | 15 +++++--- .../GHSA-jqm6-8ggx-r3ww.json | 6 +++- .../GHSA-mf3c-6mg5-67rj.json | 15 +++++--- .../GHSA-mfqx-wfm8-g2h8.json | 33 +++++++++++++++++ .../GHSA-p67q-hj2w-25v7.json | 33 +++++++++++++++++ .../GHSA-p8wr-8hg7-qcg5.json | 15 +++++--- .../GHSA-pvcg-63x2-w4px.json | 15 +++++--- .../GHSA-q7w8-q2f9-vcmh.json | 6 +++- .../GHSA-q9q9-pv7p-h33j.json | 15 +++++--- .../GHSA-qfmj-8v62-hh7x.json | 36 +++++++++++++++++++ .../GHSA-qg4m-5hg4-34vq.json | 6 +++- .../GHSA-rfj8-j94q-wxfj.json | 15 +++++--- .../GHSA-rvwg-6c86-cxf4.json | 15 +++++--- .../GHSA-x536-9g45-6jcr.json | 15 +++++--- .../GHSA-x9h6-qwxm-528g.json | 15 +++++--- .../GHSA-xxc4-h4cm-j5r2.json | 6 +++- 71 files changed, 785 insertions(+), 181 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-793v-gxfp-9q9h/GHSA-793v-gxfp-9q9h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qfmj-8v62-hh7x/GHSA-qfmj-8v62-hh7x.json diff --git a/advisories/unreviewed/2023/03/GHSA-3wpp-5prr-27h8/GHSA-3wpp-5prr-27h8.json b/advisories/unreviewed/2023/03/GHSA-3wpp-5prr-27h8/GHSA-3wpp-5prr-27h8.json index f663e800d98..0c1dad45007 100644 --- a/advisories/unreviewed/2023/03/GHSA-3wpp-5prr-27h8/GHSA-3wpp-5prr-27h8.json +++ b/advisories/unreviewed/2023/03/GHSA-3wpp-5prr-27h8/GHSA-3wpp-5prr-27h8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wpp-5prr-27h8", - "modified": "2023-03-16T15:30:17Z", + "modified": "2025-03-05T21:32:02Z", "published": "2023-03-10T21:30:19Z", "aliases": [ "CVE-2023-25148" diff --git a/advisories/unreviewed/2023/03/GHSA-63p5-chvq-vhq6/GHSA-63p5-chvq-vhq6.json b/advisories/unreviewed/2023/03/GHSA-63p5-chvq-vhq6/GHSA-63p5-chvq-vhq6.json index d399ebaedf6..82bd4f48a29 100644 --- a/advisories/unreviewed/2023/03/GHSA-63p5-chvq-vhq6/GHSA-63p5-chvq-vhq6.json +++ b/advisories/unreviewed/2023/03/GHSA-63p5-chvq-vhq6/GHSA-63p5-chvq-vhq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63p5-chvq-vhq6", - "modified": "2023-03-16T15:30:19Z", + "modified": "2025-03-05T21:32:01Z", "published": "2023-03-10T21:30:20Z", "aliases": [ "CVE-2023-25145" diff --git a/advisories/unreviewed/2023/03/GHSA-974m-g68h-9gxx/GHSA-974m-g68h-9gxx.json b/advisories/unreviewed/2023/03/GHSA-974m-g68h-9gxx/GHSA-974m-g68h-9gxx.json index 94c13a46da7..f321fcde1b3 100644 --- a/advisories/unreviewed/2023/03/GHSA-974m-g68h-9gxx/GHSA-974m-g68h-9gxx.json +++ b/advisories/unreviewed/2023/03/GHSA-974m-g68h-9gxx/GHSA-974m-g68h-9gxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-974m-g68h-9gxx", - "modified": "2023-03-13T06:30:25Z", + "modified": "2025-03-05T21:31:56Z", "published": "2023-03-07T21:30:17Z", "aliases": [ "CVE-2023-20632" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://corp.mediatek.com/product-security-bulletin/March-2023" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/bulletins/sb23-072" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-hhwq-8w3p-w65v/GHSA-hhwq-8w3p-w65v.json b/advisories/unreviewed/2023/03/GHSA-hhwq-8w3p-w65v/GHSA-hhwq-8w3p-w65v.json index 26ad521b0fa..e06f9af3efd 100644 --- a/advisories/unreviewed/2023/03/GHSA-hhwq-8w3p-w65v/GHSA-hhwq-8w3p-w65v.json +++ b/advisories/unreviewed/2023/03/GHSA-hhwq-8w3p-w65v/GHSA-hhwq-8w3p-w65v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhwq-8w3p-w65v", - "modified": "2023-03-13T06:30:25Z", + "modified": "2025-03-05T21:31:56Z", "published": "2023-03-07T21:30:17Z", "aliases": [ "CVE-2023-20630" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://corp.mediatek.com/product-security-bulletin/March-2023" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/bulletins/sb23-072" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-hr8p-qwmc-vxmp/GHSA-hr8p-qwmc-vxmp.json b/advisories/unreviewed/2023/03/GHSA-hr8p-qwmc-vxmp/GHSA-hr8p-qwmc-vxmp.json index df18bebfc9e..0909e4a20c5 100644 --- a/advisories/unreviewed/2023/03/GHSA-hr8p-qwmc-vxmp/GHSA-hr8p-qwmc-vxmp.json +++ b/advisories/unreviewed/2023/03/GHSA-hr8p-qwmc-vxmp/GHSA-hr8p-qwmc-vxmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr8p-qwmc-vxmp", - "modified": "2023-03-14T21:30:21Z", + "modified": "2025-03-05T21:31:59Z", "published": "2023-03-08T21:30:23Z", "aliases": [ "CVE-2023-22889" diff --git a/advisories/unreviewed/2023/03/GHSA-qvqh-m74g-fqcf/GHSA-qvqh-m74g-fqcf.json b/advisories/unreviewed/2023/03/GHSA-qvqh-m74g-fqcf/GHSA-qvqh-m74g-fqcf.json index b46c0c9d2f5..36d0e881437 100644 --- a/advisories/unreviewed/2023/03/GHSA-qvqh-m74g-fqcf/GHSA-qvqh-m74g-fqcf.json +++ b/advisories/unreviewed/2023/03/GHSA-qvqh-m74g-fqcf/GHSA-qvqh-m74g-fqcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvqh-m74g-fqcf", - "modified": "2023-03-16T15:30:19Z", + "modified": "2025-03-05T21:32:01Z", "published": "2023-03-10T21:30:19Z", "aliases": [ "CVE-2023-25146" diff --git a/advisories/unreviewed/2023/03/GHSA-rf23-mj2w-9g24/GHSA-rf23-mj2w-9g24.json b/advisories/unreviewed/2023/03/GHSA-rf23-mj2w-9g24/GHSA-rf23-mj2w-9g24.json index 67fb6e7e759..f8c3b6e56dd 100644 --- a/advisories/unreviewed/2023/03/GHSA-rf23-mj2w-9g24/GHSA-rf23-mj2w-9g24.json +++ b/advisories/unreviewed/2023/03/GHSA-rf23-mj2w-9g24/GHSA-rf23-mj2w-9g24.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-v7xw-hr75-rm43/GHSA-v7xw-hr75-rm43.json b/advisories/unreviewed/2023/03/GHSA-v7xw-hr75-rm43/GHSA-v7xw-hr75-rm43.json index feec5d12544..34939a007c7 100644 --- a/advisories/unreviewed/2023/03/GHSA-v7xw-hr75-rm43/GHSA-v7xw-hr75-rm43.json +++ b/advisories/unreviewed/2023/03/GHSA-v7xw-hr75-rm43/GHSA-v7xw-hr75-rm43.