diff --git a/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json b/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json index 62c693737ad..be4d57be5f7 100644 --- a/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json +++ b/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-628r-386p-mrwh", - "modified": "2022-07-27T00:00:38Z", + "modified": "2025-01-14T18:31:46Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2488" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.204539" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1999" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-fvqw-cch9-724p/GHSA-fvqw-cch9-724p.json b/advisories/unreviewed/2023/05/GHSA-fvqw-cch9-724p/GHSA-fvqw-cch9-724p.json index 80bd58895d7..3d1e42b0651 100644 --- a/advisories/unreviewed/2023/05/GHSA-fvqw-cch9-724p/GHSA-fvqw-cch9-724p.json +++ b/advisories/unreviewed/2023/05/GHSA-fvqw-cch9-724p/GHSA-fvqw-cch9-724p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-g944-359j-5vf2/GHSA-g944-359j-5vf2.json b/advisories/unreviewed/2023/05/GHSA-g944-359j-5vf2/GHSA-g944-359j-5vf2.json index 5d44ad75b7c..dc7120afc32 100644 --- a/advisories/unreviewed/2023/05/GHSA-g944-359j-5vf2/GHSA-g944-359j-5vf2.json +++ b/advisories/unreviewed/2023/05/GHSA-g944-359j-5vf2/GHSA-g944-359j-5vf2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-gppq-ggm3-q93m/GHSA-gppq-ggm3-q93m.json b/advisories/unreviewed/2023/05/GHSA-gppq-ggm3-q93m/GHSA-gppq-ggm3-q93m.json index 832f2bd493b..49667b72814 100644 --- a/advisories/unreviewed/2023/05/GHSA-gppq-ggm3-q93m/GHSA-gppq-ggm3-q93m.json +++ b/advisories/unreviewed/2023/05/GHSA-gppq-ggm3-q93m/GHSA-gppq-ggm3-q93m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gppq-ggm3-q93m", - "modified": "2024-04-04T04:23:48Z", + "modified": "2025-01-14T18:31:49Z", "published": "2023-05-30T21:30:23Z", "aliases": [ "CVE-2023-23956" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23956" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/173038" + }, { "type": "WEB", "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/22221" diff --git a/advisories/unreviewed/2023/05/GHSA-m832-c36h-pr9r/GHSA-m832-c36h-pr9r.json b/advisories/unreviewed/2023/05/GHSA-m832-c36h-pr9r/GHSA-m832-c36h-pr9r.json index 55b145750a1..bd2e0099722 100644 --- a/advisories/unreviewed/2023/05/GHSA-m832-c36h-pr9r/GHSA-m832-c36h-pr9r.json +++ b/advisories/unreviewed/2023/05/GHSA-m832-c36h-pr9r/GHSA-m832-c36h-pr9r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-843" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-p7qh-388w-r44j/GHSA-p7qh-388w-r44j.json b/advisories/unreviewed/2023/05/GHSA-p7qh-388w-r44j/GHSA-p7qh-388w-r44j.json index c8786237a41..7c461b86b00 100644 --- a/advisories/unreviewed/2023/05/GHSA-p7qh-388w-r44j/GHSA-p7qh-388w-r44j.json +++ b/advisories/unreviewed/2023/05/GHSA-p7qh-388w-r44j/GHSA-p7qh-388w-r44j.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/05/GHSA-rhhm-9xfq-x5qf/GHSA-rhhm-9xfq-x5qf.json b/advisories/unreviewed/2023/05/GHSA-rhhm-9xfq-x5qf/GHSA-rhhm-9xfq-x5qf.json index 00be3f57467..f5ab399a512 100644 --- a/advisories/unreviewed/2023/05/GHSA-rhhm-9xfq-x5qf/GHSA-rhhm-9xfq-x5qf.json +++ b/advisories/unreviewed/2023/05/GHSA-rhhm-9xfq-x5qf/GHSA-rhhm-9xfq-x5qf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-252r-cvww-g3vf/GHSA-252r-cvww-g3vf.json b/advisories/unreviewed/2024/03/GHSA-252r-cvww-g3vf/GHSA-252r-cvww-g3vf.json index 997d76894fe..bab8c0c8521 100644 --- a/advisories/unreviewed/2024/03/GHSA-252r-cvww-g3vf/GHSA-252r-cvww-g3vf.json +++ b/advisories/unreviewed/2024/03/GHSA-252r-cvww-g3vf/GHSA-252r-cvww-g3vf.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-2pv7-ppmq-phqc/GHSA-2pv7-ppmq-phqc.json b/advisories/unreviewed/2024/03/GHSA-2pv7-ppmq-phqc/GHSA-2pv7-ppmq-phqc.json index 7fb339c26f3..0994c888cee 100644 --- a/advisories/unreviewed/2024/03/GHSA-2pv7-ppmq-phqc/GHSA-2pv7-ppmq-phqc.json +++ b/advisories/unreviewed/2024/03/GHSA-2pv7-ppmq-phqc/GHSA-2pv7-ppmq-phqc.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-6j89-jrg7-jp74/GHSA-6j89-jrg7-jp74.json b/advisories/unreviewed/2024/03/GHSA-6j89-jrg7-jp74/GHSA-6j89-jrg7-jp74.json index 376b07f2454..237afa56241 100644 --- a/advisories/unreviewed/2024/03/GHSA-6j89-jrg7-jp74/GHSA-6j89-jrg7-jp74.json +++ b/advisories/unreviewed/2024/03/GHSA-6j89-jrg7-jp74/GHSA-6j89-jrg7-jp74.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9p7q-wmmc-3rgf/GHSA-9p7q-wmmc-3rgf.json b/advisories/unreviewed/2024/03/GHSA-9p7q-wmmc-3rgf/GHSA-9p7q-wmmc-3rgf.json index 0c40121aef1..e4b0a25f25f 100644 --- a/advisories/unreviewed/2024/03/GHSA-9p7q-wmmc-3rgf/GHSA-9p7q-wmmc-3rgf.json +++ b/advisories/unreviewed/2024/03/GHSA-9p7q-wmmc-3rgf/GHSA-9p7q-wmmc-3rgf.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g8fc-h787-jhv2/GHSA-g8fc-h787-jhv2.json b/advisories/unreviewed/2024/03/GHSA-g8fc-h787-jhv2/GHSA-g8fc-h787-jhv2.json index 25f6a6d18c7..af0f25a0ace 100644 --- a/advisories/unreviewed/2024/03/GHSA-g8fc-h787-jhv2/GHSA-g8fc-h787-jhv2.json +++ b/advisories/unreviewed/2024/03/GHSA-g8fc-h787-jhv2/GHSA-g8fc-h787-jhv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g8fc-h787-jhv2", - "modified": "2024-03-04T18:30:38Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-03-04T18:30:38Z", "aliases": [ "CVE-2021-47093" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel_pmc_core: fix memleak on registration failure\n\nIn case device registration fails during module initialisation, the\nplatform device structure needs to be freed using platform_device_put()\nto properly free all resources (e.g. the device name).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gmwj-428v-53wv/GHSA-gmwj-428v-53wv.json b/advisories/unreviewed/2024/03/GHSA-gmwj-428v-53wv/GHSA-gmwj-428v-53wv.json index 1a3464624e1..645062ebca6 100644 --- a/advisories/unreviewed/2024/03/GHSA-gmwj-428v-53wv/GHSA-gmwj-428v-53wv.json +++ b/advisories/unreviewed/2024/03/GHSA-gmwj-428v-53wv/GHSA-gmwj-428v-53wv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gmwj-428v-53wv", - "modified": "2024-03-04T21:31:11Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-03-04T21:31:11Z", "aliases": [ "CVE-2021-47106" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix use-after-free in nft_set_catchall_destroy()\n\nWe need to use list_for_each_entry_safe() iterator\nbecause we can not access @catchall after kfree_rcu() call.\n\nsyzbot reported:\n\nBUG: KASAN: use-after-free in nft_set_catchall_destroy net/netfilter/nf_tables_api.c:4486 [inline]\nBUG: KASAN: use-after-free in nft_set_destroy net/netfilter/nf_tables_api.c:4504 [inline]\nBUG: KASAN: use-after-free in nft_set_destroy+0x3fd/0x4f0 net/netfilter/nf_tables_api.c:4493\nRead of size 8 at addr ffff8880716e5b80 by task syz-executor.3/8871\n\nCPU: 1 PID: 8871 Comm: syz-executor.3 Not tainted 5.16.0-rc5-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x2ed mm/kasan/report.c:247\n __kasan_report mm/kasan/report.c:433 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:450\n nft_set_catchall_destroy net/netfilter/nf_tables_api.c:4486 [inline]\n nft_set_destroy net/netfilter/nf_tables_api.c:4504 [inline]\n nft_set_destroy+0x3fd/0x4f0 net/netfilter/nf_tables_api.c:4493\n __nft_release_table+0x79f/0xcd0 net/netfilter/nf_tables_api.c:9626\n nft_rcv_nl_event+0x4f8/0x670 net/netfilter/nf_tables_api.c:9688\n notifier_call_chain+0xb5/0x200 kernel/notifier.c:83\n blocking_notifier_call_chain kernel/notifier.c:318 [inline]\n blocking_notifier_call_chain+0x67/0x90 kernel/notifier.c:306\n netlink_release+0xcb6/0x1dd0 net/netlink/af_netlink.c:788\n __sock_release+0xcd/0x280 net/socket.c:649\n sock_close+0x18/0x20 net/socket.c:1314\n __fput+0x286/0x9f0 fs/file_table.c:280\n task_work_run+0xdd/0x1a0 kernel/task_work.c:164\n tracehook_notify_resume include/linux/tracehook.h:189 [inline]\n exit_to_user_mode_loop kernel/entry/common.c:175 [inline]\n exit_to_user_mode_prepare+0x27e/0x290 kernel/entry/common.c:207\n __syscall_exit_to_user_mode_work kernel/entry/common.c:289 [inline]\n syscall_exit_to_user_mode+0x19/0x60 kernel/entry/common.c:300\n do_syscall_64+0x42/0xb0 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f75fbf28adb\nCode: 0f 05 48 3d 00 f0 ff ff 77 45 c3 0f 1f 40 00 48 83 ec 18 89 7c 24 0c e8 63 fc ff ff 8b 7c 24 0c 41 89 c0 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 35 44 89 c7 89 44 24 0c e8 a1 fc ff ff 8b 44\nRSP: 002b:00007ffd8da7ec10 EFLAGS: 00000293 ORIG_RAX: 0000000000000003\nRAX: 0000000000000000 RBX: 0000000000000004 RCX: 00007f75fbf28adb\nRDX: 00007f75fc08e828 RSI: ffffffffffffffff RDI: 0000000000000003\nRBP: 00007f75fc08a960 R08: 0000000000000000 R09: 00007f75fc08e830\nR10: 00007ffd8da7ed10 R11: 0000000000000293 R12: 00000000002067c3\nR13: 00007ffd8da7ed10 R14: 00007f75fc088f60 R15: 0000000000000032\n \n\nAllocated by task 8886:\n kasan_save_stack+0x1e/0x50 mm/kasan/common.c:38\n kasan_set_track mm/kasan/common.c:46 [inline]\n set_alloc_info mm/kasan/common.c:434 [inline]\n ____kasan_kmalloc mm/kasan/common.c:513 [inline]\n ____kasan_kmalloc mm/kasan/common.c:472 [inline]\n __kasan_kmalloc+0xa6/0xd0 mm/kasan/common.c:522\n kasan_kmalloc include/linux/kasan.h:269 [inline]\n kmem_cache_alloc_trace+0x1ea/0x4a0 mm/slab.c:3575\n kmalloc include/linux/slab.h:590 [inline]\n nft_setelem_catchall_insert net/netfilter/nf_tables_api.c:5544 [inline]\n nft_setelem_insert net/netfilter/nf_tables_api.c:5562 [inline]\n nft_add_set_elem+0x232e/0x2f40 net/netfilter/nf_tables_api.c:5936\n nf_tables_newsetelem+0x6ff/0xbb0 net/netfilter/nf_tables_api.c:6032\n nfnetlink_rcv_batch+0x1710/0x25f0 net/netfilter/nfnetlink.c:513\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:634 [inline]\n nfnetlink_rcv+0x3af/0x420 net/netfilter/nfnetlink.c:652\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x904/0xdf0 net/netlink/af_netlink.c:1921\n sock_sendmsg_nosec net/\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T19:15:18Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json index 2810efe457d..ec4f1f2c799 100644 --- a/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json +++ b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6m7r-j2xg-cvhq", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26704" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only discards orig_inode and donor_inode\npreallocations when moved_len is not zero. When the loop fails to exit\nafter successfully moving some extents, moved_len is not updated and\nremains at 0, so it does not discard the preallocations.\n\nIf the moved extents overlap with the preallocated extents, the\noverlapped extents are freed twice in ext4_mb_release_inode_pa() and\next4_process_freed_data() (as described in commit 94d7c16cbbbd (\"ext4:\nFix double-free of blocks with EXT4_IOC_MOVE_EXT\")), and bb_free is\nincremented twice. Hence when trim is executed, a zero-division bug is\ntriggered in mb_update_avg_fragment_size() because bb_free is not zero\nand bb_fragments is zero.\n\nTherefore, update move_len after each extent move to avoid the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json b/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json index d18d658332b..33260b024c8 100644 --- a/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json +++ b/advisories/unreviewed/2024/04/GHSA-7257-c3g3-gcf6/GHSA-7257-c3g3-gcf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7257-c3g3-gcf6", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable()\n\n ...\n cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request);\n list_del_init(&priv_req->list);\n ...\n\n'priv_req' actually free at cdns3_gadget_ep_free_request(). But\nlist_del_init() use priv_req->list after it.\n\n[ 1542.642868][ T534] BUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xd4\n[ 1542.642868][ T534]\n[ 1542.653162][ T534] Use-after-free read at 0x000000009ed0ba99 (in kfence-#3):\n[ 1542.660311][ T534] __list_del_entry_valid+0x10/0xd4\n[ 1542.665375][ T534] cdns3_gadget_ep_disable+0x1f8/0x388 [cdns3]\n[ 1542.671571][ T534] usb_ep_disable+0x44/0xe4\n[ 1542.675948][ T534] ffs_func_eps_disable+0x64/0xc8\n[ 1542.680839][ T534] ffs_func_set_alt+0x74/0x368\n[ 1542.685478][ T534] ffs_func_disable+0x18/0x28\n\nMove list_del_init() before cdns3_gadget_ep_free_request() to resolve this\nproblem.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json index f77934a79b9..04e6fc1ec69 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json +++ b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7pq6-8v5c-6wmr", - "modified": "2024-04-03T15:30:41Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-01T09:30:31Z", "aliases": [ "CVE-2024-26653" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: ljca: Fix double free in error handling path\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function ljca_auxdev_release\ncalls kfree(auxdev->dev.platform_data) to free the parameter data\nof the function ljca_new_client_device. The callers of\nljca_new_client_device shouldn't call kfree() again\nin the error handling path to free the platform data.\n\nFix this by cleaning up the redundant kfree() in all callers and\nadding kfree() the passed in platform_data on errors which happen\nbefore auxiliary_device_init() succeeds .", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T09:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json b/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json index 3b32a7374b2..a3307c1f510 100644 --- a/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json +++ b/advisories/unreviewed/2024/04/GHSA-825r-gh5g-48mg/GHSA-825r-gh5g-48mg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-825r-gh5g-48mg", - "modified": "2024-06-25T21:31:12Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: fix memory double free when handle zero packet\n\n829 if (request->complete) {\n830 spin_unlock(&priv_dev->lock);\n831 usb_gadget_giveback_request(&priv_ep->endpoint,\n832 request);\n833 spin_lock(&priv_dev->lock);\n834 }\n835\n836 if (request->buf == priv_dev->zlp_buf)\n837 cdns3_gadget_ep_free_request(&priv_ep->endpoint, request);\n\nDriver append an additional zero packet request when queue a packet, which\nlength mod max packet size is 0. When transfer complete, run to line 831,\nusb_gadget_giveback_request() will free this requestion. 836 condition is\ntrue, so cdns3_gadget_ep_free_request() free this request again.\n\nLog:\n\n[ 1920.140696][ T150] BUG: KFENCE: use-after-free read in cdns3_gadget_giveback+0x134/0x2c0 [cdns3]\n[ 1920.140696][ T150]\n[ 1920.151837][ T150] Use-after-free read at 0x000000003d1cd10b (in kfence-#36):\n[ 1920.159082][ T150] cdns3_gadget_giveback+0x134/0x2c0 [cdns3]\n[ 1920.164988][ T150] cdns3_transfer_completed+0x438/0x5f8 [cdns3]\n\nAdd check at line 829, skip call usb_gadget_giveback_request() if it is\nadditional zero length packet request. Needn't call\nusb_gadget_giveback_request() because it is allocated in this driver.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-84hw-www5-5v7p/GHSA-84hw-www5-5v7p.json b/advisories/unreviewed/2024/04/GHSA-84hw-www5-5v7p/GHSA-84hw-www5-5v7p.json index aced0ed1400..aeb58250c5b 100644 --- a/advisories/unreviewed/2024/04/GHSA-84hw-www5-5v7p/GHSA-84hw-www5-5v7p.json +++ b/advisories/unreviewed/2024/04/GHSA-84hw-www5-5v7p/GHSA-84hw-www5-5v7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-84hw-www5-5v7p", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26734" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndevlink: fix possible use-after-free and memory leaks in devlink_init()\n\nThe pernet operations structure for the subsystem must be registered\nbefore registering the generic netlink family.\n\nMake an unregister in case of unsuccessful registration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json index 356e7afd60b..aa4f1b35fb1 100644 --- a/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json +++ b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9xp8-8c5r-6wfh", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: prevent use-after-free in encode_cap_msg()\n\nIn fs/ceph/caps.c, in encode_cap_msg(), \"use after free\" error was\ncaught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This\nimplies before the refcount could be increment here, it was freed.\n\nIn same file, in \"handle_cap_grant()\" refcount is decremented by this\nline - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race\noccurred and resource was freed by the latter line before the former\nline could increment it.