From 969a6eb93b54b96d216f3801f6b7175530cba38c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Feb 2025 00:32:41 +0000 Subject: [PATCH] Publish Advisories GHSA-6mwv-3cpw-pj8r GHSA-v5pq-9c2g-hvrv GHSA-2hhx-vp2f-m5hf GHSA-44g2-wmg5-f6v6 GHSA-6657-mm8f-wwhr GHSA-8hvg-x32p-2j7j GHSA-c649-279m-q7qv GHSA-c92g-p5cr-cr59 GHSA-cwp8-xjvj-w9x6 GHSA-f984-xmh4-jcvg GHSA-frm2-g564-fqfx GHSA-m4vh-3qj9-43jx GHSA-mp36-c9p8-hm2m GHSA-mpgh-fjjh-gjv4 GHSA-q7m5-gr49-2535 GHSA-w63g-mh88-r763 GHSA-wqvq-w4mh-vpj8 GHSA-x869-v47h-j67h GHSA-xg8w-g5cc-8wvr GHSA-xjq3-p9vw-4qrf --- .../GHSA-6mwv-3cpw-pj8r.json | 6 ++- .../GHSA-v5pq-9c2g-hvrv.json | 6 ++- .../GHSA-2hhx-vp2f-m5hf.json | 29 +++++++++++++++ .../GHSA-44g2-wmg5-f6v6.json | 29 +++++++++++++++ .../GHSA-6657-mm8f-wwhr.json | 25 +++++++++++++ .../GHSA-8hvg-x32p-2j7j.json | 37 +++++++++++++++++++ .../GHSA-c649-279m-q7qv.json | 29 +++++++++++++++ .../GHSA-c92g-p5cr-cr59.json | 15 ++++++-- .../GHSA-cwp8-xjvj-w9x6.json | 29 +++++++++++++++ .../GHSA-f984-xmh4-jcvg.json | 29 +++++++++++++++ .../GHSA-frm2-g564-fqfx.json | 29 +++++++++++++++ .../GHSA-m4vh-3qj9-43jx.json | 29 +++++++++++++++ .../GHSA-mp36-c9p8-hm2m.json | 29 +++++++++++++++ .../GHSA-mpgh-fjjh-gjv4.json | 15 ++++++-- .../GHSA-q7m5-gr49-2535.json | 29 +++++++++++++++ .../GHSA-w63g-mh88-r763.json | 29 +++++++++++++++ .../GHSA-wqvq-w4mh-vpj8.json | 29 +++++++++++++++ .../GHSA-x869-v47h-j67h.json | 29 +++++++++++++++ .../GHSA-xg8w-g5cc-8wvr.json | 29 +++++++++++++++ .../GHSA-xjq3-p9vw-4qrf.json | 29 +++++++++++++++ 20 files changed, 500 insertions(+), 10 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-44g2-wmg5-f6v6/GHSA-44g2-wmg5-f6v6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6657-mm8f-wwhr/GHSA-6657-mm8f-wwhr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8hvg-x32p-2j7j/GHSA-8hvg-x32p-2j7j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cwp8-xjvj-w9x6/GHSA-cwp8-xjvj-w9x6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f984-xmh4-jcvg/GHSA-f984-xmh4-jcvg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-frm2-g564-fqfx/GHSA-frm2-g564-fqfx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4vh-3qj9-43jx/GHSA-m4vh-3qj9-43jx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mp36-c9p8-hm2m/GHSA-mp36-c9p8-hm2m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q7m5-gr49-2535/GHSA-q7m5-gr49-2535.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wqvq-w4mh-vpj8/GHSA-wqvq-w4mh-vpj8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x869-v47h-j67h/GHSA-x869-v47h-j67h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xg8w-g5cc-8wvr/GHSA-xg8w-g5cc-8wvr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json diff --git a/advisories/unreviewed/2024/05/GHSA-6mwv-3cpw-pj8r/GHSA-6mwv-3cpw-pj8r.json b/advisories/unreviewed/2024/05/GHSA-6mwv-3cpw-pj8r/GHSA-6mwv-3cpw-pj8r.json index 00385966f7d..481c00c9d37 100644 --- a/advisories/unreviewed/2024/05/GHSA-6mwv-3cpw-pj8r/GHSA-6mwv-3cpw-pj8r.json +++ b/advisories/unreviewed/2024/05/GHSA-6mwv-3cpw-pj8r/GHSA-6mwv-3cpw-pj8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mwv-3cpw-pj8r", - "modified": "2024-05-15T21:31:26Z", + "modified": "2025-02-21T00:31:08Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4911" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-v5pq-9c2g-hvrv/GHSA-v5pq-9c2g-hvrv.json b/advisories/unreviewed/2024/05/GHSA-v5pq-9c2g-hvrv/GHSA-v5pq-9c2g-hvrv.json index 9fedf3fd25f..c60d9b40038 100644 --- a/advisories/unreviewed/2024/05/GHSA-v5pq-9c2g-hvrv/GHSA-v5pq-9c2g-hvrv.json +++ b/advisories/unreviewed/2024/05/GHSA-v5pq-9c2g-hvrv/GHSA-v5pq-9c2g-hvrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5pq-9c2g-hvrv", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T00:31:08Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4919" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json b/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json new file mode 100644 index 00000000000..4eb88d1236a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hhx-vp2f-m5hf", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25664" + ], + "details": "Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25664" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC8V4/SetIpMacBind.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-44g2-wmg5-f6v6/GHSA-44g2-wmg5-f6v6.json b/advisories/unreviewed/2025/02/GHSA-44g2-wmg5-f6v6/GHSA-44g2-wmg5-f6v6.json new file mode 100644 index 00000000000..fa307971876 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-44g2-wmg5-f6v6/GHSA-44g2-wmg5-f6v6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44g2-wmg5-f6v6", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-22973" + ], + "details": "An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22973" + }, + { + "type": "WEB", + "url": "https://github.com/202110420106/CVE/blob/master/CVE-2025-22973.