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7xw-hr75-rm43", - "modified": "2023-03-16T18:30:28Z", + "modified": "2025-03-05T21:31:59Z", "published": "2023-03-08T21:30:23Z", "aliases": [ "CVE-2023-22891" diff --git a/advisories/unreviewed/2023/03/GHSA-w922-qg6g-84wc/GHSA-w922-qg6g-84wc.json b/advisories/unreviewed/2023/03/GHSA-w922-qg6g-84wc/GHSA-w922-qg6g-84wc.json index e9cb8512548..288655538b9 100644 --- a/advisories/unreviewed/2023/03/GHSA-w922-qg6g-84wc/GHSA-w922-qg6g-84wc.json +++ b/advisories/unreviewed/2023/03/GHSA-w922-qg6g-84wc/GHSA-w922-qg6g-84wc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-c89p-xpwc-c8c4/GHSA-c89p-xpwc-c8c4.json b/advisories/unreviewed/2023/04/GHSA-c89p-xpwc-c8c4/GHSA-c89p-xpwc-c8c4.json index 49171602f30..22f4b766749 100644 --- a/advisories/unreviewed/2023/04/GHSA-c89p-xpwc-c8c4/GHSA-c89p-xpwc-c8c4.json +++ b/advisories/unreviewed/2023/04/GHSA-c89p-xpwc-c8c4/GHSA-c89p-xpwc-c8c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c89p-xpwc-c8c4", - "modified": "2023-04-12T18:30:38Z", + "modified": "2025-03-05T21:32:02Z", "published": "2023-04-06T06:30:19Z", "aliases": [ "CVE-2023-29420" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" diff --git a/advisories/unreviewed/2023/04/GHSA-q597-3v27-cmvx/GHSA-q597-3v27-cmvx.json b/advisories/unreviewed/2023/04/GHSA-q597-3v27-cmvx/GHSA-q597-3v27-cmvx.json index 6d9eb4e027c..96dd0c3233a 100644 --- a/advisories/unreviewed/2023/04/GHSA-q597-3v27-cmvx/GHSA-q597-3v27-cmvx.json +++ b/advisories/unreviewed/2023/04/GHSA-q597-3v27-cmvx/GHSA-q597-3v27-cmvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q597-3v27-cmvx", - "modified": "2023-04-12T18:30:38Z", + "modified": "2025-03-05T21:32:02Z", "published": "2023-04-06T06:30:19Z", "aliases": [ "CVE-2023-29418" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" diff --git a/advisories/unreviewed/2023/04/GHSA-qrqf-2crr-jvqf/GHSA-qrqf-2crr-jvqf.json b/advisories/unreviewed/2023/04/GHSA-qrqf-2crr-jvqf/GHSA-qrqf-2crr-jvqf.json index 59c2ee37fae..a6ec41b237d 100644 --- a/advisories/unreviewed/2023/04/GHSA-qrqf-2crr-jvqf/GHSA-qrqf-2crr-jvqf.json +++ b/advisories/unreviewed/2023/04/GHSA-qrqf-2crr-jvqf/GHSA-qrqf-2crr-jvqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrqf-2crr-jvqf", - "modified": "2023-04-12T18:30:38Z", + "modified": "2025-03-05T21:32:02Z", "published": "2023-04-06T06:30:19Z", "aliases": [ "CVE-2023-29419" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://github.com/kspalaiologos/bzip3/compare/1.2.2...1.2.3" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA7S7HDUAINOTCSWQZ5LIW756DYY22V2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMLFV2FJK3CM7NJLVPZI5RUAFQZICPWW" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JLSE25SV7K2NB6FTFT4UHJOJUHBHYHY" diff --git a/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json b/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json index 27a5e2b8e87..e3b390bcd22 100644 --- a/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json +++ b/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm67-cprv-v6wx", - "modified": "2024-04-04T05:34:00Z", + "modified": "2025-03-05T21:32:01Z", "published": "2023-07-06T19:24:11Z", "aliases": [ "CVE-2023-0030" diff --git a/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json b/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json index a482c887b83..ee23b636da2 100644 --- a/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json +++ b/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-69q2-pwf5-cf5q", - "modified": "2024-03-27T12:30:41Z", + "modified": "2025-03-05T21:32:03Z", "published": "2024-03-27T12:30:41Z", "aliases": [ "CVE-2024-30177" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json b/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json index 4d31bec1506..c02554dc5ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json +++ b/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ch5h-vgj6-vhx6", - "modified": "2024-03-28T06:30:46Z", + "modified": "2025-03-05T21:32:03Z", "published": "2024-03-28T06:30:46Z", "aliases": [ "CVE-2023-36679" ], - "details": "Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.\n\n", + "details": "Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json b/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json index 7c815efef78..bc6b4cef069 100644 --- a/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json +++ b/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m6hg-jwrh-92jj", - "modified": "2024-03-26T12:31:29Z", + "modified": "2025-03-05T21:32:02Z", "published": "2024-03-26T12:31:29Z", "aliases": [ "CVE-2024-30232" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-4r7g-qqxf-m6v8/GHSA-4r7g-qqxf-m6v8.json b/advisories/unreviewed/2025/02/GHSA-4r7g-qqxf-m6v8/GHSA-4r7g-qqxf-m6v8.json index 15c4c821243..134e03994c3 100644 --- a/advisories/unreviewed/2025/02/GHSA-4r7g-qqxf-m6v8/GHSA-4r7g-qqxf-m6v8.json +++ b/advisories/unreviewed/2025/02/GHSA-4r7g-qqxf-m6v8/GHSA-4r7g-qqxf-m6v8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4r7g-qqxf-m6v8", - "modified": "2025-02-27T03:34:06Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-02-27T03:34:06Z", "aliases": [ "CVE-2025-21776" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: hub: Ignore non-compliant devices with too many configs or interfaces\n\nRobert Morris created a test program which can cause\nusb_hub_to_struct_hub() to dereference a NULL or inappropriate\npointer:\n\nOops: general protection fault, probably for non-canonical address\n0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI\nCPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14\nHardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110\n...\nCall Trace:\n \n ? die_addr+0x31/0x80\n ? exc_general_protection+0x1b4/0x3c0\n ? asm_exc_general_protection+0x26/0x30\n ? usb_hub_adjust_deviceremovable+0x78/0x110\n hub_probe+0x7c7/0xab0\n usb_probe_interface+0x14b/0x350\n really_probe+0xd0/0x2d0\n ? __pfx___device_attach_driver+0x10/0x10\n __driver_probe_device+0x6e/0x110\n driver_probe_device+0x1a/0x90\n __device_attach_driver+0x7e/0xc0\n bus_for_each_drv+0x7f/0xd0\n __device_attach+0xaa/0x1a0\n bus_probe_device+0x8b/0xa0\n device_add+0x62e/0x810\n usb_set_configuration+0x65d/0x990\n usb_generic_driver_probe+0x4b/0x70\n usb_probe_device+0x36/0xd0\n\nThe cause of this error is that the device has two interfaces, and the\nhub driver binds to interface 1 instead of interface 0, which is where\nusb_hub_to_struct_hub() looks.