\n\nencode_cap_msg() is called by __send_cap() and __send_cap() is called by\nceph_check_caps() after calling __prep_cap(). __prep_cap() is where\narg->xattr_buf is assigned to ci->i_xattrs.blob. This is the spot where\nthe refcount must be increased to prevent \"use after free\" error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f79p-pc32-pmjw/GHSA-f79p-pc32-pmjw.json b/advisories/unreviewed/2024/04/GHSA-f79p-pc32-pmjw/GHSA-f79p-pc32-pmjw.json index 5e7d07e365b..2ea8e03f138 100644 --- a/advisories/unreviewed/2024/04/GHSA-f79p-pc32-pmjw/GHSA-f79p-pc32-pmjw.json +++ b/advisories/unreviewed/2024/04/GHSA-f79p-pc32-pmjw/GHSA-f79p-pc32-pmjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f79p-pc32-pmjw", - "modified": "2024-04-10T21:30:30Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-10T21:30:30Z", "aliases": [ "CVE-2021-47184" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix NULL ptr dereference on VSI filter sync\n\nRemove the reason of null pointer dereference in sync VSI filters.\nAdded new I40E_VSI_RELEASING flag to signalize deleting and releasing\nof VSI resources to sync this thread with sync filters subtask.\nWithout this patch it is possible to start update the VSI filter list\nafter VSI is removed, that's causing a kernel oops.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q4cm-jgpj-qg42/GHSA-q4cm-jgpj-qg42.json b/advisories/unreviewed/2024/04/GHSA-q4cm-jgpj-qg42/GHSA-q4cm-jgpj-qg42.json index a9dbc6cb7c6..ca01d612256 100644 --- a/advisories/unreviewed/2024/04/GHSA-q4cm-jgpj-qg42/GHSA-q4cm-jgpj-qg42.json +++ b/advisories/unreviewed/2024/04/GHSA-q4cm-jgpj-qg42/GHSA-q4cm-jgpj-qg42.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4cm-jgpj-qg42", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47191" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix out-of-bound read in resp_readcap16()\n\nThe following warning was observed running syzkaller:\n\n[ 3813.830724] sg_write: data in/out 65466/242 bytes for SCSI command 0x9e-- guessing data in;\n[ 3813.830724] program syz-executor not setting count and/or reply_len properly\n[ 3813.836956] ==================================================================\n[ 3813.839465] BUG: KASAN: stack-out-of-bounds in sg_copy_buffer+0x157/0x1e0\n[ 3813.841773] Read of size 4096 at addr ffff8883cf80f540 by task syz-executor/1549\n[ 3813.846612] Call Trace:\n[ 3813.846995] dump_stack+0x108/0x15f\n[ 3813.847524] print_address_description+0xa5/0x372\n[ 3813.848243] kasan_report.cold+0x236/0x2a8\n[ 3813.849439] check_memory_region+0x240/0x270\n[ 3813.850094] memcpy+0x30/0x80\n[ 3813.850553] sg_copy_buffer+0x157/0x1e0\n[ 3813.853032] sg_copy_from_buffer+0x13/0x20\n[ 3813.853660] fill_from_dev_buffer+0x135/0x370\n[ 3813.854329] resp_readcap16+0x1ac/0x280\n[ 3813.856917] schedule_resp+0x41f/0x1630\n[ 3813.858203] scsi_debug_queuecommand+0xb32/0x17e0\n[ 3813.862699] scsi_dispatch_cmd+0x330/0x950\n[ 3813.863329] scsi_request_fn+0xd8e/0x1710\n[ 3813.863946] __blk_run_queue+0x10b/0x230\n[ 3813.864544] blk_execute_rq_nowait+0x1d8/0x400\n[ 3813.865220] sg_common_write.isra.0+0xe61/0x2420\n[ 3813.871637] sg_write+0x6c8/0xef0\n[ 3813.878853] __vfs_write+0xe4/0x800\n[ 3813.883487] vfs_write+0x17b/0x530\n[ 3813.884008] ksys_write+0x103/0x270\n[ 3813.886268] __x64_sys_write+0x77/0xc0\n[ 3813.886841] do_syscall_64+0x106/0x360\n[ 3813.887415] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nThis issue can be reproduced with the following syzkaller log:\n\nr0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\\x00', 0x26e1, 0x0)\nr1 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000000)='fd/3\\x00')\nopen_by_handle_at(r1, &(0x7f00000003c0)=ANY=[@ANYRESHEX], 0x602000)\nr2 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x40782)\nwrite$binfmt_aout(r2, &(0x7f0000000340)=ANY=[@ANYBLOB=\"00000000deff000000000000000000000000000000000000000000000000000047f007af9e107a41ec395f1bded7be24277a1501ff6196a83366f4e6362bc0ff2b247f68a972989b094b2da4fb3607fcf611a22dd04310d28c75039d\"], 0x126)\n\nIn resp_readcap16() we get \"int alloc_len\" value -1104926854, and then pass\nthe huge arr_len to fill_from_dev_buffer(), but arr is only 32 bytes. This\nleads to OOB in sg_copy_buffer().\n\nTo solve this issue, define alloc_len as u32.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q54v-653w-2v9v/GHSA-q54v-653w-2v9v.json b/advisories/unreviewed/2024/04/GHSA-q54v-653w-2v9v/GHSA-q54v-653w-2v9v.json index 888d781a12d..47422ec6812 100644 --- a/advisories/unreviewed/2024/04/GHSA-q54v-653w-2v9v/GHSA-q54v-653w-2v9v.json +++ b/advisories/unreviewed/2024/04/GHSA-q54v-653w-2v9v/GHSA-q54v-653w-2v9v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q54v-653w-2v9v", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47199" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: CT, Fix multiple allocations and memleak of mod acts\n\nCT clear action offload adds additional mod hdr actions to the\nflow's original mod actions in order to clear the registers which\nhold ct_state.\nWhen such flow also includes encap action, a neigh update event\ncan cause the driver to unoffload the flow and then reoffload it.\n\nEach time this happens, the ct clear handling adds that same set\nof mod hdr actions to reset ct_state until the max of mod hdr\nactions is reached.\n\nAlso the driver never releases the allocated mod hdr actions and\ncausing a memleak.\n\nFix above two issues by moving CT clear mod acts allocation\ninto the parsing actions phase and only use it when offloading the rule.\nThe release of mod acts will be done in the normal flow_put().\n\n backtrace:\n [<000000007316e2f3>] krealloc+0x83/0xd0\n [<00000000ef157de1>] mlx5e_mod_hdr_alloc+0x147/0x300 [mlx5_core]\n [<00000000970ce4ae>] mlx5e_tc_match_to_reg_set_and_get_id+0xd7/0x240 [mlx5_core]\n [<0000000067c5fa17>] mlx5e_tc_match_to_reg_set+0xa/0x20 [mlx5_core]\n [<00000000d032eb98>] mlx5_tc_ct_entry_set_registers.isra.0+0x36/0xc0 [mlx5_core]\n [<00000000fd23b869>] mlx5_tc_ct_flow_offload+0x272/0x1f10 [mlx5_core]\n [<000000004fc24acc>] mlx5e_tc_offload_fdb_rules.part.0+0x150/0x620 [mlx5_core]\n [<00000000dc741c17>] mlx5e_tc_encap_flows_add+0x489/0x690 [mlx5_core]\n [<00000000e92e49d7>] mlx5e_rep_update_flows+0x6e4/0x9b0 [mlx5_core]\n [<00000000f60f5602>] mlx5e_rep_neigh_update+0x39a/0x5d0 [mlx5_core]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json b/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json index 3ef26ec7ff3..71f1e5cc3f8 100644 --- a/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json +++ b/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r2x-3jh4-chhv", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47455" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: Fix possible memory leak in ptp_clock_register()\n\nI got memory leak as follows when doing fault injection test:\n\nunreferenced object 0xffff88800906c618 (size 8):\n comm \"i2c-idt82p33931\", pid 4421, jiffies 4294948083 (age 13.188s)\n hex dump (first 8 bytes):\n 70 74 70 30 00 00 00 00 ptp0....\n backtrace:\n [<00000000312ed458>] __kmalloc_track_caller+0x19f/0x3a0\n [<0000000079f6e2ff>] kvasprintf+0xb5/0x150\n [<0000000026aae54f>] kvasprintf_const+0x60/0x190\n [<00000000f323a5f7>] kobject_set_name_vargs+0x56/0x150\n [<000000004e35abdd>] dev_set_name+0xc0/0x100\n [<00000000f20cfe25>] ptp_clock_register+0x9f4/0xd30 [ptp]\n [<000000008bb9f0de>] idt82p33_probe.cold+0x8b6/0x1561 [ptp_idt82p33]\n\nWhen posix_clock_register() returns an error, the name allocated\nin dev_set_name() will be leaked, the put_device() should be used\nto give up the device reference, then the name will be freed in\nkobject_cleanup() and other memory will be freed in ptp_clock_release().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json b/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json index da057082087..6cdfdf9880d 100644 --- a/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json +++ b/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f2f-22g2-g2gq", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52863" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (axi-fan-control) Fix possible NULL pointer dereference\n\naxi_fan_control_irq_handler(), dependent on the private\naxi_fan_control_data structure, might be called before the hwmon\ndevice is registered. That will cause an \"Unable to handle kernel\nNULL pointer dereference\" error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json b/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json index f86c178fefa..6aa53a1fef1 100644 --- a/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json +++ b/advisories/unreviewed/2024/05/GHSA-72f9-x2qq-3795/GHSA-72f9-x2qq-3795.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-72f9-x2qq-3795", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52859" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: hisi: Fix use-after-free when register pmu fails\n\nWhen we fail to register the uncore pmu, the pmu context may not been\nallocated. The error handing will call cpuhp_state_remove_instance()\nto call uncore pmu offline callback, which migrate the pmu context.\nSince that's liable to lead to some kind of use-after-free.\n\nUse cpuhp_state_remove_instance_nocalls() instead of\ncpuhp_state_remove_instance() so that the notifiers don't execute after\nthe PMU device has been failed to register.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7h3c-w5w5-q4p8/GHSA-7h3c-w5w5-q4p8.json b/advisories/unreviewed/2024/05/GHSA-7h3c-w5w5-q4p8/GHSA-7h3c-w5w5-q4p8.json index abe073ac90f..8c1ef48cf8e 100644 --- a/advisories/unreviewed/2024/05/GHSA-7h3c-w5w5-q4p8/GHSA-7h3c-w5w5-q4p8.json +++ b/advisories/unreviewed/2024/05/GHSA-7h3c-w5w5-q4p8/GHSA-7h3c-w5w5-q4p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7h3c-w5w5-q4p8", - "modified": "2024-05-20T12:30:29Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35975" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Fix transmit scheduler resource leak\n\nInorder to support shaping and scheduling, Upon class creation\nNetdev driver allocates trasmit schedulers.\n\nThe previous patch which added support for Round robin scheduling has\na bug due to which driver is not freeing transmit schedulers post\nclass deletion.\n\nThis patch fixes the same.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json b/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json index 0257e1aa87d..6cc81cdff6f 100644 --- a/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json +++ b/advisories/unreviewed/2024/05/GHSA-7prj-h6r4-gh9j/GHSA-7prj-h6r4-gh9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7prj-h6r4-gh9j", - "modified": "2024-05-21T18:31:21Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52785" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix racing issue between ufshcd_mcq_abort() and ISR\n\nIf command timeout happens and cq complete IRQ is raised at the same time,\nufshcd_mcq_abort clears lprb->cmd and a NULL pointer deref happens in the\nISR. Error log:\n\nufshcd_abort: Device abort task at tag 18\nUnable to handle kernel NULL pointer dereference at virtual address\n0000000000000108\npc : [0xffffffe27ef867ac] scsi_dma_unmap+0xc/0x44\nlr : [0xffffffe27f1b898c] ufshcd_release_scsi_cmd+0x24/0x114", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json b/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json index d0305871e31..c18df3a9824 100644 --- a/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json +++ b/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xq6-r35j-j33m", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47459" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv\n\nIt will trigger UAF for rx_kref of j1939_priv as following.\n\n cpu0 cpu1\nj1939_sk_bind(socket0, ndev0, ...)\nj1939_netdev_start\n j1939_sk_bind(socket1, ndev0, ...)\n j1939_netdev_start\nj1939_priv_set\n j1939_priv_get_by_ndev_locked\nj1939_jsk_add\n.....\nj1939_netdev_stop\nkref_put_lock(&priv->rx_kref, ...)\n kref_get(&priv->rx_kref, ...)\n REFCOUNT_WARN(\"addition on 0;...\")\n\n====================================================\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 1 PID: 20874 at lib/refcount.c:25 refcount_warn_saturate+0x169/0x1e0\nRIP: 0010:refcount_warn_saturate+0x169/0x1e0\nCall Trace:\n j1939_netdev_start+0x68b/0x920\n j1939_sk_bind+0x426/0xeb0\n ? security_socket_bind+0x83/0xb0\n\nThe rx_kref's kref_get() and kref_put() should use j1939_netdev_lock to\nprotect.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json b/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json index b7486cb3de6..19989274a66 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json +++ b/advisories/unreviewed/2024/05/GHSA-8r5m-pqvh-q2vm/GHSA-8r5m-pqvh-q2vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8r5m-pqvh-q2vm", - "modified": "2024-05-21T18:31:21Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52808" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Set debugfs_dir pointer to NULL after removing debugfs\n\nIf init debugfs failed during device registration due to memory allocation\nfailure, debugfs_remove_recursive() is called, after which debugfs_dir is\nnot set to NULL. debugfs_remove_recursive() will be called again during\ndevice removal. As a result, illegal pointer is accessed.\n\n[ 1665.467244] hisi_sas_v3_hw 0000:b4:02.0: failed to init debugfs!\n...\n[ 1669.836708] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0\n[ 1669.872669] pc : down_write+0x24/0x70\n[ 1669.876315] lr : down_write+0x1c/0x70\n[ 1669.879961] sp : ffff000036f53a30\n[ 1669.883260] x29: ffff000036f53a30 x28: ffffa027c31549f8\n[ 1669.888547] x27: ffffa027c3140000 x26: 0000000000000000\n[ 1669.893834] x25: ffffa027bf37c270 x24: ffffa027bf37c270\n[ 1669.899122] x23: ffff0000095406b8 x22: ffff0000095406a8\n[ 1669.904408] x21: 0000000000000000 x20: ffffa027bf37c310\n[ 1669.909695] x19: 00000000000000a0 x18: ffff8027dcd86f10\n[ 1669.914982] x17: 0000000000000000 x16: 0000000000000000\n[ 1669.920268] x15: 0000000000000000 x14: ffffa0274014f870\n[ 1669.925555] x13: 0000000000000040 x12: 0000000000000228\n[ 1669.930842] x11: 0000000000000020 x10: 0000000000000bb0\n[ 1669.936129] x9 : ffff000036f537f0 x8 : ffff80273088ca10\n[ 1669.941416] x7 : 000000000000001d x6 : 00000000ffffffff\n[ 1669.946702] x5 : ffff000008a36310 x4 : ffff80273088be00\n[ 1669.951989] x3 : ffff000009513e90 x2 : 0000000000000000\n[ 1669.957276] x1 : 00000000000000a0 x0 : ffffffff00000001\n[ 1669.962563] Call trace:\n[ 1669.965000] down_write+0x24/0x70\n[ 1669.968301] debugfs_remove_recursive+0x5c/0x1b0\n[ 1669.972905] hisi_sas_debugfs_exit+0x24/0x30 [hisi_sas_main]\n[ 1669.978541] hisi_sas_v3_remove+0x130/0x150 [hisi_sas_v3_hw]\n[ 1669.984175] pci_device_remove+0x48/0xd8\n[ 1669.988082] device_release_driver_internal+0x1b4/0x250\n[ 1669.993282] device_release_driver+0x28/0x38\n[ 1669.997534] pci_stop_bus_device+0x84/0xb8\n[ 1670.001611] pci_stop_and_remove_bus_device_locked+0x24/0x40\n[ 1670.007244] remove_store+0xfc/0x140\n[ 1670.010802] dev_attr_store+0x44/0x60\n[ 1670.014448] sysfs_kf_write+0x58/0x80\n[ 1670.018095] kernfs_fop_write+0xe8/0x1f0\n[ 1670.022000] __vfs_write+0x60/0x190\n[ 1670.025472] vfs_write+0xac/0x1c0\n[ 1670.028771] ksys_write+0x6c/0xd8\n[ 1670.032071] __arm64_sys_write+0x24/0x30\n[ 1670.035977] el0_svc_common+0x78/0x130\n[ 1670.039710] el0_svc_handler+0x38/0x78\n[ 1670.043442] el0_svc+0x8/0xc\n\nTo fix this, set debugfs_dir to NULL after debugfs_remove_recursive().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:19Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json b/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json index ebcd3b8b33f..1b0c2f8c85f 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json +++ b/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7rf-8xcx-vfgm", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52865" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json b/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json index 9a7436208e4..ff706bf2eee 100644 --- a/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json +++ b/advisories/unreviewed/2024/05/GHSA-gcw5-rpqg-f587/GHSA-gcw5-rpqg-f587.