From 9bf57a3252acd504acbd16be32337271b546343a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 10 Jan 2025 15:32:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jg74-mwgw-v6x3.json | 6 ++- .../GHSA-5c4w-8hhh-3c3h.json | 6 ++- .../GHSA-99wr-c2px-grmh.json | 6 ++- .../GHSA-chgm-7r52-whjj.json | 6 ++- .../GHSA-g5vr-rgqm-vf78.json | 6 ++- .../GHSA-4x7q-prxg-7hxw.json | 3 +- .../GHSA-v6wm-cwm9-2486.json | 3 +- .../GHSA-hmv7-p2f3-v8fp.json | 3 +- .../GHSA-pj5g-v5v3-3c22.json | 1 + .../GHSA-2r9h-x757-8j9q.json | 6 ++- .../GHSA-34p7-67p6-m2pf.json | 6 ++- .../GHSA-g446-rqm3-4h89.json | 6 ++- .../GHSA-22mx-7hxm-5fcw.json | 6 ++- .../GHSA-28pp-6j97-mmc8.json | 6 ++- .../GHSA-2945-84q7-684p.json | 29 ++++++++++++ .../GHSA-4g53-844p-p879.json | 44 +++++++++++++++++++ .../GHSA-4mjp-wj5r-mc96.json | 44 +++++++++++++++++++ .../GHSA-4qxv-j5h7-m4jq.json | 15 +++++-- .../GHSA-4rjf-m3j3-4xh4.json | 11 +++-- .../GHSA-7429-74cp-cgh9.json | 29 ++++++++++++ .../GHSA-75gg-px33-62vq.json | 36 +++++++++++++++ .../GHSA-88m8-572v-8fjh.json | 6 ++- .../GHSA-c5jf-c5pw-3xhj.json | 36 +++++++++++++++ .../GHSA-jrrh-q8c6-fqg3.json | 11 +++-- .../GHSA-x58x-7p55-7r3g.json | 29 ++++++++++++ 25 files changed, 336 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4g53-844p-p879/GHSA-4g53-844p-p879.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4mjp-wj5r-mc96/GHSA-4mjp-wj5r-mc96.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c5jf-c5pw-3xhj/GHSA-c5jf-c5pw-3xhj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json diff --git a/advisories/github-reviewed/2024/09/GHSA-jg74-mwgw-v6x3/GHSA-jg74-mwgw-v6x3.json b/advisories/github-reviewed/2024/09/GHSA-jg74-mwgw-v6x3/GHSA-jg74-mwgw-v6x3.json index bd1d7062306..2ed2f3917b1 100644 --- a/advisories/github-reviewed/2024/09/GHSA-jg74-mwgw-v6x3/GHSA-jg74-mwgw-v6x3.json +++ b/advisories/github-reviewed/2024/09/GHSA-jg74-mwgw-v6x3/GHSA-jg74-mwgw-v6x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jg74-mwgw-v6x3", - "modified": "2024-10-09T22:20:22Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-09-26T21:31:11Z", "aliases": [ "CVE-2024-7594" @@ -55,6 +55,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-3162" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0007" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-5c4w-8hhh-3c3h/GHSA-5c4w-8hhh-3c3h.json b/advisories/github-reviewed/2024/10/GHSA-5c4w-8hhh-3c3h/GHSA-5c4w-8hhh-3c3h.json index d52085aed95..149877a596a 100644 --- a/advisories/github-reviewed/2024/10/GHSA-5c4w-8hhh-3c3h/GHSA-5c4w-8hhh-3c3h.json +++ b/advisories/github-reviewed/2024/10/GHSA-5c4w-8hhh-3c3h/GHSA-5c4w-8hhh-3c3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c4w-8hhh-3c3h", - "modified": "2024-11-08T18:56:35Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-10-31T00:30:36Z", "aliases": [ "CVE-2024-10006" @@ -63,6 +63,10 @@ { "type": "PACKAGE", "url": "https://github.com/hashicorp/consul" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0005" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-99wr-c2px-grmh/GHSA-99wr-c2px-grmh.json b/advisories/github-reviewed/2024/10/GHSA-99wr-c2px-grmh/GHSA-99wr-c2px-grmh.json index e4130bb8dd2..1866c38bb1f 100644 --- a/advisories/github-reviewed/2024/10/GHSA-99wr-c2px-grmh/GHSA-99wr-c2px-grmh.json +++ b/advisories/github-reviewed/2024/10/GHSA-99wr-c2px-grmh/GHSA-99wr-c2px-grmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99wr-c2px-grmh", - "modified": "2024-11-04T21:28:44Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-10-31T00:30:36Z", "aliases": [ "CVE-2024-10086" @@ -59,6 +59,10 @@ { "type": "PACKAGE", "url": "https://github.com/hashicorp/consul" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0006" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-chgm-7r52-whjj/GHSA-chgm-7r52-whjj.json b/advisories/github-reviewed/2024/10/GHSA-chgm-7r52-whjj/GHSA-chgm-7r52-whjj.json index 23e9b27f93c..bf5b8a34638 100644 --- a/advisories/github-reviewed/2024/10/GHSA-chgm-7r52-whjj/GHSA-chgm-7r52-whjj.json +++ b/advisories/github-reviewed/2024/10/GHSA-chgm-7r52-whjj/GHSA-chgm-7r52-whjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chgm-7r52-whjj", - "modified": "2024-11-04T21:28:32Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-10-31T00:30:36Z", "aliases": [ "CVE-2024-10005" @@ -63,6 +63,10 @@ { "type": "PACKAGE", "url": "https://github.com/hashicorp/consul" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0004" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json b/advisories/github-reviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json index 8f04ee04dad..204f72fa905 100644 --- a/advisories/github-reviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json +++ b/advisories/github-reviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5vr-rgqm-vf78", - "modified": "2024-12-19T22:35:06Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-12-19T18:31:38Z", "aliases": [ "CVE-2024-38819" @@ -75,6 +75,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-framework" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0010" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38819" diff --git a/advisories/unreviewed/2024/04/GHSA-4x7q-prxg-7hxw/GHSA-4x7q-prxg-7hxw.json b/advisories/unreviewed/2024/04/GHSA-4x7q-prxg-7hxw/GHSA-4x7q-prxg-7hxw.json index 5edf4cfd6a3..2cd81998c65 100644 --- a/advisories/unreviewed/2024/04/GHSA-4x7q-prxg-7hxw/GHSA-4x7q-prxg-7hxw.json +++ b/advisories/unreviewed/2024/04/GHSA-4x7q-prxg-7hxw/GHSA-4x7q-prxg-7hxw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-250" + "CWE-250", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json b/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json index 2be5801a610..576e39762ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json +++ b/advisories/unreviewed/2024/04/GHSA-v6wm-cwm9-2486/GHSA-v6wm-cwm9-2486.