\n\nWe can prevent the problem from occurring by refusing to accept hub\ndevices that violate the USB spec by having more than one\nconfiguration or interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5v6r-j86q-gwmh/GHSA-5v6r-j86q-gwmh.json b/advisories/unreviewed/2025/02/GHSA-5v6r-j86q-gwmh/GHSA-5v6r-j86q-gwmh.json index 1419d648f33..3594e2b73e0 100644 --- a/advisories/unreviewed/2025/02/GHSA-5v6r-j86q-gwmh/GHSA-5v6r-j86q-gwmh.json +++ b/advisories/unreviewed/2025/02/GHSA-5v6r-j86q-gwmh/GHSA-5v6r-j86q-gwmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5v6r-j86q-gwmh", - "modified": "2025-02-27T03:34:06Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21775" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: ctucanfd: handle skb allocation failure\n\nIf skb allocation fails, the pointer to struct can_frame is NULL. This\nis actually handled everywhere inside ctucan_err_interrupt() except for\nthe only place.\n\nAdd the missed NULL check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE static\nanalysis tool.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6hjx-r579-83fp/GHSA-6hjx-r579-83fp.json b/advisories/unreviewed/2025/02/GHSA-6hjx-r579-83fp/GHSA-6hjx-r579-83fp.json index a9bbedef10e..f698ea9bba7 100644 --- a/advisories/unreviewed/2025/02/GHSA-6hjx-r579-83fp/GHSA-6hjx-r579-83fp.json +++ b/advisories/unreviewed/2025/02/GHSA-6hjx-r579-83fp/GHSA-6hjx-r579-83fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hjx-r579-83fp", - "modified": "2025-02-27T03:34:04Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-27T03:34:04Z", "aliases": [ "CVE-2025-21748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix integer overflows on 32 bit systems\n\nOn 32bit systems the addition operations in ipc_msg_alloc() can\npotentially overflow leading to memory corruption.\nAdd bounds checking using KSMBD_IPC_MAX_PAYLOAD to avoid overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json b/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json index 8ed88d78a15..773fba991be 100644 --- a/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json +++ b/advisories/unreviewed/2025/02/GHSA-6w55-mvg6-h5h5/GHSA-6w55-mvg6-h5h5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6w55-mvg6-h5h5", - "modified": "2025-02-12T18:31:36Z", + "modified": "2025-03-05T21:32:04Z", "published": "2025-02-12T18:31:36Z", "aliases": [ "CVE-2025-25741" ], "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the IPv6_PppoePassword parameter in the SetIPv6PppoeSettings module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-12T18:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6xr9-pvgc-m3pc/GHSA-6xr9-pvgc-m3pc.json b/advisories/unreviewed/2025/02/GHSA-6xr9-pvgc-m3pc/GHSA-6xr9-pvgc-m3pc.json index 22666280c9f..77b7e76c667 100644 --- a/advisories/unreviewed/2025/02/GHSA-6xr9-pvgc-m3pc/GHSA-6xr9-pvgc-m3pc.json +++ b/advisories/unreviewed/2025/02/GHSA-6xr9-pvgc-m3pc/GHSA-6xr9-pvgc-m3pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6xr9-pvgc-m3pc", - "modified": "2025-02-27T03:34:04Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-27T03:34:04Z", "aliases": [ "CVE-2025-21743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: ipheth: fix possible overflow in DPE length check\n\nOriginally, it was possible for the DPE length check to overflow if\nwDatagramIndex + wDatagramLength > U16_MAX. This could lead to an OoB\nread.\n\nMove the wDatagramIndex term to the other side of the inequality.\n\nAn existing condition ensures that wDatagramIndex < urb->actual_length.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json b/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json index 5c0af6249ea..b51877a8714 100644 --- a/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json +++ b/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fg2-2f57-9p5h", - "modified": "2025-02-24T09:35:45Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-24T09:35:45Z", "aliases": [ "CVE-2025-0690" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346123" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-9q42-qq54-fwvj/GHSA-9q42-qq54-fwvj.json b/advisories/unreviewed/2025/02/GHSA-9q42-qq54-fwvj/GHSA-9q42-qq54-fwvj.json index 97a858903f1..3db547e5d91 100644 --- a/advisories/unreviewed/2025/02/GHSA-9q42-qq54-fwvj/GHSA-9q42-qq54-fwvj.json +++ b/advisories/unreviewed/2025/02/GHSA-9q42-qq54-fwvj/GHSA-9q42-qq54-fwvj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9q42-qq54-fwvj", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-03-05T21:32:06Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu: Fix potential memory leak in iopf_queue_remove_device()\n\nThe iopf_queue_remove_device() helper removes a device from the per-iommu\niopf queue when PRI is disabled on the device. It responds to all\noutstanding iopf's with an IOMMU_PAGE_RESP_INVALID code and detaches the\ndevice from the queue.\n\nHowever, it fails to release the group structure that represents a group\nof iopf's awaiting for a response after responding to the hardware. This\ncan cause a memory leak if iopf_queue_remove_device() is called with\npending iopf's.\n\nFix it by calling iopf_free_group() after the iopf group is responded.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:17Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cp4j-vw64-wp3f/GHSA-cp4j-vw64-wp3f.json b/advisories/unreviewed/2025/02/GHSA-cp4j-vw64-wp3f/GHSA-cp4j-vw64-wp3f.json index b40980407d8..a7809190705 100644 --- a/advisories/unreviewed/2025/02/GHSA-cp4j-vw64-wp3f/GHSA-cp4j-vw64-wp3f.json +++ b/advisories/unreviewed/2025/02/GHSA-cp4j-vw64-wp3f/GHSA-cp4j-vw64-wp3f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cp4j-vw64-wp3f", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21774" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: rockchip: rkcanfd_handle_rx_fifo_overflow_int(): bail out if skb cannot be allocated\n\nFix NULL pointer check in rkcanfd_handle_rx_fifo_overflow_int() to\nbail out if skb cannot be allocated.