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gcw5-rpqg-f587", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52777" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix gtk offload status event locking\n\nThe ath11k active pdevs are protected by RCU but the gtk offload status\nevent handling code calling ath11k_mac_get_arvif_by_vdev_id() was not\nmarked as a read-side critical section.\n\nMark the code in question as an RCU read-side critical section to avoid\nany potential use-after-free issues.\n\nCompile tested only.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json b/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json index 5412a6121fb..16d18a1abb6 100644 --- a/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json +++ b/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h664-w632-w34v", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47445" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix null pointer dereference on pointer edp\n\nThe initialization of pointer dev dereferences pointer edp before\nedp is null checked, so there is a potential null pointer deference\nissue. Fix this by only dereferencing edp after edp has been null\nchecked.\n\nAddresses-Coverity: (\"Dereference before null check\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2cp-mh84-p47v/GHSA-q2cp-mh84-p47v.json b/advisories/unreviewed/2024/05/GHSA-q2cp-mh84-p47v/GHSA-q2cp-mh84-p47v.json index a025a33120e..6be61fbc411 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2cp-mh84-p47v/GHSA-q2cp-mh84-p47v.json +++ b/advisories/unreviewed/2024/05/GHSA-q2cp-mh84-p47v/GHSA-q2cp-mh84-p47v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q2cp-mh84-p47v", - "modified": "2024-05-20T12:30:29Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-05-20T12:30:29Z", "aliases": [ "CVE-2024-35979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nraid1: fix use-after-free for original bio in raid1_write_request()\n\nr1_bio->bios[] is used to record new bios that will be issued to\nunderlying disks, however, in raid1_write_request(), r1_bio->bios[]\nwill set to the original bio temporarily. Meanwhile, if blocked rdev\nis set, free_r1bio() will be called causing that all r1_bio->bios[]\nto be freed:\n\nraid1_write_request()\n r1_bio = alloc_r1bio(mddev, bio); -> r1_bio->bios[] is NULL\n for (i = 0; i < disks; i++) -> for each rdev in conf\n // first rdev is normal\n r1_bio->bios[0] = bio; -> set to original bio\n // second rdev is blocked\n if (test_bit(Blocked, &rdev->flags))\n break\n\n if (blocked_rdev)\n free_r1bio()\n put_all_bios()\n bio_put(r1_bio->bios[0]) -> original bio is freed\n\nTest scripts:\n\nmdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean\nfio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \\\n -iodepth=128 -name=test -direct=1\necho blocked > /sys/block/md0/md/rd2/state\n\nTest result:\n\nBUG bio-264 (Not tainted): Object already free\n-----------------------------------------------------------------------------\n\nAllocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869\n kmem_cache_alloc+0x324/0x480\n mempool_alloc_slab+0x24/0x50\n mempool_alloc+0x6e/0x220\n bio_alloc_bioset+0x1af/0x4d0\n blkdev_direct_IO+0x164/0x8a0\n blkdev_write_iter+0x309/0x440\n aio_write+0x139/0x2f0\n io_submit_one+0x5ca/0xb70\n __do_sys_io_submit+0x86/0x270\n __x64_sys_io_submit+0x22/0x30\n do_syscall_64+0xb1/0x210\n entry_SYSCALL_64_after_hwframe+0x6c/0x74\nFreed in mempool_free_slab+0x1f/0x30 age=1 cpu=1 pid=869\n kmem_cache_free+0x28c/0x550\n mempool_free_slab+0x1f/0x30\n mempool_free+0x40/0x100\n bio_free+0x59/0x80\n bio_put+0xf0/0x220\n free_r1bio+0x74/0xb0\n raid1_make_request+0xadf/0x1150\n md_handle_request+0xc7/0x3b0\n md_submit_bio+0x76/0x130\n __submit_bio+0xd8/0x1d0\n submit_bio_noacct_nocheck+0x1eb/0x5c0\n submit_bio_noacct+0x169/0xd40\n submit_bio+0xee/0x1d0\n blkdev_direct_IO+0x322/0x8a0\n blkdev_write_iter+0x309/0x440\n aio_write+0x139/0x2f0\n\nSince that bios for underlying disks are not allocated yet, fix this\nproblem by using mempool_free() directly to free the r1_bio.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r3pw-96wv-8pj5/GHSA-r3pw-96wv-8pj5.json b/advisories/unreviewed/2024/05/GHSA-r3pw-96wv-8pj5/GHSA-r3pw-96wv-8pj5.json index 9cd5376a7aa..e97e8851a52 100644 --- a/advisories/unreviewed/2024/05/GHSA-r3pw-96wv-8pj5/GHSA-r3pw-96wv-8pj5.json +++ b/advisories/unreviewed/2024/05/GHSA-r3pw-96wv-8pj5/GHSA-r3pw-96wv-8pj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3pw-96wv-8pj5", - "modified": "2024-05-20T12:30:29Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-05-20T12:30:29Z", "aliases": [ "CVE-2024-35977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/chrome: cros_ec_uart: properly fix race condition\n\nThe cros_ec_uart_probe() function calls devm_serdev_device_open() before\nit calls serdev_device_set_client_ops(). This can trigger a NULL pointer\ndereference:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n ...\n Call Trace:\n \n ...\n ? ttyport_receive_buf\n\nA simplified version of crashing code is as follows:\n\n static inline size_t serdev_controller_receive_buf(struct serdev_controller *ctrl,\n const u8 *data,\n size_t count)\n {\n struct serdev_device *serdev = ctrl->serdev;\n\n if (!serdev || !serdev->ops->receive_buf) // CRASH!\n return 0;\n\n return serdev->ops->receive_buf(serdev, data, count);\n }\n\nIt assumes that if SERPORT_ACTIVE is set and serdev exists, serdev->ops\nwill also exist. This conflicts with the existing cros_ec_uart_probe()\nlogic, as it first calls devm_serdev_device_open() (which sets\nSERPORT_ACTIVE), and only later sets serdev->ops via\nserdev_device_set_client_ops().\n\nCommit 01f95d42b8f4 (\"platform/chrome: cros_ec_uart: fix race\ncondition\") attempted to fix a similar race condition, but while doing\nso, made the window of error for this race condition to happen much\nwider.\n\nAttempt to fix the race condition again, making sure we fully setup\nbefore calling devm_serdev_device_open().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vp78-5x9p-m27h/GHSA-vp78-5x9p-m27h.json b/advisories/unreviewed/2024/05/GHSA-vp78-5x9p-m27h/GHSA-vp78-5x9p-m27h.json index dc07d430f75..92344f19389 100644 --- a/advisories/unreviewed/2024/05/GHSA-vp78-5x9p-m27h/GHSA-vp78-5x9p-m27h.json +++ b/advisories/unreviewed/2024/05/GHSA-vp78-5x9p-m27h/GHSA-vp78-5x9p-m27h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp78-5x9p-m27h", - "modified": "2024-05-21T15:31:43Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-05-21T15:31:43Z", "aliases": [ "CVE-2021-47341" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio\n\nBUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:183\nRead of size 8 at addr ffff0000c03a2500 by task syz-executor083/4269\n\nCPU: 5 PID: 4269 Comm: syz-executor083 Not tainted 5.10.0 #7\nHardware name: linux,dummy-virt (DT)\nCall trace:\n dump_backtrace+0x0/0x2d0 arch/arm64/kernel/stacktrace.c:132\n show_stack+0x28/0x34 arch/arm64/kernel/stacktrace.c:196\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x110/0x164 lib/dump_stack.c:118\n print_address_description+0x78/0x5c8 mm/kasan/report.c:385\n __kasan_report mm/kasan/report.c:545 [inline]\n kasan_report+0x148/0x1e4 mm/kasan/report.c:562\n check_memory_region_inline mm/kasan/generic.c:183 [inline]\n __asan_load8+0xb4/0xbc mm/kasan/generic.c:252\n kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:183\n kvm_vm_ioctl+0xe30/0x14c4 arch/arm64/kvm/../../../virt/kvm/kvm_main.c:3755\n vfs_ioctl fs/ioctl.c:48 [inline]\n __do_sys_ioctl fs/ioctl.c:753 [inline]\n __se_sys_ioctl fs/ioctl.c:739 [inline]\n __arm64_sys_ioctl+0xf88/0x131c fs/ioctl.c:739\n __invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]\n invoke_syscall arch/arm64/kernel/syscall.c:48 [inline]\n el0_svc_common arch/arm64/kernel/syscall.c:158 [inline]\n do_el0_svc+0x120/0x290 arch/arm64/kernel/syscall.c:220\n el0_svc+0x1c/0x28 arch/arm64/kernel/entry-common.c:367\n el0_sync_handler+0x98/0x170 arch/arm64/kernel/entry-common.c:383\n el0_sync+0x140/0x180 arch/arm64/kernel/entry.S:670\n\nAllocated by task 4269:\n stack_trace_save+0x80/0xb8 kernel/stacktrace.c:121\n kasan_save_stack mm/kasan/common.c:48 [inline]\n kasan_set_track mm/kasan/common.c:56 [inline]\n __kasan_kmalloc+0xdc/0x120 mm/kasan/common.c:461\n kasan_kmalloc+0xc/0x14 mm/kasan/common.c:475\n kmem_cache_alloc_trace include/linux/slab.h:450 [inline]\n kmalloc include/linux/slab.h:552 [inline]\n kzalloc include/linux/slab.h:664 [inline]\n kvm_vm_ioctl_register_coalesced_mmio+0x78/0x1cc arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:146\n kvm_vm_ioctl+0x7e8/0x14c4 arch/arm64/kvm/../../../virt/kvm/kvm_main.c:3746\n vfs_ioctl fs/ioctl.c:48 [inline]\n __do_sys_ioctl fs/ioctl.c:753 [inline]\n __se_sys_ioctl fs/ioctl.c:739 [inline]\n __arm64_sys_ioctl+0xf88/0x131c fs/ioctl.c:739\n __invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]\n invoke_syscall arch/arm64/kernel/syscall.c:48 [inline]\n el0_svc_common arch/arm64/kernel/syscall.c:158 [inline]\n do_el0_svc+0x120/0x290 arch/arm64/kernel/syscall.c:220\n el0_svc+0x1c/0x28 arch/arm64/kernel/entry-common.c:367\n el0_sync_handler+0x98/0x170 arch/arm64/kernel/entry-common.c:383\n el0_sync+0x140/0x180 arch/arm64/kernel/entry.S:670\n\nFreed by task 4269:\n stack_trace_save+0x80/0xb8 kernel/stacktrace.c:121\n kasan_save_stack mm/kasan/common.c:48 [inline]\n kasan_set_track+0x38/0x6c mm/kasan/common.c:56\n kasan_set_free_info+0x20/0x40 mm/kasan/generic.c:355\n __kasan_slab_free+0x124/0x150 mm/kasan/common.c:422\n kasan_slab_free+0x10/0x1c mm/kasan/common.c:431\n slab_free_hook mm/slub.c:1544 [inline]\n slab_free_freelist_hook mm/slub.c:1577 [inline]\n slab_free mm/slub.c:3142 [inline]\n kfree+0x104/0x38c mm/slub.c:4124\n coalesced_mmio_destructor+0x94/0xa4 arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:102\n kvm_iodevice_destructor include/kvm/iodev.h:61 [inline]\n kvm_io_bus_unregister_dev+0x248/0x280 arch/arm64/kvm/../../../virt/kvm/kvm_main.c:4374\n kvm_vm_ioctl_unregister_coalesced_mmio+0x158/0x1ec arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:186\n kvm_vm_ioctl+0xe30/0x14c4 arch/arm64/kvm/../../../virt/kvm/kvm_main.c:3755\n vfs_ioctl fs/ioctl.c:48 [inline]\n __do_sys_ioctl fs/ioctl.c:753 [inline]\n __se_sys_ioctl fs/ioctl.c:739 [inline]\n __arm64_sys_ioctl+0xf88/0x131c fs/ioctl.c:739\n __invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]\n invoke_syscall arch/arm64/kernel/sys\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json b/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json index 96e3e394154..8627959d104 100644 --- a/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json +++ b/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr9g-qp6c-282r", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47470" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: fix potential use-after-free in slab_debugfs_fops\n\nWhen sysfs_slab_add failed, we shouldn't call debugfs_slab_add() for s\nbecause s will be freed soon. And slab_debugfs_fops will use s later\nleading to a use-after-free.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json b/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json index 31066ef57fd..19398c2bed9 100644 --- a/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json +++ b/advisories/unreviewed/2024/05/GHSA-xwvh-fxhh-3qrr/GHSA-xwvh-fxhh-3qrr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwvh-fxhh-3qrr", - "modified": "2024-05-21T15:31:44Z", + "modified": "2025-01-14T18:31:49Z", "published": "2024-05-21T15:31:44Z", "aliases": [ "CVE-2021-47402" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: flower: protect fl_walk() with rcu\n\nPatch that refactored fl_walk() to use idr_for_each_entry_continue_ul()\nalso removed rcu protection of individual filters which causes following\nuse-after-free when filter is deleted concurrently. Fix fl_walk() to obtain\nrcu read lock while iterating and taking the filter reference and temporary\nrelease the lock while calling arg->fn() callback that can sleep.\n\nKASAN trace:\n\n[ 352.773640] ==================================================================\n[ 352.775041] BUG: KASAN: use-after-free in fl_walk+0x159/0x240 [cls_flower]\n[ 352.776304] Read of size 4 at addr ffff8881c8251480 by task tc/2987\n\n[ 352.777862] CPU: 3 PID: 2987 Comm: tc Not tainted 5.15.0-rc2+ #2\n[ 352.778980] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 352.781022] Call Trace:\n[ 352.781573] dump_stack_lvl+0x46/0x5a\n[ 352.782332] print_address_description.constprop.0+0x1f/0x140\n[ 352.783400] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.784292] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.785138] kasan_report.cold+0x83/0xdf\n[ 352.785851] ? fl_walk+0x159/0x240 [cls_flower]\n[ 352.786587] kasan_check_range+0x145/0x1a0\n[ 352.787337] fl_walk+0x159/0x240 [cls_flower]\n[ 352.788163] ? fl_put+0x10/0x10 [cls_flower]\n[ 352.789007] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.790102] tcf_chain_dump+0x231/0x450\n[ 352.790878] ? tcf_chain_tp_delete_empty+0x170/0x170\n[ 352.791833] ? __might_sleep+0x2e/0xc0\n[ 352.792594] ? tfilter_notify+0x170/0x170\n[ 352.793400] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.794477] tc_dump_tfilter+0x385/0x4b0\n[ 352.795262] ? tc_new_tfilter+0x1180/0x1180\n[ 352.796103] ? __mod_node_page_state+0x1f/0xc0\n[ 352.796974] ? __build_skb_around+0x10e/0x130\n[ 352.797826] netlink_dump+0x2c0/0x560\n[ 352.798563] ? netlink_getsockopt+0x430/0x430\n[ 352.799433] ? __mutex_unlock_slowpath.constprop.0+0x220/0x220\n[ 352.800542] __netlink_dump_start+0x356/0x440\n[ 352.801397] rtnetlink_rcv_msg+0x3ff/0x550\n[ 352.802190] ? tc_new_tfilter+0x1180/0x1180\n[ 352.802872] ? rtnl_calcit.isra.0+0x1f0/0x1f0\n[ 352.803668] ? tc_new_tfilter+0x1180/0x1180\n[ 352.804344] ? _copy_from_iter_nocache+0x800/0x800\n[ 352.805202] ? kasan_set_track+0x1c/0x30\n[ 352.805900] netlink_rcv_skb+0xc6/0x1f0\n[ 352.806587] ? rht_deferred_worker+0x6b0/0x6b0\n[ 352.807455] ? rtnl_calcit.isra.0+0x1f0/0x1f0\n[ 352.808324] ? netlink_ack+0x4d0/0x4d0\n[ 352.809086] ? netlink_deliver_tap+0x62/0x3d0\n[ 352.809951] netlink_unicast+0x353/0x480\n[ 352.810744] ? netlink_attachskb+0x430/0x430\n[ 352.811586] ? __alloc_skb+0xd7/0x200\n[ 352.812349] netlink_sendmsg+0x396/0x680\n[ 352.813132] ? netlink_unicast+0x480/0x480\n[ 352.813952] ? __import_iovec+0x192/0x210\n[ 352.814759] ? netlink_unicast+0x480/0x480\n[ 352.815580] sock_sendmsg+0x6c/0x80\n[ 352.816299] ____sys_sendmsg+0x3a5/0x3c0\n[ 352.817096] ? kernel_sendmsg+0x30/0x30\n[ 352.817873] ? __ia32_sys_recvmmsg+0x150/0x150\n[ 352.818753] ___sys_sendmsg+0xd8/0x140\n[ 352.819518] ? sendmsg_copy_msghdr+0x110/0x110\n[ 352.820402] ? ___sys_recvmsg+0xf4/0x1a0\n[ 352.821110] ? __copy_msghdr_from_user+0x260/0x260\n[ 352.821934] ? _raw_spin_lock+0x81/0xd0\n[ 352.822680] ? __handle_mm_fault+0xef3/0x1b20\n[ 352.823549] ? rb_insert_color+0x2a/0x270\n[ 352.824373] ? copy_page_range+0x16b0/0x16b0\n[ 352.825209] ? perf_event_update_userpage+0x2d0/0x2d0\n[ 352.826190] ? __fget_light+0xd9/0xf0\n[ 352.826941] __sys_sendmsg+0xb3/0x130\n[ 352.827613] ? __sys_sendmsg_sock+0x20/0x20\n[ 352.828377] ? do_user_addr_fault+0x2c5/0x8a0\n[ 352.829184] ? fpregs_assert_state_consistent+0x52/0x60\n[ 352.830001] ? exit_to_user_mode_prepare+0x32/0x160\n[ 352.830845] do_syscall_64+0x35/0x80\n[ 352.831445] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 352.832331] RIP: 0033:0x7f7bee973c17\n[ \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:25Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fmvg-92v3-f2j5/GHSA-fmvg-92v3-f2j5.json b/advisories/unreviewed/2024/06/GHSA-fmvg-92v3-f2j5/GHSA-fmvg-92v3-f2j5.json index 6493d343fb2..d8e337a2a92 100644 --- a/advisories/unreviewed/2024/06/GHSA-fmvg-92v3-f2j5/GHSA-fmvg-92v3-f2j5.json +++ b/advisories/unreviewed/2024/06/GHSA-fmvg-92v3-f2j5/GHSA-fmvg-92v3-f2j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fmvg-92v3-f2j5", - "modified": "2024-06-27T15:30:39Z", + "modified": "2025-01-14T18:31:50Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38560" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bfa: Ensure the copied buf is NUL terminated\n\nCurrently, we allocate a nbytes-sized kernel buffer and copy nbytes from\nuserspace to that buffer. Later, we use sscanf on this buffer but we don't\nensure that the string is terminated inside the buffer, this can lead to\nOOB read when using sscanf. Fix this issue by using memdup_user_nul instead\nof memdup_user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-242f-ccpq-545j/GHSA-242f-ccpq-545j.json b/advisories/unreviewed/2024/12/GHSA-242f-ccpq-545j/GHSA-242f-ccpq-545j.json index 14776320daf..f546a5c495b 100644 --- a/advisories/unreviewed/2024/12/GHSA-242f-ccpq-545j/GHSA-242f-ccpq-545j.json +++ b/advisories/unreviewed/2024/12/GHSA-242f-ccpq-545j/GHSA-242f-ccpq-545j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-242f-ccpq-545j", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53210" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()\n\nPassing MSG_PEEK flag to skb_recv_datagram() increments skb refcount\n(skb->users) and iucv_sock_recvmsg() does not decrement skb refcount\nat exit.