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hmv7-p2f3-v8fp/GHSA-hmv7-p2f3-v8fp.json b/advisories/unreviewed/2024/05/GHSA-hmv7-p2f3-v8fp/GHSA-hmv7-p2f3-v8fp.json index dbb7f14cf0e..bbc173ceca4 100644 --- a/advisories/unreviewed/2024/05/GHSA-hmv7-p2f3-v8fp/GHSA-hmv7-p2f3-v8fp.json +++ b/advisories/unreviewed/2024/05/GHSA-hmv7-p2f3-v8fp/GHSA-hmv7-p2f3-v8fp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json b/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json index 5ff5ebd77e0..eadabaf83fb 100644 --- a/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json +++ b/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-821" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json b/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json index 921c465135d..578f4b23187 100644 --- a/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json +++ b/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r9h-x757-8j9q", - "modified": "2024-11-25T06:34:57Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-11-14T15:32:16Z", "aliases": [ "CVE-2024-10979" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/fmora50591/postgresql-env-vuln/blob/main/README.md" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0003" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2024-10979" diff --git a/advisories/unreviewed/2024/11/GHSA-34p7-67p6-m2pf/GHSA-34p7-67p6-m2pf.json b/advisories/unreviewed/2024/11/GHSA-34p7-67p6-m2pf/GHSA-34p7-67p6-m2pf.json index 3510db8ab50..c5be0df8c8e 100644 --- a/advisories/unreviewed/2024/11/GHSA-34p7-67p6-m2pf/GHSA-34p7-67p6-m2pf.json +++ b/advisories/unreviewed/2024/11/GHSA-34p7-67p6-m2pf/GHSA-34p7-67p6-m2pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34p7-67p6-m2pf", - "modified": "2024-11-13T18:31:54Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-45289" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json b/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json index ebeab871f2c..e00a0214ec9 100644 --- a/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json +++ b/advisories/unreviewed/2024/11/GHSA-g446-rqm3-4h89/GHSA-g446-rqm3-4h89.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g446-rqm3-4h89", - "modified": "2024-11-26T21:32:22Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-39281" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250110-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json b/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json index b66f2232065..9328477ac2b 100644 --- a/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json +++ b/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22mx-7hxm-5fcw", - "modified": "2024-12-19T18:31:38Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-12-19T18:31:38Z", "aliases": [ "CVE-2024-52897" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7178086" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179151" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json b/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json index f5c334b14a8..3d74f276f96 100644 --- a/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json +++ b/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28pp-6j97-mmc8", - "modified": "2024-12-19T18:31:37Z", + "modified": "2025-01-10T15:31:33Z", "published": "2024-12-19T18:31:37Z", "aliases": [ "CVE-2024-52896" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/7178244" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179152" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json b/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json new file mode 100644 index 00000000000..f214200348d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2945-84q7-684p", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2025-22946" + ], + "details": "Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22946" + }, + { + "type": "WEB", + "url": "https://noisy-caravel-a9a.notion.site/Tenda_AC9V1-0_V15-03-05-19_formSetDeviceName_sprintf_bof-16f898c94eac8057afcbceb63fda7d24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4g53-844p-p879/GHSA-4g53-844p-p879.json b/advisories/unreviewed/2025/01/GHSA-4g53-844p-p879/GHSA-4g53-844p-p879.json new file mode 100644 index 00000000000..63d94df8db3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4g53-844p-p879/GHSA-4g53-844p-p879.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g53-844p-p879", + "modified": "2025-01-10T15:31:33Z", + "published": "2025-01-10T15:31:33Z", + "aliases": [ + "CVE-2024-57822" + ], + "details": "In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57822" + }, + { + "type": "WEB", + "url": "https://github.com/dajobe/raptor/issues/70" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896" + }, + { + "type": "WEB", + "url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4mjp-wj5r-mc96/GHSA-4mjp-wj5r-mc96.json b/advisories/unreviewed/2025/01/GHSA-4mjp-wj5r-mc96/GHSA-4mjp-wj5r-mc96.json new file mode 100644 index 00000000000..ff5901ed562 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4mjp-wj5r-mc96/GHSA-4mjp-wj5r-mc96.