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json index e8f5158b8c0..36dfd09ca46 100644 --- a/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json +++ b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5v2-rhg6-jmg7", - "modified": "2025-02-18T21:32:50Z", + "modified": "2025-03-05T21:32:04Z", "published": "2025-02-18T21:32:50Z", "aliases": [ "CVE-2024-45774" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337461" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-g2f3-xcg7-rxp6/GHSA-g2f3-xcg7-rxp6.json b/advisories/unreviewed/2025/02/GHSA-g2f3-xcg7-rxp6/GHSA-g2f3-xcg7-rxp6.json index 5974d972de0..353dad63ec0 100644 --- a/advisories/unreviewed/2025/02/GHSA-g2f3-xcg7-rxp6/GHSA-g2f3-xcg7-rxp6.json +++ b/advisories/unreviewed/2025/02/GHSA-g2f3-xcg7-rxp6/GHSA-g2f3-xcg7-rxp6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g2f3-xcg7-rxp6", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-03-05T21:32:06Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21769" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: Add .owner to vmclock_miscdev_fops\n\nWithout the .owner field, the module can be unloaded while /dev/vmclock0\nis open, leading to an oops.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:17Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hfgc-7c7c-g6r6/GHSA-hfgc-7c7c-g6r6.json b/advisories/unreviewed/2025/02/GHSA-hfgc-7c7c-g6r6/GHSA-hfgc-7c7c-g6r6.json index a379d97c5a9..badfc829a49 100644 --- a/advisories/unreviewed/2025/02/GHSA-hfgc-7c7c-g6r6/GHSA-hfgc-7c7c-g6r6.json +++ b/advisories/unreviewed/2025/02/GHSA-hfgc-7c7c-g6r6/GHSA-hfgc-7c7c-g6r6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfgc-7c7c-g6r6", - "modified": "2025-02-27T03:34:04Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-27T03:34:04Z", "aliases": [ "CVE-2025-21745" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: Fix class @block_class's subsystem refcount leakage\n\nblkcg_fill_root_iostats() iterates over @block_class's devices by\nclass_dev_iter_(init|next)(), but does not end iterating with\nclass_dev_iter_exit(), so causes the class's subsystem refcount leakage.\n\nFix by ending the iterating with class_dev_iter_exit().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-p4x7-wjcj-5xfj/GHSA-p4x7-wjcj-5xfj.json b/advisories/unreviewed/2025/02/GHSA-p4x7-wjcj-5xfj/GHSA-p4x7-wjcj-5xfj.json index 76ccb35b628..188c8831deb 100644 --- a/advisories/unreviewed/2025/02/GHSA-p4x7-wjcj-5xfj/GHSA-p4x7-wjcj-5xfj.json +++ b/advisories/unreviewed/2025/02/GHSA-p4x7-wjcj-5xfj/GHSA-p4x7-wjcj-5xfj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4x7-wjcj-5xfj", - "modified": "2025-02-27T03:34:06Z", + "modified": "2025-03-05T21:32:06Z", "published": "2025-02-27T03:34:06Z", "aliases": [ "CVE-2025-21773" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: fix potential NULL pointer dereference on udev->serial\n\nThe driver assumed that es58x_dev->udev->serial could never be NULL.\nWhile this is true on commercially available devices, an attacker\ncould spoof the device identity providing a NULL USB serial number.\nThat would trigger a NULL pointer dereference.\n\nAdd a check on es58x_dev->udev->serial before accessing it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:17Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pf6p-pjxv-jwqh/GHSA-pf6p-pjxv-jwqh.json b/advisories/unreviewed/2025/02/GHSA-pf6p-pjxv-jwqh/GHSA-pf6p-pjxv-jwqh.json index 38d40141b76..d413addc579 100644 --- a/advisories/unreviewed/2025/02/GHSA-pf6p-pjxv-jwqh/GHSA-pf6p-pjxv-jwqh.json +++ b/advisories/unreviewed/2025/02/GHSA-pf6p-pjxv-jwqh/GHSA-pf6p-pjxv-jwqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pf6p-pjxv-jwqh", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-03-05T21:32:06Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21755" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Orphan socket after transport release\n\nDuring socket release, sock_orphan() is called without considering that it\nsets sk->sk_wq to NULL. Later, if SO_LINGER is enabled, this leads to a\nnull pointer dereferenced in virtio_transport_wait_close().\n\nOrphan the socket only after transport release.\n\nPartially reverts the 'Fixes:' commit.\n\nKASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]\n lock_acquire+0x19e/0x500\n _raw_spin_lock_irqsave+0x47/0x70\n add_wait_queue+0x46/0x230\n virtio_transport_release+0x4e7/0x7f0\n __vsock_release+0xfd/0x490\n vsock_release+0x90/0x120\n __sock_release+0xa3/0x250\n sock_close+0x14/0x20\n __fput+0x35e/0xa90\n __x64_sys_close+0x78/0xd0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pvp4-8q5g-43fg/GHSA-pvp4-8q5g-43fg.json b/advisories/unreviewed/2025/02/GHSA-pvp4-8q5g-43fg/GHSA-pvp4-8q5g-43fg.json index dbf4af70511..41c453e2160 100644 --- a/advisories/unreviewed/2025/02/GHSA-pvp4-8q5g-43fg/GHSA-pvp4-8q5g-43fg.json +++ b/advisories/unreviewed/2025/02/GHSA-pvp4-8q5g-43fg/GHSA-pvp4-8q5g-43fg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvp4-8q5g-43fg", - "modified": "2025-02-21T12:32:13Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-21T12:32:12Z", "aliases": [ "CVE-2025-1470" ], "details": "In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures. This can lead to NULL pointer dereference crashes. Beginning in version 0.5.0, internal OMR consumers of atoe functions handle NULL return values and memory allocation failures correctly.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/02/GHSA-w5mv-5x6q-jgmp/GHSA-w5mv-5x6q-jgmp.json b/advisories/unreviewed/2025/02/GHSA-w5mv-5x6q-jgmp/GHSA-w5mv-5x6q-jgmp.json index a5b0618ff32..0daa1654d66 100644 --- a/advisories/unreviewed/2025/02/GHSA-w5mv-5x6q-jgmp/GHSA-w5mv-5x6q-jgmp.json +++ b/advisories/unreviewed/2025/02/GHSA-w5mv-5x6q-jgmp/GHSA-w5mv-5x6q-jgmp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5mv-5x6q-jgmp", - "modified": "2025-02-21T12:32:12Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-21T12:32:12Z", "aliases": [ "CVE-2025-1471" ], "details": "In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correctly and checked appropriately to prevent buffer overflows.