\nThis results in skb memory leak in skb_queue_purge() and WARN_ON in\niucv_sock_destruct() during socket close. To fix this decrease\nskb refcount by one if MSG_PEEK is set in order to prevent memory\nleak and WARN_ON.\n\nWARNING: CPU: 2 PID: 6292 at net/iucv/af_iucv.c:286 iucv_sock_destruct+0x144/0x1a0 [af_iucv]\nCPU: 2 PID: 6292 Comm: afiucv_test_msg Kdump: loaded Tainted: G W 6.10.0-rc7 #1\nHardware name: IBM 3931 A01 704 (z/VM 7.3.0)\nCall Trace:\n [<001587c682c4aa98>] iucv_sock_destruct+0x148/0x1a0 [af_iucv]\n [<001587c682c4a9d0>] iucv_sock_destruct+0x80/0x1a0 [af_iucv]\n [<001587c704117a32>] __sk_destruct+0x52/0x550\n [<001587c704104a54>] __sock_release+0xa4/0x230\n [<001587c704104c0c>] sock_close+0x2c/0x40\n [<001587c702c5f5a8>] __fput+0x2e8/0x970\n [<001587c7024148c4>] task_work_run+0x1c4/0x2c0\n [<001587c7023b0716>] do_exit+0x996/0x1050\n [<001587c7023b13aa>] do_group_exit+0x13a/0x360\n [<001587c7023b1626>] __s390x_sys_exit_group+0x56/0x60\n [<001587c7022bccca>] do_syscall+0x27a/0x380\n [<001587c7049a6a0c>] __do_syscall+0x9c/0x160\n [<001587c7049ce8a8>] system_call+0x70/0x98\n Last Breaking-Event-Address:\n [<001587c682c4a9d4>] iucv_sock_destruct+0x84/0x1a0 [af_iucv]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:28Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2585-gp7f-g466/GHSA-2585-gp7f-g466.json b/advisories/unreviewed/2024/12/GHSA-2585-gp7f-g466/GHSA-2585-gp7f-g466.json index 66fb3051f76..50501c12c62 100644 --- a/advisories/unreviewed/2024/12/GHSA-2585-gp7f-g466/GHSA-2585-gp7f-g466.json +++ b/advisories/unreviewed/2024/12/GHSA-2585-gp7f-g466/GHSA-2585-gp7f-g466.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2585-gp7f-g466", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53202" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: Fix possible resource leak in fw_log_firmware_info()\n\nThe alg instance should be released under the exception path, otherwise\nthere may be resource leak here.\n\nTo mitigate this, free the alg instance with crypto_free_shash when kmalloc\nfails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:27Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2gwr-frhx-j93x/GHSA-2gwr-frhx-j93x.json b/advisories/unreviewed/2024/12/GHSA-2gwr-frhx-j93x/GHSA-2gwr-frhx-j93x.json index d9195d13055..ea8829a8b24 100644 --- a/advisories/unreviewed/2024/12/GHSA-2gwr-frhx-j93x/GHSA-2gwr-frhx-j93x.json +++ b/advisories/unreviewed/2024/12/GHSA-2gwr-frhx-j93x/GHSA-2gwr-frhx-j93x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gwr-frhx-j93x", - "modified": "2024-12-27T15:31:50Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53171" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit\n\nAfter an insertion in TNC, the tree might split and cause a node to\nchange its `znode->parent`. A further deletion of other nodes in the\ntree (which also could free the nodes), the aforementioned node's\n`znode->cparent` could still point to a freed node. This\n`znode->cparent` may not be updated when getting nodes to commit in\n`ubifs_tnc_start_commit()`. This could then trigger a use-after-free\nwhen accessing the `znode->cparent` in `write_index()` in\n`ubifs_tnc_end_commit()`.\n\nThis can be triggered by running\n\n rm -f /etc/test-file.bin\n dd if=/dev/urandom of=/etc/test-file.bin bs=1M count=60 conv=fsync\n\nin a loop, and with `CONFIG_UBIFS_FS_AUTHENTICATION`. KASAN then\nreports:\n\n BUG: KASAN: use-after-free in ubifs_tnc_end_commit+0xa5c/0x1950\n Write of size 32 at addr ffffff800a3af86c by task ubifs_bgt0_20/153\n\n Call trace:\n dump_backtrace+0x0/0x340\n show_stack+0x18/0x24\n dump_stack_lvl+0x9c/0xbc\n print_address_description.constprop.0+0x74/0x2b0\n kasan_report+0x1d8/0x1f0\n kasan_check_range+0xf8/0x1a0\n memcpy+0x84/0xf4\n ubifs_tnc_end_commit+0xa5c/0x1950\n do_commit+0x4e0/0x1340\n ubifs_bg_thread+0x234/0x2e0\n kthread+0x36c/0x410\n ret_from_fork+0x10/0x20\n\n Allocated by task 401:\n kasan_save_stack+0x38/0x70\n __kasan_kmalloc+0x8c/0xd0\n __kmalloc+0x34c/0x5bc\n tnc_insert+0x140/0x16a4\n ubifs_tnc_add+0x370/0x52c\n ubifs_jnl_write_data+0x5d8/0x870\n do_writepage+0x36c/0x510\n ubifs_writepage+0x190/0x4dc\n __writepage+0x58/0x154\n write_cache_pages+0x394/0x830\n do_writepages+0x1f0/0x5b0\n filemap_fdatawrite_wbc+0x170/0x25c\n file_write_and_wait_range+0x140/0x190\n ubifs_fsync+0xe8/0x290\n vfs_fsync_range+0xc0/0x1e4\n do_fsync+0x40/0x90\n __arm64_sys_fsync+0x34/0x50\n invoke_syscall.constprop.0+0xa8/0x260\n do_el0_svc+0xc8/0x1f0\n el0_svc+0x34/0x70\n el0t_64_sync_handler+0x108/0x114\n el0t_64_sync+0x1a4/0x1a8\n\n Freed by task 403:\n kasan_save_stack+0x38/0x70\n kasan_set_track+0x28/0x40\n kasan_set_free_info+0x28/0x4c\n __kasan_slab_free+0xd4/0x13c\n kfree+0xc4/0x3a0\n tnc_delete+0x3f4/0xe40\n ubifs_tnc_remove_range+0x368/0x73c\n ubifs_tnc_remove_ino+0x29c/0x2e0\n ubifs_jnl_delete_inode+0x150/0x260\n ubifs_evict_inode+0x1d4/0x2e4\n evict+0x1c8/0x450\n iput+0x2a0/0x3c4\n do_unlinkat+0x2cc/0x490\n __arm64_sys_unlinkat+0x90/0x100\n invoke_syscall.constprop.0+0xa8/0x260\n do_el0_svc+0xc8/0x1f0\n el0_svc+0x34/0x70\n el0t_64_sync_handler+0x108/0x114\n el0t_64_sync+0x1a4/0x1a8\n\nThe offending `memcpy()` in `ubifs_copy_hash()` has a use-after-free\nwhen a node becomes root in TNC but still has a `cparent` to an already\nfreed node. More specifically, consider the following TNC:\n\n zroot\n /\n /\n zp1\n /\n /\n zn\n\nInserting a new node `zn_new` with a key smaller then `zn` will trigger\na split in `tnc_insert()` if `zp1` is full:\n\n zroot\n / \\\n / \\\n zp1 zp2\n / \\\n / \\\n zn_new zn\n\n`zn->parent` has now been moved to `zp2`, *but* `zn->cparent` still\npoints to `zp1`.\n\nNow, consider a removal of all the nodes _except_ `zn`. Just when\n`tnc_delete()` is about to delete `zroot` and `zp2`:\n\n zroot\n \\\n \\\n zp2\n \\\n \\\n zn\n\n`zroot` and `zp2` get freed and the tree collapses:\n\n zn\n\n`zn` now becomes the new `zroot`.\n\n`get_znodes_to_commit()` will now only find `zn`, the new `zroot`, and\n`write_index()` will check its `znode->cparent` that wrongly points to\nthe already freed `zp1`. `ubifs_copy_hash()` thus gets wrongly called\nwith `znode->cparent->zbranch[znode->iip].hash` that triggers the\nuse-after-free!\n\nFix this by explicitly setting `znode->cparent` to `NULL` in\n`get_znodes_to_commit()` for the root node. The search for the dirty\nnodes\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2qfq-q4fv-fp24/GHSA-2qfq-q4fv-fp24.json b/advisories/unreviewed/2024/12/GHSA-2qfq-q4fv-fp24/GHSA-2qfq-q4fv-fp24.json index ae75a951f53..7f8560d08b1 100644 --- a/advisories/unreviewed/2024/12/GHSA-2qfq-q4fv-fp24/GHSA-2qfq-q4fv-fp24.json +++ b/advisories/unreviewed/2024/12/GHSA-2qfq-q4fv-fp24/GHSA-2qfq-q4fv-fp24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qfq-q4fv-fp24", - "modified": "2025-01-09T18:32:13Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53179" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free of signing key\n\nCustomers have reported use-after-free in @ses->auth_key.response with\nSMB2.1 + sign mounts which occurs due to following race:\n\ntask A task B\ncifs_mount()\n dfs_mount_share()\n get_session()\n cifs_mount_get_session() cifs_send_recv()\n cifs_get_smb_ses() compound_send_recv()\n cifs_setup_session() smb2_setup_request()\n kfree_sensitive() smb2_calc_signature()\n crypto_shash_setkey() *UAF*\n\nFix this by ensuring that we have a valid @ses->auth_key.response by\nchecking whether @ses->ses_status is SES_GOOD or SES_EXITING with\n@ses->ses_lock held. After commit 24a9799aa8ef (\"smb: client: fix UAF\nin smb2_reconnect_server()\"), we made sure to call ->logoff() only\nwhen @ses was known to be good (e.g. valid ->auth_key.response), so\nit's safe to access signing key when @ses->ses_status == SES_EXITING.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json b/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json index 5e4fbca9fd2..4bff3eeb022 100644 --- a/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json +++ b/advisories/unreviewed/2024/12/GHSA-453g-5mrh-qccr/GHSA-453g-5mrh-qccr.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json b/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json index c784d4083a8..aea7952e357 100644 --- a/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json +++ b/advisories/unreviewed/2024/12/GHSA-5pqw-jjjw-gf67/GHSA-5pqw-jjjw-gf67.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-453" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-79fx-6w6m-964r/GHSA-79fx-6w6m-964r.json b/advisories/unreviewed/2024/12/GHSA-79fx-6w6m-964r/GHSA-79fx-6w6m-964r.json index 7fd384f8ea7..2afedcaf97d 100644 --- a/advisories/unreviewed/2024/12/GHSA-79fx-6w6m-964r/GHSA-79fx-6w6m-964r.json +++ b/advisories/unreviewed/2024/12/GHSA-79fx-6w6m-964r/GHSA-79fx-6w6m-964r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79fx-6w6m-964r", - "modified": "2024-12-27T15:31:50Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53173" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.0: Fix a use-after-free problem in the asynchronous open()\n\nYang Erkun reports that when two threads are opening files at the same\ntime, and are forced to abort before a reply is seen, then the call to\nnfs_release_seqid() in nfs4_opendata_free() can result in a\nuse-after-free of the pointer to the defunct rpc task of the other\nthread.\nThe fix is to ensure that if the RPC call is aborted before the call to\nnfs_wait_on_sequence() is complete, then we must call nfs_release_seqid()\nin nfs4_open_release() before the rpc_task is freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7fw8-m89x-2xhm/GHSA-7fw8-m89x-2xhm.json b/advisories/unreviewed/2024/12/GHSA-7fw8-m89x-2xhm/GHSA-7fw8-m89x-2xhm.json index 9beaa75abb7..4b512a61218 100644 --- a/advisories/unreviewed/2024/12/GHSA-7fw8-m89x-2xhm/GHSA-7fw8-m89x-2xhm.json +++ b/advisories/unreviewed/2024/12/GHSA-7fw8-m89x-2xhm/GHSA-7fw8-m89x-2xhm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fw8-m89x-2xhm", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-14T18:31:55Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56632" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix the memleak while create new ctrl failed\n\nNow while we create new ctrl failed, we have not free the\ntagset occupied by admin_q, here try to fix it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json b/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json index 76939741fb7..8f3695bf32f 100644 --- a/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json +++ b/advisories/unreviewed/2024/12/GHSA-7j7p-8xpw-v444/GHSA-7j7p-8xpw-v444.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json b/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json index 3594bc53774..8dd0928325a 100644 --- a/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json +++ b/advisories/unreviewed/2024/12/GHSA-889v-7c4r-6cg6/GHSA-889v-7c4r-6cg6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-889v-7c4r-6cg6", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53205" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: realtek: usb: fix NULL deref in rtk_usb2phy_probe\n\nIn rtk_usb2phy_probe() devm_kzalloc() may return NULL\nbut this returned value is not checked.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:28Z" diff --git a/advisories/unreviewed/2024/12/GHSA-983j-f2fq-2775/GHSA-983j-f2fq-2775.json b/advisories/unreviewed/2024/12/GHSA-983j-f2fq-2775/GHSA-983j-f2fq-2775.json index a65a8a6d497..6411c687df3 100644 --- a/advisories/unreviewed/2024/12/GHSA-983j-f2fq-2775/GHSA-983j-f2fq-2775.json +++ b/advisories/unreviewed/2024/12/GHSA-983j-f2fq-2775/GHSA-983j-f2fq-2775.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-983j-f2fq-2775", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56554" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix freeze UAF in binder_release_work()\n\nWhen a binder reference is cleaned up, any freeze work queued in the\nassociated process should also be removed. Otherwise, the reference is\nfreed while its ref->freeze.work is still queued in proc->work leading\nto a use-after-free issue as shown by the following KASAN report:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in binder_release_work+0x398/0x3d0\n Read of size 8 at addr ffff31600ee91488 by task kworker/5:1/211\n\n CPU: 5 UID: 0 PID: 211 Comm: kworker/5:1 Not tainted 6.11.0-rc7-00382-gfc6c92196396 #22\n Hardware name: linux,dummy-virt (DT)\n Workqueue: events binder_deferred_func\n Call trace:\n binder_release_work+0x398/0x3d0\n binder_deferred_func+0xb60/0x109c\n process_one_work+0x51c/0xbd4\n worker_thread+0x608/0xee8\n\n Allocated by task 703:\n __kmalloc_cache_noprof+0x130/0x280\n binder_thread_write+0xdb4/0x42a0\n binder_ioctl+0x18f0/0x25ac\n __arm64_sys_ioctl+0x124/0x190\n invoke_syscall+0x6c/0x254\n\n Freed by task 211:\n kfree+0xc4/0x230\n binder_deferred_func+0xae8/0x109c\n process_one_work+0x51c/0xbd4\n worker_thread+0x608/0xee8\n ==================================================================\n\nThis commit fixes the issue by ensuring any queued freeze work is removed\nwhen cleaning up a binder reference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json b/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json index 74db63f8858..33520f1f61d 100644 --- a/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json +++ b/advisories/unreviewed/2024/12/GHSA-c4cm-m6vc-3xvq/GHSA-c4cm-m6vc-3xvq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-f25m-f79x-gq3f/GHSA-f25m-f79x-gq3f.json b/advisories/unreviewed/2024/12/GHSA-f25m-f79x-gq3f/GHSA-f25m-f79x-gq3f.json index 36266971d13..b0450a974dd 100644 --- a/advisories/unreviewed/2024/12/GHSA-f25m-f79x-gq3f/GHSA-f25m-f79x-gq3f.json +++ b/advisories/unreviewed/2024/12/GHSA-f25m-f79x-gq3f/GHSA-f25m-f79x-gq3f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f25m-f79x-gq3f", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-14T18:31:55Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56682" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/riscv-aplic: Prevent crash when MSI domain is missing\n\nIf the APLIC driver is probed before the IMSIC driver, the parent MSI\ndomain will be missing, which causes a NULL pointer dereference in\nmsi_create_device_irq_domain().\n\nAvoid this by deferring probe until the parent MSI domain is available. Use\ndev_err_probe() to avoid printing an error message when returning\n-EPROBE_DEFER.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f7pw-25q4-98v7/GHSA-f7pw-25q4-98v7.json b/advisories/unreviewed/2024/12/GHSA-f7pw-25q4-98v7/GHSA-f7pw-25q4-98v7.json index 2d9063244ac..0ef8a50e352 100644 --- a/advisories/unreviewed/2024/12/GHSA-f7pw-25q4-98v7/GHSA-f7pw-25q4-98v7.json +++ b/advisories/unreviewed/2024/12/GHSA-f7pw-25q4-98v7/GHSA-f7pw-25q4-98v7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7pw-25q4-98v7", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56572" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()\n\nThe buffer in the loop should be released under the exception path,\notherwise there may be a memory leak here.\n\nTo mitigate this, free the buffer when allegro_alloc_buffer fails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fpvp-p3gv-cf29/GHSA-fpvp-p3gv-cf29.json b/advisories/unreviewed/2024/12/GHSA-fpvp-p3gv-cf29/GHSA-fpvp-p3gv-cf29.json index d7ac8307bf9..04a7148bd42 100644 --- a/advisories/unreviewed/2024/12/GHSA-fpvp-p3gv-cf29/GHSA-fpvp-p3gv-cf29.json +++ b/advisories/unreviewed/2024/12/GHSA-fpvp-p3gv-cf29/GHSA-fpvp-p3gv-cf29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpvp-p3gv-cf29", - "modified": "2024-12-27T15:31:50Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53165" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsh: intc: Fix use-after-free bug in register_intc_controller()\n\nIn the error handling for this function, d is freed without ever\nremoving it from intc_list which would lead to a use after free.