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6657-mm8f-wwhr/GHSA-6657-mm8f-wwhr.json b/advisories/unreviewed/2025/02/GHSA-6657-mm8f-wwhr/GHSA-6657-mm8f-wwhr.json new file mode 100644 index 00000000000..995257f5d55 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6657-mm8f-wwhr/GHSA-6657-mm8f-wwhr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6657-mm8f-wwhr", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2024-7131" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7131" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8hvg-x32p-2j7j/GHSA-8hvg-x32p-2j7j.json b/advisories/unreviewed/2025/02/GHSA-8hvg-x32p-2j7j/GHSA-8hvg-x32p-2j7j.json new file mode 100644 index 00000000000..d8cc90bfeb8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8hvg-x32p-2j7j/GHSA-8hvg-x32p-2j7j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hvg-x32p-2j7j", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2024-54756" + ], + "details": "A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54756" + }, + { + "type": "WEB", + "url": "https://github.com/Chainmanner/GZDoom-Arbitrary-Code-Execution-via-ZScript-PoC" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2025/Feb/11" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Feb/11" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json b/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json new file mode 100644 index 00000000000..93e2d2a0b89 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c649-279m-q7qv", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25663" + ], + "details": "A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25663" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC8V4/WifiExtraSet.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c92g-p5cr-cr59/GHSA-c92g-p5cr-cr59.json b/advisories/unreviewed/2025/02/GHSA-c92g-p5cr-cr59/GHSA-c92g-p5cr-cr59.json index cdf51d5934d..f5fb9726bdb 100644 --- a/advisories/unreviewed/2025/02/GHSA-c92g-p5cr-cr59/GHSA-c92g-p5cr-cr59.json +++ b/advisories/unreviewed/2025/02/GHSA-c92g-p5cr-cr59/GHSA-c92g-p5cr-cr59.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c92g-p5cr-cr59", - "modified": "2025-02-19T00:31:19Z", + "modified": "2025-02-21T00:31:08Z", "published": "2025-02-19T00:31:19Z", "aliases": [ "CVE-2025-25473" ], "details": "FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-18T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cwp8-xjvj-w9x6/GHSA-cwp8-xjvj-w9x6.json b/advisories/unreviewed/2025/02/GHSA-cwp8-xjvj-w9x6/GHSA-cwp8-xjvj-w9x6.json new file mode 100644 index 00000000000..6183b804c42 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cwp8-xjvj-w9x6/GHSA-cwp8-xjvj-w9x6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwp8-xjvj-w9x6", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25960" + ], + "details": "Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25960" + }, + { + "type": "WEB", + "url": "https://github.com/Abel-Lan/phpcms/issues/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f984-xmh4-jcvg/GHSA-f984-xmh4-jcvg.json b/advisories/unreviewed/2025/02/GHSA-f984-xmh4-jcvg/GHSA-f984-xmh4-jcvg.json new file mode 100644 index 00000000000..2dd3794070d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f984-xmh4-jcvg/GHSA-f984-xmh4-jcvg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f984-xmh4-jcvg", + "modified": "2025-02-21T00:31:11Z", + "published": "2025-02-21T00:31:11Z", + "aliases": [ + "CVE-2025-25679" + ], + "details": "Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25679" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/i12V1/WifiMacFilterSet.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-frm2-g564-fqfx/GHSA-frm2-g564-fqfx.json b/advisories/unreviewed/2025/02/GHSA-frm2-g564-fqfx/GHSA-frm2-g564-fqfx.json new file mode 100644 index 00000000000..14b7db92dc0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-frm2-g564-fqfx/GHSA-frm2-g564-fqfx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frm2-g564-fqfx", + "modified": "2025-02-21T00:31:10Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25667" + ], + "details": "Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25667" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC8V4/saveParentControlInfo.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4vh-3qj9-43jx/GHSA-m4vh-3qj9-43jx.json b/advisories/unreviewed/2025/02/GHSA-m4vh-3qj9-43jx/GHSA-m4vh-3qj9-43jx.json new file mode 100644 index 00000000000..da7558cded8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4vh-3qj9-43jx/GHSA-m4vh-3qj9-43jx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4vh-3qj9-43jx", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25958" + ], + "details": "Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25958" + }, + { + "type": "WEB", + "url": "https://github.com/Abel-Lan/phpcms/issues/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mp36-c9p8-hm2m/GHSA-mp36-c9p8-hm2m.json b/advisories/unreviewed/2025/02/GHSA-mp36-c9p8-hm2m/GHSA-mp36-c9p8-hm2m.json new file mode 100644 index 00000000000..fea4b5d9695 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mp36-c9p8-hm2m/GHSA-mp36-c9p8-hm2m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp36-c9p8-hm2m", + "modified": "2025-02-21T00:31:10Z", + "published": "2025-02-21T00:31:10Z", + "aliases": [ + "CVE-2025-25674" + ], + "details": "Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25674" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC10V1/fast_setting_wifi_set.