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/02/GHSA-xqj4-x748-chwg/GHSA-xqj4-x748-chwg.json b/advisories/unreviewed/2025/02/GHSA-xqj4-x748-chwg/GHSA-xqj4-x748-chwg.json index fa4481a7f8c..976fdee0655 100644 --- a/advisories/unreviewed/2025/02/GHSA-xqj4-x748-chwg/GHSA-xqj4-x748-chwg.json +++ b/advisories/unreviewed/2025/02/GHSA-xqj4-x748-chwg/GHSA-xqj4-x748-chwg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xqj4-x748-chwg", - "modified": "2025-02-27T03:34:04Z", + "modified": "2025-03-05T21:32:05Z", "published": "2025-02-27T03:34:04Z", "aliases": [ "CVE-2025-21744" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()\n\nOn removal of the device or unloading of the kernel module a potential NULL\npointer dereference occurs.\n\nThe following sequence deletes the interface:\n\n brcmf_detach()\n brcmf_remove_interface()\n brcmf_del_if()\n\nInside the brcmf_del_if() function the drvr->if2bss[ifidx] is updated to\nBRCMF_BSSIDX_INVALID (-1) if the bsscfgidx matches.\n\nAfter brcmf_remove_interface() call the brcmf_proto_detach() function is\ncalled providing the following sequence:\n\n brcmf_detach()\n brcmf_proto_detach()\n brcmf_proto_msgbuf_detach()\n brcmf_flowring_detach()\n brcmf_msgbuf_delete_flowring()\n brcmf_msgbuf_remove_flowring()\n brcmf_flowring_delete()\n brcmf_get_ifp()\n brcmf_txfinalize()\n\nSince brcmf_get_ip() can and actually will return NULL in this case the\ncall to brcmf_txfinalize() will result in a NULL pointer dereference inside\nbrcmf_txfinalize() when trying to update ifp->ndev->stats.tx_errors.\n\nThis will only happen if a flowring still has an skb.\n\nAlthough the NULL pointer dereference has only been seen when trying to\nupdate the tx statistic, all other uses of the ifp pointer have been\nguarded as well with an early return if ifp is NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:15Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json b/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json new file mode 100644 index 00000000000..4587bb53eab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h2j-468c-9fxc", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2025-25634" + ], + "details": "A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25634" + }, + { + "type": "WEB", + "url": "https://github.com/Pr0b1em/IoT/blob/master/TendaAC15v15.03.05.19GetParentControlInfo.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2rhp-j953-ghxr/GHSA-2rhp-j953-ghxr.json b/advisories/unreviewed/2025/03/GHSA-2rhp-j953-ghxr/GHSA-2rhp-j953-ghxr.json index 58a6b9b612c..7b457fbac5b 100644 --- a/advisories/unreviewed/2025/03/GHSA-2rhp-j953-ghxr/GHSA-2rhp-j953-ghxr.json +++ b/advisories/unreviewed/2025/03/GHSA-2rhp-j953-ghxr/GHSA-2rhp-j953-ghxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2rhp-j953-ghxr", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27668" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-829" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-33vr-4wpq-62wv/GHSA-33vr-4wpq-62wv.json b/advisories/unreviewed/2025/03/GHSA-33vr-4wpq-62wv/GHSA-33vr-4wpq-62wv.json index 5d097d73353..46a4ee73453 100644 --- a/advisories/unreviewed/2025/03/GHSA-33vr-4wpq-62wv/GHSA-33vr-4wpq-62wv.json +++ b/advisories/unreviewed/2025/03/GHSA-33vr-4wpq-62wv/GHSA-33vr-4wpq-62wv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-33vr-4wpq-62wv", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27669" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230524-0013.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3xq6-ch8v-2ghj/GHSA-3xq6-ch8v-2ghj.json b/advisories/unreviewed/2025/03/GHSA-3xq6-ch8v-2ghj/GHSA-3xq6-ch8v-2ghj.json index af4a1a8320b..cad469bc96b 100644 --- a/advisories/unreviewed/2025/03/GHSA-3xq6-ch8v-2ghj/GHSA-3xq6-ch8v-2ghj.json +++ b/advisories/unreviewed/2025/03/GHSA-3xq6-ch8v-2ghj/GHSA-3xq6-ch8v-2ghj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3xq6-ch8v-2ghj", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27670" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-20230524-0014.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-347" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json b/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json new file mode 100644 index 00000000000..abe031a2e73 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gjv-fwgw-f3qc", + "modified": "2025-03-05T21:32:12Z", + "published": "2025-03-05T21:32:12Z", + "aliases": [ + "CVE-2024-48246" + ], + "details": "Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the \"Name\" parameter of /vehicle-management/booking.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48246" + }, + { + "type": "WEB", + "url": "https://github.com/ShadowByte1/CVE-2024-48246" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mpm-xvfm-qh84/GHSA-6mpm-xvfm-qh84.json b/advisories/unreviewed/2025/03/GHSA-6mpm-xvfm-qh84/GHSA-6mpm-xvfm-qh84.json index 9b1800436d6..d766a9126c5 100644 --- a/advisories/unreviewed/2025/03/GHSA-6mpm-xvfm-qh84/GHSA-6mpm-xvfm-qh84.json +++ b/advisories/unreviewed/2025/03/GHSA-6mpm-xvfm-qh84/GHSA-6mpm-xvfm-qh84.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-6mpm-xvfm-qh84", - "modified": "2025-03-05T18:32:09Z", + "modified": "2025-03-05T21:32:13Z", "published": "2025-03-05T18:32:09Z", "aliases": [ "CVE-2024-53458" ], "details": "Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53458" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/182468" + }, { "type": "WEB", "url": "https://packetstormsecurity.com/files/182468/Sysax-Multi-Server-6.99-SSH-Denial-Of-Service.html" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T18:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6v75-2jr8-rwxg/GHSA-6v75-2jr8-rwxg.json b/advisories/unreviewed/2025/03/GHSA-6v75-2jr8-rwxg/GHSA-6v75-2jr8-rwxg.json index 9694975db0d..e8d78d1f620 100644 --- a/advisories/unreviewed/2025/03/GHSA-6v75-2jr8-rwxg/GHSA-6v75-2jr8-rwxg.json +++ b/advisories/unreviewed/2025/03/GHSA-6v75-2jr8-rwxg/GHSA-6v75-2jr8-rwxg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v75-2jr8-rwxg", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:11Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27684" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-215" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-793v-gxfp-9q9h/GHSA-793v-gxfp-9q9h.json