\nTo fix this, let's only add it to the list after everything has\nsucceeded.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fxr3-xppx-fcgp/GHSA-fxr3-xppx-fcgp.json b/advisories/unreviewed/2024/12/GHSA-fxr3-xppx-fcgp/GHSA-fxr3-xppx-fcgp.json index a73acf7d274..025bde9b688 100644 --- a/advisories/unreviewed/2024/12/GHSA-fxr3-xppx-fcgp/GHSA-fxr3-xppx-fcgp.json +++ b/advisories/unreviewed/2024/12/GHSA-fxr3-xppx-fcgp/GHSA-fxr3-xppx-fcgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fxr3-xppx-fcgp", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-14T18:31:55Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56622" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: sysfs: Prevent div by zero\n\nPrevent a division by 0 when monitoring is not enabled.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json b/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json index a1b7e3aeee4..5b0eca38653 100644 --- a/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json +++ b/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm94-vr86-wgqv", - "modified": "2024-12-27T12:30:36Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T12:30:35Z", "aliases": [ "CVE-2024-3393" ], "details": "A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json b/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json index f16222033a8..d55c8fb0783 100644 --- a/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json +++ b/advisories/unreviewed/2024/12/GHSA-h49r-vq54-f89j/GHSA-h49r-vq54-f89j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-hrqf-4crg-qqjg/GHSA-hrqf-4crg-qqjg.json b/advisories/unreviewed/2024/12/GHSA-hrqf-4crg-qqjg/GHSA-hrqf-4crg-qqjg.json index 2db05e692c7..84135fc5201 100644 --- a/advisories/unreviewed/2024/12/GHSA-hrqf-4crg-qqjg/GHSA-hrqf-4crg-qqjg.json +++ b/advisories/unreviewed/2024/12/GHSA-hrqf-4crg-qqjg/GHSA-hrqf-4crg-qqjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hrqf-4crg-qqjg", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53237" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix use-after-free in device_for_each_child()\n\nSyzbot has reported the following KASAN splat:\n\nBUG: KASAN: slab-use-after-free in device_for_each_child+0x18f/0x1a0\nRead of size 8 at addr ffff88801f605308 by task kbnepd bnep0/4980\n\nCPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x100/0x190\n ? device_for_each_child+0x18f/0x1a0\n print_report+0x13a/0x4cb\n ? __virt_addr_valid+0x5e/0x590\n ? __phys_addr+0xc6/0x150\n ? device_for_each_child+0x18f/0x1a0\n kasan_report+0xda/0x110\n ? device_for_each_child+0x18f/0x1a0\n ? __pfx_dev_memalloc_noio+0x10/0x10\n device_for_each_child+0x18f/0x1a0\n ? __pfx_device_for_each_child+0x10/0x10\n pm_runtime_set_memalloc_noio+0xf2/0x180\n netdev_unregister_kobject+0x1ed/0x270\n unregister_netdevice_many_notify+0x123c/0x1d80\n ? __mutex_trylock_common+0xde/0x250\n ? __pfx_unregister_netdevice_many_notify+0x10/0x10\n ? trace_contention_end+0xe6/0x140\n ? __mutex_lock+0x4e7/0x8f0\n ? __pfx_lock_acquire.part.0+0x10/0x10\n ? rcu_is_watching+0x12/0xc0\n ? unregister_netdev+0x12/0x30\n unregister_netdevice_queue+0x30d/0x3f0\n ? __pfx_unregister_netdevice_queue+0x10/0x10\n ? __pfx_down_write+0x10/0x10\n unregister_netdev+0x1c/0x30\n bnep_session+0x1fb3/0x2ab0\n ? __pfx_bnep_session+0x10/0x10\n ? __pfx_lock_release+0x10/0x10\n ? __pfx_woken_wake_function+0x10/0x10\n ? __kthread_parkme+0x132/0x200\n ? __pfx_bnep_session+0x10/0x10\n ? kthread+0x13a/0x370\n ? __pfx_bnep_session+0x10/0x10\n kthread+0x2b7/0x370\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x48/0x80\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nAllocated by task 4974:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n __kmalloc_noprof+0x1d1/0x440\n hci_alloc_dev_priv+0x1d/0x2820\n __vhci_create_device+0xef/0x7d0\n vhci_write+0x2c7/0x480\n vfs_write+0x6a0/0xfc0\n ksys_write+0x12f/0x260\n do_syscall_64+0xc7/0x250\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 4979:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x4f/0x70\n kfree+0x141/0x490\n hci_release_dev+0x4d9/0x600\n bt_host_release+0x6a/0xb0\n device_release+0xa4/0x240\n kobject_put+0x1ec/0x5a0\n put_device+0x1f/0x30\n vhci_release+0x81/0xf0\n __fput+0x3f6/0xb30\n task_work_run+0x151/0x250\n do_exit+0xa79/0x2c30\n do_group_exit+0xd5/0x2a0\n get_signal+0x1fcd/0x2210\n arch_do_signal_or_restart+0x93/0x780\n syscall_exit_to_user_mode+0x140/0x290\n do_syscall_64+0xd4/0x250\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nIn 'hci_conn_del_sysfs()', 'device_unregister()' may be called when\nan underlying (kobject) reference counter is greater than 1. This\nmeans that reparenting (happened when the device is actually freed)\nis delayed and, during that delay, parent controller device (hciX)\nmay be deleted. Since the latter may create a dangling pointer to\nfreed parent, avoid that scenario by reparenting to NULL explicitly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hx9w-rm9x-mqpr/GHSA-hx9w-rm9x-mqpr.json b/advisories/unreviewed/2024/12/GHSA-hx9w-rm9x-mqpr/GHSA-hx9w-rm9x-mqpr.json index ea6fc218be1..cc501c2127b 100644 --- a/advisories/unreviewed/2024/12/GHSA-hx9w-rm9x-mqpr/GHSA-hx9w-rm9x-mqpr.json +++ b/advisories/unreviewed/2024/12/GHSA-hx9w-rm9x-mqpr/GHSA-hx9w-rm9x-mqpr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx9w-rm9x-mqpr", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53206" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix use-after-free of nreq in reqsk_timer_handler().\n\nThe cited commit replaced inet_csk_reqsk_queue_drop_and_put() with\n__inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_handler().\n\nThen, oreq should be passed to reqsk_put() instead of req; otherwise\nuse-after-free of nreq could happen when reqsk is migrated but the\nretry attempt failed (e.g. due to timeout).\n\nLet's pass oreq to reqsk_put().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:28Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json b/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json index 353a9329db9..c451f60368d 100644 --- a/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json +++ b/advisories/unreviewed/2024/12/GHSA-j6r2-q88x-5m39/GHSA-j6r2-q88x-5m39.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json b/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json index ae3f32eec96..2d40f19ed0e 100644 --- a/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json +++ b/advisories/unreviewed/2024/12/GHSA-m66h-xc6v-38j2/GHSA-m66h-xc6v-38j2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json b/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json index 7ce257f3c73..db4389d7972 100644 --- a/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json +++ b/advisories/unreviewed/2024/12/GHSA-mhch-rj8x-4v2p/GHSA-mhch-rj8x-4v2p.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json b/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json index 0cbbbb923b2..0fc3754d4db 100644 --- a/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json +++ b/advisories/unreviewed/2024/12/GHSA-p6qw-9qh6-cc5x/GHSA-p6qw-9qh6-cc5x.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-843" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-pm64-f9ff-xc6w/GHSA-pm64-f9ff-xc6w.json b/advisories/unreviewed/2024/12/GHSA-pm64-f9ff-xc6w/GHSA-pm64-f9ff-xc6w.json index 8c80e481765..744b6cdd814 100644 --- a/advisories/unreviewed/2024/12/GHSA-pm64-f9ff-xc6w/GHSA-pm64-f9ff-xc6w.json +++ b/advisories/unreviewed/2024/12/GHSA-pm64-f9ff-xc6w/GHSA-pm64-f9ff-xc6w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pm64-f9ff-xc6w", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56534" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: avoid memory leak in iocharset\n\nA memleak was found as below:\n\nunreferenced object 0xffff0000d10164d8 (size 8):\n comm \"pool-udisksd\", pid 108217, jiffies 4295408555\n hex dump (first 8 bytes):\n 75 74 66 38 00 cc cc cc utf8....\n backtrace (crc de430d31):\n [] kmemleak_alloc+0xb8/0xc8\n [] __kmalloc_node_track_caller_noprof+0x380/0x474\n [] kstrdup+0x70/0xfc\n [] isofs_parse_param+0x228/0x2c0 [isofs]\n [] vfs_parse_fs_param+0xf4/0x164\n [] vfs_parse_fs_string+0x8c/0xd4\n [] vfs_parse_monolithic_sep+0xb0/0xfc\n [] generic_parse_monolithic+0x30/0x3c\n [] parse_monolithic_mount_data+0x40/0x4c\n [] path_mount+0x6c4/0x9ec\n [] do_mount+0xac/0xc4\n [] __arm64_sys_mount+0x16c/0x2b0\n [] invoke_syscall+0x7c/0x104\n [] el0_svc_common.constprop.1+0xe0/0x104\n [] do_el0_svc+0x2c/0x38\n [] el0_svc+0x3c/0x1b8\n\nThe opt->iocharset is freed inside the isofs_fill_super function,\nBut there may be situations where it's not possible to\nenter this function.\n\nFor example, in the get_tree_bdev_flags function,when\nencountering the situation where \"Can't mount, would change RO state,\"\nIn such a case, isofs_fill_super will not have the opportunity\nto be called,which means that opt->iocharset will not have the chance\nto be freed,ultimately leading to a memory leak.\n\nLet's move the memory freeing of opt->iocharset into\nisofs_free_fc function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pp3m-qp57-r498/GHSA-pp3m-qp57-r498.json b/advisories/unreviewed/2024/12/GHSA-pp3m-qp57-r498/GHSA-pp3m-qp57-r498.json index 8bc0dc4388c..0f21d84cbe9 100644 --- a/advisories/unreviewed/2024/12/GHSA-pp3m-qp57-r498/GHSA-pp3m-qp57-r498.json +++ b/advisories/unreviewed/2024/12/GHSA-pp3m-qp57-r498/GHSA-pp3m-qp57-r498.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pp3m-qp57-r498", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56542" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix a memleak issue when driver is removed\n\nRunning \"modprobe amdgpu\" the second time (followed by a modprobe -r\namdgpu) causes a call trace like:\n\n[ 845.212163] Memory manager not clean during takedown.\n[ 845.212170] WARNING: CPU: 4 PID: 2481 at drivers/gpu/drm/drm_mm.c:999 drm_mm_takedown+0x2b/0x40\n[ 845.212177] Modules linked in: amdgpu(OE-) amddrm_ttm_helper(OE) amddrm_buddy(OE) amdxcp(OE) amd_sched(OE) drm_exec drm_suballoc_helper drm_display_helper i2c_algo_bit amdttm(OE) amdkcl(OE) cec rc_core sunrpc qrtr intel_rapl_msr intel_rapl_common snd_hda_codec_hdmi edac_mce_amd snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_usb_audio snd_hda_codec snd_usbmidi_lib kvm_amd snd_hda_core snd_ump mc snd_hwdep kvm snd_pcm snd_seq_midi snd_seq_midi_event irqbypass crct10dif_pclmul snd_rawmidi polyval_clmulni polyval_generic ghash_clmulni_intel sha256_ssse3 sha1_ssse3 snd_seq aesni_intel crypto_simd snd_seq_device cryptd snd_timer mfd_aaeon asus_nb_wmi eeepc_wmi joydev asus_wmi snd ledtrig_audio sparse_keymap ccp wmi_bmof input_leds k10temp i2c_piix4 platform_profile rapl soundcore gpio_amdpt mac_hid binfmt_misc msr parport_pc ppdev lp parport efi_pstore nfnetlink dmi_sysfs ip_tables x_tables autofs4 hid_logitech_hidpp hid_logitech_dj hid_generic usbhid hid ahci xhci_pci igc crc32_pclmul libahci xhci_pci_renesas video\n[ 845.212284] wmi [last unloaded: amddrm_ttm_helper(OE)]\n[ 845.212290] CPU: 4 PID: 2481 Comm: modprobe Tainted: G W OE 6.8.0-31-generic #31-Ubuntu\n[ 845.212296] RIP: 0010:drm_mm_takedown+0x2b/0x40\n[ 845.212300] Code: 1f 44 00 00 48 8b 47 38 48 83 c7 38 48 39 f8 75 09 31 c0 31 ff e9 90 2e 86 00 55 48 c7 c7 d0 f6 8e 8a 48 89 e5 e8 f5 db 45 ff <0f> 0b 5d 31 c0 31 ff e9 74 2e 86 00 66 0f 1f 84 00 00 00 00 00 90\n[ 845.212302] RSP: 0018:ffffb11302127ae0 EFLAGS: 00010246\n[ 845.212305] RAX: 0000000000000000 RBX: ffff92aa5020fc08 RCX: 0000000000000000\n[ 845.212307] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 845.212309] RBP: ffffb11302127ae0 R08: 0000000000000000 R09: 0000000000000000\n[ 845.212310] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000004\n[ 845.212312] R13: ffff92aa50200000 R14: ffff92aa5020fb10 R15: ffff92aa5020faa0\n[ 845.212313] FS: 0000707dd7c7c080(0000) GS:ffff92b93de00000(0000) knlGS:0000000000000000\n[ 845.212316] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 845.212318] CR2: 00007d48b0aee200 CR3: 0000000115a58000 CR4: 0000000000f50ef0\n[ 845.212320] PKRU: 55555554\n[ 845.212321] Call Trace:\n[ 845.212323] \n[ 845.212328] ? show_regs+0x6d/0x80\n[ 845.212333] ? __warn+0x89/0x160\n[ 845.212339] ? drm_mm_takedown+0x2b/0x40\n[ 845.212344] ? report_bug+0x17e/0x1b0\n[ 845.212350] ? handle_bug+0x51/0xa0\n[ 845.212355] ? exc_invalid_op+0x18/0x80\n[ 845.212359] ? asm_exc_invalid_op+0x1b/0x20\n[ 845.212366] ? drm_mm_takedown+0x2b/0x40\n[ 845.212371] amdgpu_gtt_mgr_fini+0xa9/0x130 [amdgpu]\n[ 845.212645] amdgpu_ttm_fini+0x264/0x340 [amdgpu]\n[ 845.212770] amdgpu_bo_fini+0x2e/0xc0 [amdgpu]\n[ 845.212894] gmc_v12_0_sw_fini+0x2a/0x40 [amdgpu]\n[ 845.213036] amdgpu_device_fini_sw+0x11a/0x590 [amdgpu]\n[ 845.213159] amdgpu_driver_release_kms+0x16/0x40 [amdgpu]\n[ 845.213302] devm_drm_dev_init_release+0x5e/0x90\n[ 845.213305] devm_action_release+0x12/0x30\n[ 845.213308] release_nodes+0x42/0xd0\n[ 845.213311] devres_release_all+0x97/0xe0\n[ 845.213314] device_unbind_cleanup+0x12/0x80\n[ 845.213317] device_release_driver_internal+0x230/0x270\n[ 845.213319] ? srso_alias_return_thunk+0x5/0xfbef5\n\nThis is caused by lost memory during early init phase. First time driver\nis removed, memory is freed but when second time the driver is inserted,\nVBIOS dmub is not active, since the PSP policy is to retain the driver\nloaded version on subsequent warm boots. Hence, communication with VBIOS\nDMUB fails.\n\nFix this by aborting further comm\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:33Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json b/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json index 6716d2ada99..2dd78e3ce9f 100644 --- a/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json +++ b/advisories/unreviewed/2024/12/GHSA-q5hq-6qcp-phr8/GHSA-q5hq-6qcp-phr8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-591" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-qf3g-cg7v-c4x9/GHSA-qf3g-cg7v-c4x9.json b/advisories/unreviewed/2024/12/GHSA-qf3g-cg7v-c4x9/GHSA-qf3g-cg7v-c4x9.json index beb8956d544..22e8248b921 100644 --- a/advisories/unreviewed/2024/12/GHSA-qf3g-cg7v-c4x9/GHSA-qf3g-cg7v-c4x9.json +++ b/advisories/unreviewed/2024/12/GHSA-qf3g-cg7v-c4x9/GHSA-qf3g-cg7v-c4x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qf3g-cg7v-c4x9", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56538" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: zynqmp_kms: Unplug DRM device before removal\n\nPrevent userspace accesses to the DRM device from causing\nuse-after-frees by unplugging the device before we remove it. This\ncauses any further userspace accesses to result in an error without\nfurther calls into this driver's internals.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:33Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json b/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json index e4f8bb59317..5a623ff3c53 100644 --- a/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json +++ b/advisories/unreviewed/2024/12/GHSA-qgrj-p6f4-pxj8/GHSA-qgrj-p6f4-pxj8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-v2pf-j76r-xqh4/GHSA-v2pf-j76r-xqh4.json b/advisories/unreviewed/2024/12/GHSA-v2pf-j76r-xqh4/GHSA-v2pf-j76r-xqh4.json index e263dab2550..a12f3990d1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-v2pf-j76r-xqh4/GHSA-v2pf-j76r-xqh4.json +++ b/advisories/unreviewed/2024/12/GHSA-v2pf-j76r-xqh4/GHSA-v2pf-j76r-xqh4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2pf-j76r-xqh4", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56567" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nad7780: fix division by zero in ad7780_write_raw()\n\nIn the ad7780_write_raw() , val2 can be zero, which might lead to a\ndivision by zero error in DIV_ROUND_CLOSEST(). The ad7780_write_raw()\nis based on iio_info's write_raw. While val is explicitly declared that\ncan be zero (in read mode), val2 is not specified to be non-zero.