Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-01-10 15:32:54 +00:00
parent 3755833582
commit 9bf57a3252
25 changed files with 336 additions and 24 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg74-mwgw-v6x3",
"modified": "2024-10-09T22:20:22Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-09-26T21:31:11Z",
"aliases": [
"CVE-2024-7594"
@@ -55,6 +55,10 @@
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2024-3162"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0007"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5c4w-8hhh-3c3h",
"modified": "2024-11-08T18:56:35Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-10-31T00:30:36Z",
"aliases": [
"CVE-2024-10006"
@@ -63,6 +63,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/consul"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0005"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99wr-c2px-grmh",
"modified": "2024-11-04T21:28:44Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-10-31T00:30:36Z",
"aliases": [
"CVE-2024-10086"
@@ -59,6 +59,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/consul"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0006"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chgm-7r52-whjj",
"modified": "2024-11-04T21:28:32Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-10-31T00:30:36Z",
"aliases": [
"CVE-2024-10005"
@@ -63,6 +63,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/hashicorp/consul"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0004"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5vr-rgqm-vf78",
"modified": "2024-12-19T22:35:06Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-12-19T18:31:38Z",
"aliases": [
"CVE-2024-38819"
@@ -75,6 +75,10 @@
"type": "PACKAGE",
"url": "https://github.com/spring-projects/spring-framework"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0010"
},
{
"type": "WEB",
"url": "https://spring.io/security/cve-2024-38819"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-250"
"CWE-250",
"CWE-639"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285"
"CWE-285",
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-639"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-639",
"CWE-821"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r9h-x757-8j9q",
"modified": "2024-11-25T06:34:57Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-11-14T15:32:16Z",
"aliases": [
"CVE-2024-10979"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://github.com/fmora50591/postgresql-env-vuln/blob/main/README.md"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0003"
},
{
"type": "WEB",
"url": "https://www.postgresql.org/support/security/CVE-2024-10979"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34p7-67p6-m2pf",
"modified": "2024-11-13T18:31:54Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-11-12T15:30:43Z",
"aliases": [
"CVE-2024-45289"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0001"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g446-rqm3-4h89",
"modified": "2024-11-26T21:32:22Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-11-12T15:30:43Z",
"aliases": [
"CVE-2024-39281"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250110-0002"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22mx-7hxm-5fcw",
"modified": "2024-12-19T18:31:38Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-12-19T18:31:38Z",
"aliases": [
"CVE-2024-52897"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7178086"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179151"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28pp-6j97-mmc8",
"modified": "2024-12-19T18:31:37Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2024-12-19T18:31:37Z",
"aliases": [
"CVE-2024-52896"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7178244"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179152"
}
],
"database_specific": {
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2945-84q7-684p",
"modified": "2025-01-10T15:31:34Z",
"published": "2025-01-10T15:31:34Z",
"aliases": [
"CVE-2025-22946"
],
"details": "Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22946"
},
{
"type": "WEB",
"url": "https://noisy-caravel-a9a.notion.site/Tenda_AC9V1-0_V15-03-05-19_formSetDeviceName_sprintf_bof-16f898c94eac8057afcbceb63fda7d24"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-10T15:15:16Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g53-844p-p879",
"modified": "2025-01-10T15:31:33Z",
"published": "2025-01-10T15:31:33Z",
"aliases": [
"CVE-2024-57822"
],
"details": "In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57822"
},
{
"type": "WEB",
"url": "https://github.com/dajobe/raptor/issues/70"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896"
},
{
"type": "WEB",
"url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-10T13:15:09Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mjp-wj5r-mc96",
"modified": "2025-01-10T15:31:34Z",
"published": "2025-01-10T15:31:34Z",
"aliases": [
"CVE-2024-57823"
],
"details": "In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57823"
},
{
"type": "WEB",
"url": "https://github.com/dajobe/raptor/issues/70"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896"
},
{
"type": "WEB",
"url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-191"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-10T13:15:10Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qxv-j5h7-m4jq",
"modified": "2025-01-10T00:30:36Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2025-01-10T00:30:36Z",
"aliases": [
"CVE-2024-51229"
],
"details": "Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-09T22:15:29Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rjf-m3j3-4xh4",
"modified": "2025-01-08T18:30:48Z",
"modified": "2025-01-10T15:31:33Z",
"published": "2025-01-08T18:30:48Z",
"aliases": [
"CVE-2023-35685"
],
"details": "In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-08T18:15:15Z"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7429-74cp-cgh9",
"modified": "2025-01-10T15:31:34Z",
"published": "2025-01-10T15:31:34Z",
"aliases": [
"CVE-2025-23022"
],
"details": "FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23022"
},
{
"type": "WEB",
"url": "https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-10T15:15:16Z"
}
}

Some files were not shown because too many files have changed in this diff Show More