b/advisories/unreviewed/2025/03/GHSA-793v-gxfp-9q9h/GHSA-793v-gxfp-9q9h.json new file mode 100644 index 00000000000..7d322afda34 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-793v-gxfp-9q9h/GHSA-793v-gxfp-9q9h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-793v-gxfp-9q9h", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2025-25362" + ], + "details": "A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25362" + }, + { + "type": "WEB", + "url": "https://github.com/explosion/spacy-llm/issues/492" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82qh-7crj-p5wh/GHSA-82qh-7crj-p5wh.json b/advisories/unreviewed/2025/03/GHSA-82qh-7crj-p5wh/GHSA-82qh-7crj-p5wh.json index db9a78f976b..c2380571d05 100644 --- a/advisories/unreviewed/2025/03/GHSA-82qh-7crj-p5wh/GHSA-82qh-7crj-p5wh.json +++ b/advisories/unreviewed/2025/03/GHSA-82qh-7crj-p5wh/GHSA-82qh-7crj-p5wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-82qh-7crj-p5wh", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:11Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27685" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8hqq-hvx2-7hvc/GHSA-8hqq-hvx2-7hvc.json b/advisories/unreviewed/2025/03/GHSA-8hqq-hvx2-7hvc/GHSA-8hqq-hvx2-7hvc.json index 751388ed3f1..19acdadeaf2 100644 --- a/advisories/unreviewed/2025/03/GHSA-8hqq-hvx2-7hvc/GHSA-8hqq-hvx2-7hvc.json +++ b/advisories/unreviewed/2025/03/GHSA-8hqq-hvx2-7hvc/GHSA-8hqq-hvx2-7hvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8hqq-hvx2-7hvc", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27667" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumeration OVE-20230524-0011.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8xvr-2xvr-m437/GHSA-8xvr-2xvr-m437.json b/advisories/unreviewed/2025/03/GHSA-8xvr-2xvr-m437/GHSA-8xvr-2xvr-m437.json index 2cf2234a612..db610180a68 100644 --- a/advisories/unreviewed/2025/03/GHSA-8xvr-2xvr-m437/GHSA-8xvr-2xvr-m437.json +++ b/advisories/unreviewed/2025/03/GHSA-8xvr-2xvr-m437/GHSA-8xvr-2xvr-m437.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xvr-2xvr-m437", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27645" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9cf6-w6g4-wf93/GHSA-9cf6-w6g4-wf93.json b/advisories/unreviewed/2025/03/GHSA-9cf6-w6g4-wf93/GHSA-9cf6-w6g4-wf93.json index 88a54ecbb43..5537f093944 100644 --- a/advisories/unreviewed/2025/03/GHSA-9cf6-w6g4-wf93/GHSA-9cf6-w6g4-wf93.json +++ b/advisories/unreviewed/2025/03/GHSA-9cf6-w6g4-wf93/GHSA-9cf6-w6g4-wf93.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cf6-w6g4-wf93", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27646" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c22c-c436-hqcq/GHSA-c22c-c436-hqcq.json b/advisories/unreviewed/2025/03/GHSA-c22c-c436-hqcq/GHSA-c22c-c436-hqcq.json index 0c57e77c216..98b486f57e2 100644 --- a/advisories/unreviewed/2025/03/GHSA-c22c-c436-hqcq/GHSA-c22c-c436-hqcq.json +++ b/advisories/unreviewed/2025/03/GHSA-c22c-c436-hqcq/GHSA-c22c-c436-hqcq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c22c-c436-hqcq", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27648" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-2024-003.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json b/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json new file mode 100644 index 00000000000..2c71712ed2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg3h-9f75-2rjp", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2025-25632" + ], + "details": "Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25632" + }, + { + "type": "WEB", + "url": "https://github.com/Pr0b1em/IoT/blob/master/TendaAC15v15.03.05.19telnet.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cj4j-rhvm-wqq7/GHSA-cj4j-rhvm-wqq7.json b/advisories/unreviewed/2025/03/GHSA-cj4j-rhvm-wqq7/GHSA-cj4j-rhvm-wqq7.json index 516c6d72ac8..b5439ffabb1 100644 --- a/advisories/unreviewed/2025/03/GHSA-cj4j-rhvm-wqq7/GHSA-cj4j-rhvm-wqq7.json +++ b/advisories/unreviewed/2025/03/GHSA-cj4j-rhvm-wqq7/GHSA-cj4j-rhvm-wqq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj4j-rhvm-wqq7", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:11Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27683" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f84w-xq57-rqf4/GHSA-f84w-xq57-rqf4.json b/advisories/unreviewed/2025/03/GHSA-f84w-xq57-rqf4/GHSA-f84w-xq57-rqf4.json index aa9a9179913..7b3479b4e7a 100644 --- a/advisories/unreviewed/2025/03/GHSA-f84w-xq57-rqf4/GHSA-f84w-xq57-rqf4.json +++ b/advisories/unreviewed/2025/03/GHSA-f84w-xq57-rqf4/GHSA-f84w-xq57-rqf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f84w-xq57-rqf4", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:08Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27643" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:35Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json b/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json index ce582ea4272..ca74de263f1 100644 --- a/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json +++ b/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fj56-7h2j-m3p3", - "modified": "2025-03-04T18:33:44Z", + "modified": "2025-03-05T21:32:08Z", "published": "2025-03-04T18:33:44Z", "aliases": [ "CVE-2025-26182" ], "details": "An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T17:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g2m6-q89m-g82f/GHSA-g2m6-q89m-g82f.json b/advisories/unreviewed/2025/03/GHSA-g2m6-q89m-g82f/GHSA-g2m6-q89m-g82f.json index 0f1b164b4ed..832b5c9792f 100644 --- a/advisories/unreviewed/2025/03/GHSA-g2m6-q89m-g82f/GHSA-g2m6-q89m-g82f.json +++ b/advisories/unreviewed/2025/03/GHSA-g2m6-q89m-g82f/GHSA-g2m6-q89m-g82f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g2m6-q89m-g82f", - "modified": "2025-03-05T06:31:42Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27650" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gp8f-w5c5-9274/GHSA-gp8f-w5c5-9274.json b/advisories/unreviewed/2025/03/GHSA-gp8f-w5c5-9274/GHSA-gp8f-w5c5-9274.json index ed69685b09f..58b750b23ed 100644 --- a/advisories/unreviewed/2025/03/GHSA-gp8f-w5c5-9274/GHSA-gp8f-w5c5-9274.json +++ b/advisories/unreviewed/2025/03/GHSA-gp8f-w5c5-9274/GHSA-gp8f-w5c5-9274.