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json b/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json index c0869bf0d06..cfafd8ea482 100644 --- a/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json +++ b/advisories/unreviewed/2024/12/GHSA-vgp8-265x-9xj2/GHSA-vgp8-265x-9xj2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-w9v5-63v9-9qvj/GHSA-w9v5-63v9-9qvj.json b/advisories/unreviewed/2024/12/GHSA-w9v5-63v9-9qvj/GHSA-w9v5-63v9-9qvj.json index 344959c58df..c5595d9cc15 100644 --- a/advisories/unreviewed/2024/12/GHSA-w9v5-63v9-9qvj/GHSA-w9v5-63v9-9qvj.json +++ b/advisories/unreviewed/2024/12/GHSA-w9v5-63v9-9qvj/GHSA-w9v5-63v9-9qvj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9v5-63v9-9qvj", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-14T18:31:53Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53186" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in SMB request handling\n\nA race condition exists between SMB request handling in\n`ksmbd_conn_handler_loop()` and the freeing of `ksmbd_conn` in the\nworkqueue handler `handle_ksmbd_work()`. This leads to a UAF.\n- KASAN: slab-use-after-free Read in handle_ksmbd_work\n- KASAN: slab-use-after-free in rtlock_slowlock_locked\n\nThis race condition arises as follows:\n- `ksmbd_conn_handler_loop()` waits for `conn->r_count` to reach zero:\n `wait_event(conn->r_count_q, atomic_read(&conn->r_count) == 0);`\n- Meanwhile, `handle_ksmbd_work()` decrements `conn->r_count` using\n `atomic_dec_return(&conn->r_count)`, and if it reaches zero, calls\n `ksmbd_conn_free()`, which frees `conn`.\n- However, after `handle_ksmbd_work()` decrements `conn->r_count`,\n it may still access `conn->r_count_q` in the following line:\n `waitqueue_active(&conn->r_count_q)` or `wake_up(&conn->r_count_q)`\n This results in a UAF, as `conn` has already been freed.\n\nThe discovery of this UAF can be referenced in the following PR for\nsyzkaller's support for SMB requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wccj-rqrc-g885/GHSA-wccj-rqrc-g885.json b/advisories/unreviewed/2024/12/GHSA-wccj-rqrc-g885/GHSA-wccj-rqrc-g885.json index 8f32ba48328..4b2fcbed943 100644 --- a/advisories/unreviewed/2024/12/GHSA-wccj-rqrc-g885/GHSA-wccj-rqrc-g885.json +++ b/advisories/unreviewed/2024/12/GHSA-wccj-rqrc-g885/GHSA-wccj-rqrc-g885.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wccj-rqrc-g885", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T18:31:54Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56556" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix node UAF in binder_add_freeze_work()\n\nIn binder_add_freeze_work() we iterate over the proc->nodes with the\nproc->inner_lock held. However, this lock is temporarily dropped in\norder to acquire the node->lock first (lock nesting order). This can\nrace with binder_node_release() and trigger a use-after-free:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c\n Write of size 4 at addr ffff53c04c29dd04 by task freeze/640\n\n CPU: 5 UID: 0 PID: 640 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #17\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n _raw_spin_lock+0xe4/0x19c\n binder_add_freeze_work+0x148/0x478\n binder_ioctl+0x1e70/0x25ac\n __arm64_sys_ioctl+0x124/0x190\n\n Allocated by task 637:\n __kmalloc_cache_noprof+0x12c/0x27c\n binder_new_node+0x50/0x700\n binder_transaction+0x35ac/0x6f74\n binder_thread_write+0xfb8/0x42a0\n binder_ioctl+0x18f0/0x25ac\n __arm64_sys_ioctl+0x124/0x190\n\n Freed by task 637:\n kfree+0xf0/0x330\n binder_thread_read+0x1e88/0x3a68\n binder_ioctl+0x16d8/0x25ac\n __arm64_sys_ioctl+0x124/0x190\n ==================================================================\n\nFix the race by taking a temporary reference on the node before\nreleasing the proc->inner lock. This ensures the node remains alive\nwhile in use.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-272x-qrpw-27mm/GHSA-272x-qrpw-27mm.json b/advisories/unreviewed/2025/01/GHSA-272x-qrpw-27mm/GHSA-272x-qrpw-27mm.json new file mode 100644 index 00000000000..05d44a55ed3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-272x-qrpw-27mm/GHSA-272x-qrpw-27mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-272x-qrpw-27mm", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21363" + ], + "details": "Microsoft Word Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21363" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-29f7-2v24-7hpm/GHSA-29f7-2v24-7hpm.json b/advisories/unreviewed/2025/01/GHSA-29f7-2v24-7hpm/GHSA-29f7-2v24-7hpm.json new file mode 100644 index 00000000000..6a994ff87ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-29f7-2v24-7hpm/GHSA-29f7-2v24-7hpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29f7-2v24-7hpm", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21311" + ], + "details": "Windows NTLM V1 Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21311" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21311" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-29gm-gchh-5j4j/GHSA-29gm-gchh-5j4j.json b/advisories/unreviewed/2025/01/GHSA-29gm-gchh-5j4j/GHSA-29gm-gchh-5j4j.json new file mode 100644 index 00000000000..d751047a053 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-29gm-gchh-5j4j/GHSA-29gm-gchh-5j4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29gm-gchh-5j4j", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21356" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21356" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2cjr-qx2h-9vmq/GHSA-2cjr-qx2h-9vmq.json b/advisories/unreviewed/2025/01/GHSA-2cjr-qx2h-9vmq/GHSA-2cjr-qx2h-9vmq.json index 9240eec99d3..9767e8d2a1f 100644 --- a/advisories/unreviewed/2025/01/GHSA-2cjr-qx2h-9vmq/GHSA-2cjr-qx2h-9vmq.json +++ b/advisories/unreviewed/2025/01/GHSA-2cjr-qx2h-9vmq/GHSA-2cjr-qx2h-9vmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2cjr-qx2h-9vmq", - "modified": "2025-01-10T21:31:27Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T21:31:27Z", "aliases": [ "CVE-2024-54910" ], "details": "Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T19:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gwv-hh3j-cx86/GHSA-2gwv-hh3j-cx86.json b/advisories/unreviewed/2025/01/GHSA-2gwv-hh3j-cx86/GHSA-2gwv-hh3j-cx86.json new file mode 100644 index 00000000000..e7261acd4ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gwv-hh3j-cx86/GHSA-2gwv-hh3j-cx86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gwv-hh3j-cx86", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21217" + ], + "details": "Windows NTLM Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21217" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2j3p-vpp9-9f53/GHSA-2j3p-vpp9-9f53.json b/advisories/unreviewed/2025/01/GHSA-2j3p-vpp9-9f53/GHSA-2j3p-vpp9-9f53.json new file mode 100644 index 00000000000..ad6eb5d282c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2j3p-vpp9-9f53/GHSA-2j3p-vpp9-9f53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j3p-vpp9-9f53", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-13158" + ], + "details": "An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13158" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jcp-473g-fc9m/GHSA-2jcp-473g-fc9m.json b/advisories/unreviewed/2025/01/GHSA-2jcp-473g-fc9m/GHSA-2jcp-473g-fc9m.json new file mode 100644 index 00000000000..75132db1ee6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2jcp-473g-fc9m/GHSA-2jcp-473g-fc9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jcp-473g-fc9m", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21300" + ], + "details": "Windows upnphost.dll Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21300" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json b/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json index 545e9e06c68..28fc6ce9b8b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json +++ b/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jpw-fpqf-qc7g", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39370" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2031" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2031" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-2jqv-6gjj-98r2/GHSA-2jqv-6gjj-98r2.json b/advisories/unreviewed/2025/01/GHSA-2jqv-6gjj-98r2/GHSA-2jqv-6gjj-98r2.json new file mode 100644 index 00000000000..cdfdec6fb52 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2jqv-6gjj-98r2/GHSA-2jqv-6gjj-98r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jqv-6gjj-98r2", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21417" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21417" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21417" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json b/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json index 467c956dd97..df49b081279 100644 --- a/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json +++ b/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jw2-w8hc-jqch", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-38666" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2051" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2051" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json b/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json index 3c9172bc841..d2b5b1c3a75 100644 --- a/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json +++ b/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2mxq-9vvh-j4jv", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-57222" ], "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T18:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2p5v-755j-54f5/GHSA-2p5v-755j-54f5.json b/advisories/unreviewed/2025/01/GHSA-2p5v-755j-54f5/GHSA-2p5v-755j-54f5.json new file mode 100644 index 00000000000..bc84590a993 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2p5v-755j-54f5/GHSA-2p5v-755j-54f5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p5v-755j-54f5", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21339" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21339" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21339" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2p7g-v48x-6m2c/GHSA-2p7g-v48x-6m2c.json b/advisories/unreviewed/2025/01/GHSA-2p7g-v48x-6m2c/GHSA-2p7g-v48x-6m2c.json new file mode 100644 index 00000000000..b9387cbc198 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2p7g-v48x-6m2c/GHSA-2p7g-v48x-6m2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p7g-v48x-6m2c", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21286" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21286" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2qv3-h9c7-9qcq/GHSA-2qv3-h9c7-9qcq.json b/advisories/unreviewed/2025/01/GHSA-2qv3-h9c7-9qcq/GHSA-2qv3-h9c7-9qcq.json new file mode 100644 index 00000000000..99ed0fef82f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2qv3-h9c7-9qcq/GHSA-2qv3-h9c7-9qcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qv3-h9c7-9qcq", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21257" + ], + "details": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21257" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json b/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json index 8657e8410f1..add12f44554 100644 --- a/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json +++ b/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2rx4-vrv5-3mjp", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13265" ], "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-96" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:35Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2xch-p59c-qwvr/GHSA-2xch-p59c-qwvr.json b/advisories/unreviewed/2025/01/GHSA-2xch-p59c-qwvr/GHSA-2xch-p59c-qwvr.json index 239ea763c62..3e8ff24ab35 100644 --- a/advisories/unreviewed/2025/01/GHSA-2xch-p59c-qwvr/GHSA-2xch-p59c-qwvr.json +++ b/advisories/unreviewed/2025/01/GHSA-2xch-p59c-qwvr/GHSA-2xch-p59c-qwvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xch-p59c-qwvr", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57633" ], "details": "An issue in the exps_bind_column component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json b/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json index d150dada23f..f1209c75bda 100644 --- a/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json +++ b/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33pw-8v2f-85mj", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39280" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2055" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2055" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-37mg-956f-9m7p/GHSA-37mg-956f-9m7p.json b/advisories/unreviewed/2025/01/GHSA-37mg-956f-9m7p/GHSA-37mg-956f-9m7p.json index 2d98382d0fe..c37e43053f0 100644 --- a/advisories/unreviewed/2025/01/GHSA-37mg-956f-9m7p/GHSA-37mg-956f-9m7p.json +++ b/advisories/unreviewed/2025/01/GHSA-37mg-956f-9m7p/GHSA-37mg-956f-9m7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37mg-956f-9m7p", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57637" ], "details": "An issue in the dfe_unit_gb_dependant component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3fqg-54mc-wmg3/GHSA-3fqg-54mc-wmg3.json b/advisories/unreviewed/2025/01/GHSA-3fqg-54mc-wmg3/GHSA-3fqg-54mc-wmg3.json new file mode 100644 index 00000000000..0f3dec94d55 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3fqg-54mc-wmg3/GHSA-3fqg-54mc-wmg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fqg-54mc-wmg3", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21271" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21271" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21271" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3gf9-c7wr-m575/GHSA-3gf9-c7wr-m575.json b/advisories/unreviewed/2025/01/GHSA-3gf9-c7wr-m575/GHSA-3gf9-c7wr-m575.json new file mode 100644 index 00000000000..c3202448f2a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3gf9-c7wr-m575/GHSA-3gf9-c7wr-m575.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gf9-c7wr-m575", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21189" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21189" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3hcq-fqcw-cvgf/GHSA-3hcq-fqcw-cvgf.json b/advisories/unreviewed/2025/01/GHSA-3hcq-fqcw-cvgf/GHSA-3hcq-fqcw-cvgf.json new file mode 100644 index 00000000000..fadc267e807 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3hcq-fqcw-cvgf/GHSA-3hcq-fqcw-cvgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hcq-fqcw-cvgf", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21334" + ], + "details": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21334" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3hqw-55xh-q6hf/GHSA-3hqw-55xh-q6hf.json b/advisories/unreviewed/2025/01/GHSA-3hqw-55xh-q6hf/GHSA-3hqw-55xh-q6hf.json new file mode 100644 index 00000000000..b1bd2f40268 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3hqw-55xh-q6hf/GHSA-3hqw-55xh-q6hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hqw-55xh-q6hf", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21231" + ], + "details": "IP Helper Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21231" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3jcg-qpj5-r3rp/GHSA-3jcg-qpj5-r3rp.json b/advisories/unreviewed/2025/01/GHSA-3jcg-qpj5-r3rp/GHSA-3jcg-qpj5-r3rp.json new file mode 100644 index 00000000000..92ded575040 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3jcg-qpj5-r3rp/GHSA-3jcg-qpj5-r3rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jcg-qpj5-r3rp", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21277" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21277" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21277" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3p4r-352r-f284/GHSA-3p4r-352r-f284.json b/advisories/unreviewed/2025/01/GHSA-3p4r-352r-f284/GHSA-3p4r-352r-f284.json new file mode 100644 index 00000000000..490c6f0d6dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3p4r-352r-f284/GHSA-3p4r-352r-f284.