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mjp-wj5r-mc96", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2024-57823" + ], + "details": "In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57823" + }, + { + "type": "WEB", + "url": "https://github.com/dajobe/raptor/issues/70" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067896" + }, + { + "type": "WEB", + "url": "https://github.com/pedrib/PoC/blob/master/fuzzing/raptor-fuzz.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4qxv-j5h7-m4jq/GHSA-4qxv-j5h7-m4jq.json b/advisories/unreviewed/2025/01/GHSA-4qxv-j5h7-m4jq/GHSA-4qxv-j5h7-m4jq.json index b3ef9a1e5a8..9eeb0b58f94 100644 --- a/advisories/unreviewed/2025/01/GHSA-4qxv-j5h7-m4jq/GHSA-4qxv-j5h7-m4jq.json +++ b/advisories/unreviewed/2025/01/GHSA-4qxv-j5h7-m4jq/GHSA-4qxv-j5h7-m4jq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qxv-j5h7-m4jq", - "modified": "2025-01-10T00:30:36Z", + "modified": "2025-01-10T15:31:33Z", "published": "2025-01-10T00:30:36Z", "aliases": [ "CVE-2024-51229" ], "details": "Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T22:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json b/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json index 555a207b3f2..c2bfc3ae979 100644 --- a/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json +++ b/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rjf-m3j3-4xh4", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-10T15:31:33Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2023-35685" ], "details": "In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json b/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json new file mode 100644 index 00000000000..dae6a797133 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7429-74cp-cgh9", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2025-23022" + ], + "details": "FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23022" + }, + { + "type": "WEB", + "url": "https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json b/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json new file mode 100644 index 00000000000..f4707b34862 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-75gg-px33-62vq/GHSA-75gg-px33-62vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75gg-px33-62vq", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2024-57686" + ], + "details": "A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the \"pagetitle\" parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57686" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Land%20record/Reflected%20Cross%20Site%20Scripting.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-88m8-572v-8fjh/GHSA-88m8-572v-8fjh.json b/advisories/unreviewed/2025/01/GHSA-88m8-572v-8fjh/GHSA-88m8-572v-8fjh.json index a3b615e342e..fba17212bbc 100644 --- a/advisories/unreviewed/2025/01/GHSA-88m8-572v-8fjh/GHSA-88m8-572v-8fjh.json +++ b/advisories/unreviewed/2025/01/GHSA-88m8-572v-8fjh/GHSA-88m8-572v-8fjh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88m8-572v-8fjh", - "modified": "2025-01-09T03:30:49Z", + "modified": "2025-01-10T15:31:33Z", "published": "2025-01-09T03:30:49Z", "aliases": [ "CVE-2024-13205" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://www.websecurityinsights.my.id/2024/12/ecommerce-php-by-kurniaramadhan-sql.html?m=1" + }, + { + "type": "WEB", + "url": "https://youtu.be/YHaoqELPbBQ?si=egd2TedZ1F-i-Qae" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-c5jf-c5pw-3xhj/GHSA-c5jf-c5pw-3xhj.json b/advisories/unreviewed/2025/01/GHSA-c5jf-c5pw-3xhj/GHSA-c5jf-c5pw-3xhj.json new file mode 100644 index 00000000000..387ca858d1b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5jf-c5pw-3xhj/GHSA-c5jf-c5pw-3xhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5jf-c5pw-3xhj", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2024-41787" + ], + "details": "IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41787" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json b/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json index e359e42b22e..45744c49be9 100644 --- a/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json +++ b/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrrh-q8c6-fqg3", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T15:31:33Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13288" ], "details": "Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json b/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json new file mode 100644 index 00000000000..e5f07e12ea9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x58x-7p55-7r3g", + "modified": "2025-01-10T15:31:34Z", + "published": "2025-01-10T15:31:34Z", + "aliases": [ + "CVE-2024-57687" + ], + "details": "An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the \"Cookie\" GET request parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57687" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Land%20record/Command%20Injection.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T14:15:29Z" + } +} \ No newline at end of file