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gp8f-w5c5-9274", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27671" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hc9m-j5rq-cphm/GHSA-hc9m-j5rq-cphm.json b/advisories/unreviewed/2025/03/GHSA-hc9m-j5rq-cphm/GHSA-hc9m-j5rq-cphm.json index b4e79eac790..06558db00a5 100644 --- a/advisories/unreviewed/2025/03/GHSA-hc9m-j5rq-cphm/GHSA-hc9m-j5rq-cphm.json +++ b/advisories/unreviewed/2025/03/GHSA-hc9m-j5rq-cphm/GHSA-hc9m-j5rq-cphm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hc9m-j5rq-cphm", - "modified": "2025-03-05T06:31:42Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27651" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-014.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hw9p-62g6-396j/GHSA-hw9p-62g6-396j.json b/advisories/unreviewed/2025/03/GHSA-hw9p-62g6-396j/GHSA-hw9p-62g6-396j.json index 39874b20a41..e477f935133 100644 --- a/advisories/unreviewed/2025/03/GHSA-hw9p-62g6-396j/GHSA-hw9p-62g6-396j.json +++ b/advisories/unreviewed/2025/03/GHSA-hw9p-62g6-396j/GHSA-hw9p-62g6-396j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9p-62g6-396j", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27672" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json b/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json new file mode 100644 index 00000000000..07a9eae7ef3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3gx-p9r2-3cwr", + "modified": "2025-03-05T21:32:12Z", + "published": "2025-03-05T21:32:12Z", + "aliases": [ + "CVE-2024-51144" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51144" + }, + { + "type": "WEB", + "url": "https://github.com/ampache/ampache" + }, + { + "type": "WEB", + "url": "https://nitipoom-jar.github.io/CVE-2024-51144" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T20:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jcv4-98x3-hrjw/GHSA-jcv4-98x3-hrjw.json b/advisories/unreviewed/2025/03/GHSA-jcv4-98x3-hrjw/GHSA-jcv4-98x3-hrjw.json index 1c5856977e3..c6f609f4cd3 100644 --- a/advisories/unreviewed/2025/03/GHSA-jcv4-98x3-hrjw/GHSA-jcv4-98x3-hrjw.json +++ b/advisories/unreviewed/2025/03/GHSA-jcv4-98x3-hrjw/GHSA-jcv4-98x3-hrjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcv4-98x3-hrjw", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27644" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:35Z" diff --git a/advisories/unreviewed/2025/03/GHSA-jp47-j92m-38q6/GHSA-jp47-j92m-38q6.json b/advisories/unreviewed/2025/03/GHSA-jp47-j92m-38q6/GHSA-jp47-j92m-38q6.json index a994610aa7f..2f251c4c1c9 100644 --- a/advisories/unreviewed/2025/03/GHSA-jp47-j92m-38q6/GHSA-jp47-j92m-38q6.json +++ b/advisories/unreviewed/2025/03/GHSA-jp47-j92m-38q6/GHSA-jp47-j92m-38q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jp47-j92m-38q6", - "modified": "2025-03-05T06:31:42Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27649" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json b/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json index 08a3ccf521c..70db8241057 100644 --- a/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json +++ b/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqm6-8ggx-r3ww", - "modified": "2025-03-03T15:31:34Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T15:31:34Z", "aliases": [ "CVE-2025-1125" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346138" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-mf3c-6mg5-67rj/GHSA-mf3c-6mg5-67rj.json b/advisories/unreviewed/2025/03/GHSA-mf3c-6mg5-67rj/GHSA-mf3c-6mg5-67rj.json index 294a9d43257..c3940b99d54 100644 --- a/advisories/unreviewed/2025/03/GHSA-mf3c-6mg5-67rj/GHSA-mf3c-6mg5-67rj.json +++ b/advisories/unreviewed/2025/03/GHSA-mf3c-6mg5-67rj/GHSA-mf3c-6mg5-67rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mf3c-6mg5-67rj", - "modified": "2025-03-05T06:31:43Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27666" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Authorization Checks OVE-20230524-0010.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json b/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json new file mode 100644 index 00000000000..5f59f23d01e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfqx-wfm8-g2h8", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2024-57174" + ], + "details": "A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57174" + }, + { + "type": "WEB", + "url": "https://chenzw.medium.com/internal-domain-names-f1cd2886c654" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/BSides-SG-2022---Internal-Domain-Names?tab=readme-ov-file#finding-1---cve-2024-57174-alphion-routers" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json b/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json new file mode 100644 index 00000000000..8c9488144fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p67q-hj2w-25v7", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2024-31525" + ], + "details": "Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31525" + }, + { + "type": "WEB", + "url": "https://github.com/Peppermint-Lab/peppermint/issues/258" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/285.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p8wr-8hg7-qcg5/GHSA-p8wr-8hg7-qcg5.json b/advisories/unreviewed/2025/03/GHSA-p8wr-8hg7-qcg5/GHSA-p8wr-8hg7-qcg5.json index e049d332cfb..901324554ba 100644 --- a/advisories/unreviewed/2025/03/GHSA-p8wr-8hg7-qcg5/GHSA-p8wr-8hg7-qcg5.json +++ b/advisories/unreviewed/2025/03/GHSA-p8wr-8hg7-qcg5/GHSA-p8wr-8hg7-qcg5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p8wr-8hg7-qcg5", - "modified": "2025-03-05T06:31:42Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27665" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Antivirus Protection and thus drivers can have known malicious code OVE-20230524-0009.