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p4r-352r-f284", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21281" + ], + "details": "Microsoft COM for Windows Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21281" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21281" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3p76-rm7j-ghq5/GHSA-3p76-rm7j-ghq5.json b/advisories/unreviewed/2025/01/GHSA-3p76-rm7j-ghq5/GHSA-3p76-rm7j-ghq5.json new file mode 100644 index 00000000000..890edd7b08f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3p76-rm7j-ghq5/GHSA-3p76-rm7j-ghq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p76-rm7j-ghq5", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21314" + ], + "details": "Windows SmartScreen Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21314" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3pvj-gf5m-rhhf/GHSA-3pvj-gf5m-rhhf.json b/advisories/unreviewed/2025/01/GHSA-3pvj-gf5m-rhhf/GHSA-3pvj-gf5m-rhhf.json new file mode 100644 index 00000000000..c23a1d2e196 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3pvj-gf5m-rhhf/GHSA-3pvj-gf5m-rhhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pvj-gf5m-rhhf", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21332" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21332" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3v2q-pqp4-rfp4/GHSA-3v2q-pqp4-rfp4.json b/advisories/unreviewed/2025/01/GHSA-3v2q-pqp4-rfp4/GHSA-3v2q-pqp4-rfp4.json new file mode 100644 index 00000000000..0d1e5010ca4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3v2q-pqp4-rfp4/GHSA-3v2q-pqp4-rfp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v2q-pqp4-rfp4", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21327" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21327" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21327" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-44vv-6vcv-9h7r/GHSA-44vv-6vcv-9h7r.json b/advisories/unreviewed/2025/01/GHSA-44vv-6vcv-9h7r/GHSA-44vv-6vcv-9h7r.json new file mode 100644 index 00000000000..4821baf8e26 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44vv-6vcv-9h7r/GHSA-44vv-6vcv-9h7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44vv-6vcv-9h7r", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21409" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21409" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21409" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json b/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json index 0b5cb20595c..13561e56ad0 100644 --- a/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json +++ b/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-453m-fcx3-j43g", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39367" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2023" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2023" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-49vp-7qg3-f9gx/GHSA-49vp-7qg3-f9gx.json b/advisories/unreviewed/2025/01/GHSA-49vp-7qg3-f9gx/GHSA-49vp-7qg3-f9gx.json new file mode 100644 index 00000000000..4ace43465cf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-49vp-7qg3-f9gx/GHSA-49vp-7qg3-f9gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49vp-7qg3-f9gx", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21238" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21238" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21238" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json b/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json index 98609806b69..76a5de22155 100644 --- a/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json +++ b/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49vq-r69w-8m53", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39603" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2042" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2042" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-4f6p-j74c-h2q4/GHSA-4f6p-j74c-h2q4.json b/advisories/unreviewed/2025/01/GHSA-4f6p-j74c-h2q4/GHSA-4f6p-j74c-h2q4.json new file mode 100644 index 00000000000..148179fb89a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4f6p-j74c-h2q4/GHSA-4f6p-j74c-h2q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f6p-j74c-h2q4", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21405" + ], + "details": "Visual Studio Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21405" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4gww-xwpq-hjpp/GHSA-4gww-xwpq-hjpp.json b/advisories/unreviewed/2025/01/GHSA-4gww-xwpq-hjpp/GHSA-4gww-xwpq-hjpp.json new file mode 100644 index 00000000000..380f864e458 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4gww-xwpq-hjpp/GHSA-4gww-xwpq-hjpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gww-xwpq-hjpp", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-52898" + ], + "details": "IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52898" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179150" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4hgf-cx4c-6c53/GHSA-4hgf-cx4c-6c53.json b/advisories/unreviewed/2025/01/GHSA-4hgf-cx4c-6c53/GHSA-4hgf-cx4c-6c53.json new file mode 100644 index 00000000000..01213d5d784 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4hgf-cx4c-6c53/GHSA-4hgf-cx4c-6c53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hgf-cx4c-6c53", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21348" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21348" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4wgp-9wjx-2m53/GHSA-4wgp-9wjx-2m53.json b/advisories/unreviewed/2025/01/GHSA-4wgp-9wjx-2m53/GHSA-4wgp-9wjx-2m53.json new file mode 100644 index 00000000000..9ace6b858f4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wgp-9wjx-2m53/GHSA-4wgp-9wjx-2m53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wgp-9wjx-2m53", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21193" + ], + "details": "Active Directory Federation Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21193" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4wmv-7xrq-8xxw/GHSA-4wmv-7xrq-8xxw.json b/advisories/unreviewed/2025/01/GHSA-4wmv-7xrq-8xxw/GHSA-4wmv-7xrq-8xxw.json new file mode 100644 index 00000000000..bafc17282b6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wmv-7xrq-8xxw/GHSA-4wmv-7xrq-8xxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wmv-7xrq-8xxw", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21240" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21240" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21240" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json b/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json index 671b3add01f..a1604d6fd15 100644 --- a/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json +++ b/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53rm-p3f5-vx5c", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-34544" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2044" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2044" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-54g3-mjpm-fvf4/GHSA-54g3-mjpm-fvf4.json b/advisories/unreviewed/2025/01/GHSA-54g3-mjpm-fvf4/GHSA-54g3-mjpm-fvf4.json new file mode 100644 index 00000000000..38510e2a3e6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54g3-mjpm-fvf4/GHSA-54g3-mjpm-fvf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54g3-mjpm-fvf4", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21248" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21248" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54qx-6c6v-96w4/GHSA-54qx-6c6v-96w4.json b/advisories/unreviewed/2025/01/GHSA-54qx-6c6v-96w4/GHSA-54qx-6c6v-96w4.json new file mode 100644 index 00000000000..67373e82cdb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54qx-6c6v-96w4/GHSA-54qx-6c6v-96w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qx-6c6v-96w4", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21313" + ], + "details": "Windows Security Account Manager (SAM) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21313" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-833" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-57v2-9qhm-9cq9/GHSA-57v2-9qhm-9cq9.json b/advisories/unreviewed/2025/01/GHSA-57v2-9qhm-9cq9/GHSA-57v2-9qhm-9cq9.json new file mode 100644 index 00000000000..76d6a550c39 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-57v2-9qhm-9cq9/GHSA-57v2-9qhm-9cq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57v2-9qhm-9cq9", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21365" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21365" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5chq-jmvj-p6gp/GHSA-5chq-jmvj-p6gp.json b/advisories/unreviewed/2025/01/GHSA-5chq-jmvj-p6gp/GHSA-5chq-jmvj-p6gp.json new file mode 100644 index 00000000000..45884035ad8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5chq-jmvj-p6gp/GHSA-5chq-jmvj-p6gp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5chq-jmvj-p6gp", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21292" + ], + "details": "Windows Search Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21292" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21292" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json b/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json new file mode 100644 index 00000000000..62a931cda77 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fwx-95cc-hcxv", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13161" + ], + "details": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13161" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5qjq-4w4h-57jf/GHSA-5qjq-4w4h-57jf.json b/advisories/unreviewed/2025/01/GHSA-5qjq-4w4h-57jf/GHSA-5qjq-4w4h-57jf.json new file mode 100644 index 00000000000..90d66948b11 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5qjq-4w4h-57jf/GHSA-5qjq-4w4h-57jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qjq-4w4h-57jf", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21330" + ], + "details": "Windows Remote Desktop Services Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21330" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21330" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5r6m-h6wm-64gp/GHSA-5r6m-h6wm-64gp.json b/advisories/unreviewed/2025/01/GHSA-5r6m-h6wm-64gp/GHSA-5r6m-h6wm-64gp.json new file mode 100644 index 00000000000..a2fddd5a5ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5r6m-h6wm-64gp/GHSA-5r6m-h6wm-64gp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r6m-h6wm-64gp", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-13181" + ], + "details": "Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13181" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-7-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5rr6-c4vv-37cw/GHSA-5rr6-c4vv-37cw.json b/advisories/unreviewed/2025/01/GHSA-5rr6-c4vv-37cw/GHSA-5rr6-c4vv-37cw.json new file mode 100644 index 00000000000..9a71ac48e57 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5rr6-c4vv-37cw/GHSA-5rr6-c4vv-37cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rr6-c4vv-37cw", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21213" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21213" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21213" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5w98-4m6q-799m/GHSA-5w98-4m6q-799m.json b/advisories/unreviewed/2025/01/GHSA-5w98-4m6q-799m/GHSA-5w98-4m6q-799m.json new file mode 100644 index 00000000000..50cd3c4dd0a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5w98-4m6q-799m/GHSA-5w98-4m6q-799m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w98-4m6q-799m", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21329" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21329" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21329" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json b/advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json new file mode 100644 index 00000000000..382b5c5d0c6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wjw-h8x5-v65m", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-23366" + ], + "details": "A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23366" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-23366" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337619" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6358-wjwp-64w4/GHSA-6358-wjwp-64w4.json b/advisories/unreviewed/2025/01/GHSA-6358-wjwp-64w4/GHSA-6358-wjwp-64w4.json new file mode 100644 index 00000000000..ab7e6d6e3bb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6358-wjwp-64w4/GHSA-6358-wjwp-64w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6358-wjwp-64w4", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13167" + ], + "details": "An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13167" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6394-43ww-pm3c/GHSA-6394-43ww-pm3c.json b/advisories/unreviewed/2025/01/GHSA-6394-43ww-pm3c/GHSA-6394-43ww-pm3c.json new file mode 100644 index 00000000000..47b8f92a02d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6394-43ww-pm3c/GHSA-6394-43ww-pm3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6394-43ww-pm3c", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21278" + ], + "details": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21278" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21278" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json b/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json index c8cbf9a1ec5..f1c8c3d7a34 100644 --- a/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json +++ b/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63wg-87qv-rw4r", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13274" ], "details": "Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-799" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json b/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json index e24c651af3f..2857a1fad1c 100644 --- a/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json +++ b/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65gf-8mmg-g56g", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-37184" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2025" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2025" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-6cgr-4rv8-425w/GHSA-6cgr-4rv8-425w.json b/advisories/unreviewed/2025/01/GHSA-6cgr-4rv8-425w/GHSA-6cgr-4rv8-425w.json new file mode 100644 index 00000000000..2c46d9c08cc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6cgr-4rv8-425w/GHSA-6cgr-4rv8-425w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cgr-4rv8-425w", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21315" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21315" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6frh-xf8w-ggm9/GHSA-6frh-xf8w-ggm9.json b/advisories/unreviewed/2025/01/GHSA-6frh-xf8w-ggm9/GHSA-6frh-xf8w-ggm9.json new file mode 100644 index 00000000000..edf9310674b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6frh-xf8w-ggm9/GHSA-6frh-xf8w-ggm9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6frh-xf8w-ggm9", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-0465" + ], + "details": "A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v2/categories. The manipulation of the argument PostBody.populate leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0465" + }, + { + "type": "WEB", + "url": "https://gist.github.com/PSDat123/ad7eb46550f22632aa4c229a0857f00d" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291482" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291482" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json b/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json index 90e8bd92f51..9c310ca3010 100644 --- a/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json +++ b/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6g2w-ww3w-xh3x", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-57212" ], "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6m9g-cw25-j9jc/GHSA-6m9g-cw25-j9jc.json b/advisories/unreviewed/2025/01/GHSA-6m9g-cw25-j9jc/GHSA-6m9g-cw25-j9jc.json new file mode 100644 index 00000000000..5218d1a8578 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6m9g-cw25-j9jc/GHSA-6m9g-cw25-j9jc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m9g-cw25-j9jc", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13163" + ], + "details": "Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13163" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6mv2-fmxx-35jg/GHSA-6mv2-fmxx-35jg.json b/advisories/unreviewed/2025/01/GHSA-6mv2-fmxx-35jg/GHSA-6mv2-fmxx-35jg.json new