mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jg74-mwgw-v6x3",
|
||||
"modified": "2024-10-09T22:20:22Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-09-26T21:31:11Z",
|
||||
"aliases": [
|
||||
"CVE-2024-7594"
|
||||
@@ -55,6 +55,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2024-3162"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0007"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5c4w-8hhh-3c3h",
|
||||
"modified": "2024-11-08T18:56:35Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-10-31T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10006"
|
||||
@@ -63,6 +63,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/hashicorp/consul"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0005"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-99wr-c2px-grmh",
|
||||
"modified": "2024-11-04T21:28:44Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-10-31T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10086"
|
||||
@@ -59,6 +59,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/hashicorp/consul"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0006"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-chgm-7r52-whjj",
|
||||
"modified": "2024-11-04T21:28:32Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-10-31T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10005"
|
||||
@@ -63,6 +63,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/hashicorp/consul"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0004"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g5vr-rgqm-vf78",
|
||||
"modified": "2024-12-19T22:35:06Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-12-19T18:31:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-38819"
|
||||
@@ -75,6 +75,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/spring-projects/spring-framework"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0010"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://spring.io/security/cve-2024-38819"
|
||||
|
||||
@@ -30,7 +30,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-250"
|
||||
"CWE-250",
|
||||
"CWE-639"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -30,7 +30,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-285"
|
||||
"CWE-285",
|
||||
"CWE-863"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -26,7 +26,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-284"
|
||||
"CWE-284",
|
||||
"CWE-639"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-639",
|
||||
"CWE-821"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2r9h-x757-8j9q",
|
||||
"modified": "2024-11-25T06:34:57Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-11-14T15:32:16Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10979"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/fmora50591/postgresql-env-vuln/blob/main/README.md"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.postgresql.org/support/security/CVE-2024-10979"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-34p7-67p6-m2pf",
|
||||
"modified": "2024-11-13T18:31:54Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-11-12T15:30:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-45289"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0001"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g446-rqm3-4h89",
|
||||
"modified": "2024-11-26T21:32:22Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-11-12T15:30:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-39281"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250110-0002"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-22mx-7hxm-5fcw",
|
||||
"modified": "2024-12-19T18:31:38Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-12-19T18:31:38Z",
|
||||
"aliases": [
|
||||
"CVE-2024-52897"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7178086"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7179151"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-28pp-6j97-mmc8",
|
||||
"modified": "2024-12-19T18:31:37Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2024-12-19T18:31:37Z",
|
||||
"aliases": [
|
||||
"CVE-2024-52896"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7178244"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.ibm.com/support/pages/node/7179152"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2945-84q7-684p",
|
||||
"modified": "2025-01-10T15:31:34Z",
|
||||
"published": "2025-01-10T15:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-22946"
|
||||
],
|
||||
"details": "Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22946"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://noisy-caravel-a9a.notion.site/Tenda_AC9V1-0_V15-03-05-19_formSetDeviceName_sprintf_bof-16f898c94eac8057afcbceb63fda7d24"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-10T15:15:16Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4g53-844p-p879",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2025-01-10T15:31:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-57822"
|
||||
],
|
||||
"details": "In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57822"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/dajobe/raptor/issues/70"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-10T13:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4mjp-wj5r-mc96",
|
||||
"modified": "2025-01-10T15:31:34Z",
|
||||
"published": "2025-01-10T15:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-57823"
|
||||
],
|
||||
"details": "In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57823"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/dajobe/raptor/issues/70"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-191"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-10T13:15:10Z"
|
||||
}
|
||||
}
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4qxv-j5h7-m4jq",
|
||||
"modified": "2025-01-10T00:30:36Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2025-01-10T00:30:36Z",
|
||||
"aliases": [
|
||||
"CVE-2024-51229"
|
||||
],
|
||||
"details": "Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -20,8 +25,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-09T22:15:29Z"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4rjf-m3j3-4xh4",
|
||||
"modified": "2025-01-08T18:30:48Z",
|
||||
"modified": "2025-01-10T15:31:33Z",
|
||||
"published": "2025-01-08T18:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-35685"
|
||||
],
|
||||
"details": "In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -21,7 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-08T18:15:15Z"
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7429-74cp-cgh9",
|
||||
"modified": "2025-01-10T15:31:34Z",
|
||||
"published": "2025-01-10T15:31:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-23022"
|
||||
],
|
||||
"details": "FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23022"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-01-10T15:15:16Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user