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mpgh-fjjh-gjv4/GHSA-mpgh-fjjh-gjv4.json b/advisories/unreviewed/2025/02/GHSA-mpgh-fjjh-gjv4/GHSA-mpgh-fjjh-gjv4.json index be10b03477f..16dfd4237fb 100644 --- a/advisories/unreviewed/2025/02/GHSA-mpgh-fjjh-gjv4/GHSA-mpgh-fjjh-gjv4.json +++ b/advisories/unreviewed/2025/02/GHSA-mpgh-fjjh-gjv4/GHSA-mpgh-fjjh-gjv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mpgh-fjjh-gjv4", - "modified": "2025-02-19T00:31:19Z", + "modified": "2025-02-21T00:31:08Z", "published": "2025-02-19T00:31:19Z", "aliases": [ "CVE-2025-25474" ], "details": "DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-18T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-q7m5-gr49-2535/GHSA-q7m5-gr49-2535.json b/advisories/unreviewed/2025/02/GHSA-q7m5-gr49-2535/GHSA-q7m5-gr49-2535.json new file mode 100644 index 00000000000..dbf1d68c449 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q7m5-gr49-2535/GHSA-q7m5-gr49-2535.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7m5-gr49-2535", + "modified": "2025-02-21T00:31:11Z", + "published": "2025-02-21T00:31:11Z", + "aliases": [ + "CVE-2025-25676" + ], + "details": "Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25676" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/i12V1/wifiSSIDget.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json b/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json new file mode 100644 index 00000000000..f7f50613ea0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w63g-mh88-r763", + "modified": "2025-02-21T00:31:11Z", + "published": "2025-02-21T00:31:11Z", + "aliases": [ + "CVE-2025-25957" + ], + "details": "Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25957" + }, + { + "type": "WEB", + "url": "https://github.com/dayrui/xunruicms/issues/5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wqvq-w4mh-vpj8/GHSA-wqvq-w4mh-vpj8.json b/advisories/unreviewed/2025/02/GHSA-wqvq-w4mh-vpj8/GHSA-wqvq-w4mh-vpj8.json new file mode 100644 index 00000000000..527f8854ef9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wqvq-w4mh-vpj8/GHSA-wqvq-w4mh-vpj8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqvq-w4mh-vpj8", + "modified": "2025-02-21T00:31:11Z", + "published": "2025-02-21T00:31:11Z", + "aliases": [ + "CVE-2025-25678" + ], + "details": "Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25678" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/i12V1/setcfm.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x869-v47h-j67h/GHSA-x869-v47h-j67h.json b/advisories/unreviewed/2025/02/GHSA-x869-v47h-j67h/GHSA-x869-v47h-j67h.json new file mode 100644 index 00000000000..97212a985e1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x869-v47h-j67h/GHSA-x869-v47h-j67h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x869-v47h-j67h", + "modified": "2025-02-21T00:31:10Z", + "published": "2025-02-21T00:31:10Z", + "aliases": [ + "CVE-2025-25668" + ], + "details": "Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25668" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC8V4/setMacFilterCfg.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xg8w-g5cc-8wvr/GHSA-xg8w-g5cc-8wvr.json b/advisories/unreviewed/2025/02/GHSA-xg8w-g5cc-8wvr/GHSA-xg8w-g5cc-8wvr.json new file mode 100644 index 00000000000..ce1284a1988 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xg8w-g5cc-8wvr/GHSA-xg8w-g5cc-8wvr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg8w-g5cc-8wvr", + "modified": "2025-02-21T00:31:09Z", + "published": "2025-02-21T00:31:09Z", + "aliases": [ + "CVE-2025-25662" + ], + "details": "Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25662" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/O4V3/setMacFilterList.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json b/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json new file mode 100644 index 00000000000..e6f46bdc673 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjq3-p9vw-4qrf", + "modified": "2025-02-21T00:31:10Z", + "published": "2025-02-21T00:31:10Z", + "aliases": [ + "CVE-2025-25675" + ], + "details": "Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25675" + }, + { + "type": "WEB", + "url": "https://github.com/jangfan/my-vuln/blob/main/Tenda/AC10V1/formexeCommand.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T23:15:12Z" + } +} \ No newline at end of file