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-693" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pvcg-63x2-w4px/GHSA-pvcg-63x2-w4px.json b/advisories/unreviewed/2025/03/GHSA-pvcg-63x2-w4px/GHSA-pvcg-63x2-w4px.json index b7b0c439133..a138fff8d0e 100644 --- a/advisories/unreviewed/2025/03/GHSA-pvcg-63x2-w4px/GHSA-pvcg-63x2-w4px.json +++ b/advisories/unreviewed/2025/03/GHSA-pvcg-63x2-w4px/GHSA-pvcg-63x2-w4px.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvcg-63x2-w4px", - "modified": "2025-03-05T06:31:41Z", + "modified": "2025-03-05T21:32:09Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27647" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Authentication V-2024-002.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json b/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json index 63ce2501f4c..9be7437971a 100644 --- a/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json +++ b/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7w8-q2f9-vcmh", - "modified": "2025-03-03T15:31:34Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T15:31:34Z", "aliases": [ "CVE-2025-0689" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346122" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json b/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json index ef8bbb0f994..d5e45c42d35 100644 --- a/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json +++ b/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q9q9-pv7p-h33j", - "modified": "2025-03-04T18:33:43Z", + "modified": "2025-03-05T21:32:08Z", "published": "2025-03-04T18:33:43Z", "aliases": [ "CVE-2025-26320" ], "details": "t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qfmj-8v62-hh7x/GHSA-qfmj-8v62-hh7x.json b/advisories/unreviewed/2025/03/GHSA-qfmj-8v62-hh7x/GHSA-qfmj-8v62-hh7x.json new file mode 100644 index 00000000000..2bd2432c333 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qfmj-8v62-hh7x/GHSA-qfmj-8v62-hh7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfmj-8v62-hh7x", + "modified": "2025-03-05T21:32:13Z", + "published": "2025-03-05T21:32:13Z", + "aliases": [ + "CVE-2025-2003" + ], + "details": "Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2003" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json b/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json index a2fb5fd1e66..b19b1c868c5 100644 --- a/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json +++ b/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg4m-5hg4-34vq", - "modified": "2025-03-03T15:31:34Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T15:31:34Z", "aliases": [ "CVE-2024-45779" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345854" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-rfj8-j94q-wxfj/GHSA-rfj8-j94q-wxfj.json b/advisories/unreviewed/2025/03/GHSA-rfj8-j94q-wxfj/GHSA-rfj8-j94q-wxfj.json index 33aed39ca69..c7fe83f5382 100644 --- a/advisories/unreviewed/2025/03/GHSA-rfj8-j94q-wxfj/GHSA-rfj8-j94q-wxfj.json +++ b/advisories/unreviewed/2025/03/GHSA-rfj8-j94q-wxfj/GHSA-rfj8-j94q-wxfj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rfj8-j94q-wxfj", - "modified": "2025-03-05T06:31:42Z", + "modified": "2025-03-05T21:32:10Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27652" ], "details": "Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAS V-2023-015.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T06:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rvwg-6c86-cxf4/GHSA-rvwg-6c86-cxf4.json b/advisories/unreviewed/2025/03/GHSA-rvwg-6c86-cxf4/GHSA-rvwg-6c86-cxf4.json index 3bbe46f45b0..486bcaf6e3b 100644 --- a/advisories/unreviewed/2025/03/GHSA-rvwg-6c86-cxf4/GHSA-rvwg-6c86-cxf4.json +++ b/advisories/unreviewed/2025/03/GHSA-rvwg-6c86-cxf4/GHSA-rvwg-6c86-cxf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rvwg-6c86-cxf4", - "modified": "2025-03-03T18:31:28Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2024-55570" ], "details": "/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka incorrect access control.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T16:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x536-9g45-6jcr/GHSA-x536-9g45-6jcr.json b/advisories/unreviewed/2025/03/GHSA-x536-9g45-6jcr/GHSA-x536-9g45-6jcr.json index 604fdfd2dae..818665610fd 100644 --- a/advisories/unreviewed/2025/03/GHSA-x536-9g45-6jcr/GHSA-x536-9g45-6jcr.json +++ b/advisories/unreviewed/2025/03/GHSA-x536-9g45-6jcr/GHSA-x536-9g45-6jcr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x536-9g45-6jcr", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T18:31:29Z", "aliases": [ "CVE-2023-49031" ], "details": "Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T18:15:28Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json b/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json index 8fc11e3713e..b36a363e154 100644 --- a/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json +++ b/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9h6-qwxm-528g", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-05T21:32:08Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1939" ], "details": "Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-359" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json b/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json index 30b7f8b6a42..c784a10f447 100644 --- a/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json +++ b/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxc4-h4cm-j5r2", - "modified": "2025-03-03T15:31:34Z", + "modified": "2025-03-05T21:32:07Z", "published": "2025-03-03T15:31:34Z", "aliases": [ "CVE-2024-45780" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345856" + }, + { + "type": "WEB", + "url": "https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html" } ], "database_specific": {