file mode 100644 index 00000000000..f944ef52c81 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6mv2-fmxx-35jg/GHSA-6mv2-fmxx-35jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mv2-fmxx-35jg", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21316" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21316" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21316" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6p26-7gx2-v5m2/GHSA-6p26-7gx2-v5m2.json b/advisories/unreviewed/2025/01/GHSA-6p26-7gx2-v5m2/GHSA-6p26-7gx2-v5m2.json new file mode 100644 index 00000000000..95a82f5ec44 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6p26-7gx2-v5m2/GHSA-6p26-7gx2-v5m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p26-7gx2-v5m2", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21335" + ], + "details": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21335" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21335" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6q64-xfhv-9jpq/GHSA-6q64-xfhv-9jpq.json b/advisories/unreviewed/2025/01/GHSA-6q64-xfhv-9jpq/GHSA-6q64-xfhv-9jpq.json new file mode 100644 index 00000000000..e31870522ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6q64-xfhv-9jpq/GHSA-6q64-xfhv-9jpq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q64-xfhv-9jpq", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21260" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21260" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json b/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json index efddd000ae7..ed03809d5c9 100644 --- a/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json +++ b/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r9m-h6rv-42cg", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-36258" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2046" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2046" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-6v58-wchf-wjx9/GHSA-6v58-wchf-wjx9.json b/advisories/unreviewed/2025/01/GHSA-6v58-wchf-wjx9/GHSA-6v58-wchf-wjx9.json new file mode 100644 index 00000000000..34e65502a3c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v58-wchf-wjx9/GHSA-6v58-wchf-wjx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v58-wchf-wjx9", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21282" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21282" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json b/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json new file mode 100644 index 00000000000..ef551e7ac86 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v62-48r8-7wh2", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13159" + ], + "details": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13159" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xcg-8gp2-j443/GHSA-6xcg-8gp2-j443.json b/advisories/unreviewed/2025/01/GHSA-6xcg-8gp2-j443/GHSA-6xcg-8gp2-j443.json new file mode 100644 index 00000000000..622202f9b50 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xcg-8gp2-j443/GHSA-6xcg-8gp2-j443.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xcg-8gp2-j443", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21346" + ], + "details": "Microsoft Office Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21346" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xwm-5jc9-ww35/GHSA-6xwm-5jc9-ww35.json b/advisories/unreviewed/2025/01/GHSA-6xwm-5jc9-ww35/GHSA-6xwm-5jc9-ww35.json new file mode 100644 index 00000000000..315e6587c6e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xwm-5jc9-ww35/GHSA-6xwm-5jc9-ww35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xwm-5jc9-ww35", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21270" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21270" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21270" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json b/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json index e39bc3f869a..a5a81daa680 100644 --- a/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json +++ b/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79x5-vf8c-7456", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39604" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2038" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2038" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-7h9g-r6hv-4q98/GHSA-7h9g-r6hv-4q98.json b/advisories/unreviewed/2025/01/GHSA-7h9g-r6hv-4q98/GHSA-7h9g-r6hv-4q98.json new file mode 100644 index 00000000000..eb13512e76a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7h9g-r6hv-4q98/GHSA-7h9g-r6hv-4q98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h9g-r6hv-4q98", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21294" + ], + "details": "Microsoft Digest Authentication Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21294" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21294" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7hxv-jvhc-mgrx/GHSA-7hxv-jvhc-mgrx.json b/advisories/unreviewed/2025/01/GHSA-7hxv-jvhc-mgrx/GHSA-7hxv-jvhc-mgrx.json new file mode 100644 index 00000000000..0e6957b87b1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7hxv-jvhc-mgrx/GHSA-7hxv-jvhc-mgrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hxv-jvhc-mgrx", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21233" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21233" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json b/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json index 4badc52ade9..907fa872576 100644 --- a/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json +++ b/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p4j-prhq-8ffm", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-34166" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2000" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2000" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-7pgh-vvx6-7g2r/GHSA-7pgh-vvx6-7g2r.json b/advisories/unreviewed/2025/01/GHSA-7pgh-vvx6-7g2r/GHSA-7pgh-vvx6-7g2r.json new file mode 100644 index 00000000000..1e34c9ff29e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7pgh-vvx6-7g2r/GHSA-7pgh-vvx6-7g2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pgh-vvx6-7g2r", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21250" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21250" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7qvp-9xw6-rpfp/GHSA-7qvp-9xw6-rpfp.json b/advisories/unreviewed/2025/01/GHSA-7qvp-9xw6-rpfp/GHSA-7qvp-9xw6-rpfp.json new file mode 100644 index 00000000000..0b1bb90777a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7qvp-9xw6-rpfp/GHSA-7qvp-9xw6-rpfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qvp-9xw6-rpfp", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21178" + ], + "details": "Visual Studio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21178" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json b/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json index 5720cc68cd5..97b2c57ee97 100644 --- a/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json +++ b/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rgq-53c3-wvm6", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39363" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2017" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2017" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json index 23e551c1351..b8154297e19 100644 --- a/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json +++ b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xfj-4r7x-3733", - "modified": "2025-01-14T15:30:54Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:54Z", "aliases": [ "CVE-2024-7344" ], "details": "Howyar UEFI Application \"Reloader\" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T14:15:34Z" diff --git a/advisories/unreviewed/2025/01/GHSA-82c6-8mfc-c23h/GHSA-82c6-8mfc-c23h.json b/advisories/unreviewed/2025/01/GHSA-82c6-8mfc-c23h/GHSA-82c6-8mfc-c23h.json new file mode 100644 index 00000000000..193e8a9e272 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-82c6-8mfc-c23h/GHSA-82c6-8mfc-c23h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82c6-8mfc-c23h", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-12086" + ], + "details": "A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12086" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12086" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330577" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-83vh-f4w7-rg8v/GHSA-83vh-f4w7-rg8v.json b/advisories/unreviewed/2025/01/GHSA-83vh-f4w7-rg8v/GHSA-83vh-f4w7-rg8v.json new file mode 100644 index 00000000000..6dfea597125 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-83vh-f4w7-rg8v/GHSA-83vh-f4w7-rg8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83vh-f4w7-rg8v", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21230" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21230" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-85mq-6w92-j442/GHSA-85mq-6w92-j442.json b/advisories/unreviewed/2025/01/GHSA-85mq-6w92-j442/GHSA-85mq-6w92-j442.json new file mode 100644 index 00000000000..f3a509d280b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-85mq-6w92-j442/GHSA-85mq-6w92-j442.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85mq-6w92-j442", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21312" + ], + "details": "Windows Smart Card Reader Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21312" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-874x-xm57-9m98/GHSA-874x-xm57-9m98.json b/advisories/unreviewed/2025/01/GHSA-874x-xm57-9m98/GHSA-874x-xm57-9m98.json new file mode 100644 index 00000000000..5c337103f5c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-874x-xm57-9m98/GHSA-874x-xm57-9m98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-874x-xm57-9m98", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21280" + ], + "details": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21280" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-885j-xrf7-wxg5/GHSA-885j-xrf7-wxg5.json b/advisories/unreviewed/2025/01/GHSA-885j-xrf7-wxg5/GHSA-885j-xrf7-wxg5.json new file mode 100644 index 00000000000..e47cbe768f8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-885j-xrf7-wxg5/GHSA-885j-xrf7-wxg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-885j-xrf7-wxg5", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2024-10630" + ], + "details": "A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10630" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Application-Control-Engine-CVE-2024-10630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-366" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-88gx-r57m-pghv/GHSA-88gx-r57m-pghv.json b/advisories/unreviewed/2025/01/GHSA-88gx-r57m-pghv/GHSA-88gx-r57m-pghv.json new file mode 100644 index 00000000000..83a16529a0e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-88gx-r57m-pghv/GHSA-88gx-r57m-pghv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gx-r57m-pghv", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21338" + ], + "details": "GDI+ Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21338" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8cgg-rcwg-mmh6/GHSA-8cgg-rcwg-mmh6.json b/advisories/unreviewed/2025/01/GHSA-8cgg-rcwg-mmh6/GHSA-8cgg-rcwg-mmh6.json new file mode 100644 index 00000000000..2d4647e89f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8cgg-rcwg-mmh6/GHSA-8cgg-rcwg-mmh6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cgg-rcwg-mmh6", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21293" + ], + "details": "Active Directory Domain Services Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21293" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21293" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8cvq-3jjp-ph9p/GHSA-8cvq-3jjp-ph9p.json b/advisories/unreviewed/2025/01/GHSA-8cvq-3jjp-ph9p/GHSA-8cvq-3jjp-ph9p.json new file mode 100644 index 00000000000..8fc5aa42eeb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8cvq-3jjp-ph9p/GHSA-8cvq-3jjp-ph9p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cvq-3jjp-ph9p", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-45627" + ], + "details": "In Apache Linkis <1.7.0, due to the lack of effective filtering\nof parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will \n\nallow the attacker to read arbitrary files from the Linkis server. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out. Versions of Apache Linkis < 1.7.0 will be affected. \nWe recommend users upgrade the version of Linkis to version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45627" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/0zzx8lldwoqgzq98mg61hojgpvn76xsh" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/01/14/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json b/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json index 1b805b6e458..9d18a3d60e6 100644 --- a/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json +++ b/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f65-h57m-hqw8", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-36290" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2019" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2019" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-8fj2-r7qc-chj6/GHSA-8fj2-r7qc-chj6.json b/advisories/unreviewed/2025/01/GHSA-8fj2-r7qc-chj6/GHSA-8fj2-r7qc-chj6.json new file mode 100644 index 00000000000..4c416866183 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8fj2-r7qc-chj6/GHSA-8fj2-r7qc-chj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fj2-r7qc-chj6", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21389" + ], + "details": "Windows upnphost.dll Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21389" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8g2m-ppjp-6hg7/GHSA-8g2m-ppjp-6hg7.json b/advisories/unreviewed/2025/01/GHSA-8g2m-ppjp-6hg7/GHSA-8g2m-ppjp-6hg7.json new file mode 100644 index 00000000000..13927c77f0f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8g2m-ppjp-6hg7/GHSA-8g2m-ppjp-6hg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g2m-ppjp-6hg7", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21340" + ], + "details": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21340" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json b/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json index 7bebb8c4d66..ed11714533c 100644 --- a/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json +++ b/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8m5m-vgwc-v2rv", - "modified": "2025-01-14T15:30:52Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:52Z", "aliases": [ "CVE-2024-11863" ], "details": "Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T14:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8r3x-3hj4-q58p/GHSA-8r3x-3hj4-q58p.json b/advisories/unreviewed/2025/01/GHSA-8r3x-3hj4-q58p/GHSA-8r3x-3hj4-q58p.json new file mode 100644 index 00000000000..558fe5b1095 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8r3x-3hj4-q58p/GHSA-8r3x-3hj4-q58p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r3x-3hj4-q58p", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21328" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21328" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21328" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8v9j-24jq-vx9h/GHSA-8v9j-24jq-vx9h.json b/advisories/unreviewed/2025/01/GHSA-8v9j-24jq-vx9h/GHSA-8v9j-24jq-vx9h.json new file mode 100644 index 00000000000..133754b0136 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8v9j-24jq-vx9h/GHSA-8v9j-24jq-vx9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v9j-24jq-vx9h", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21202" + ], + "details": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21202" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json b/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json index 426f87d300a..f6d9840721a 100644 --- a/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json +++ b/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9268-6mh2-4xfg", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39299" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2048" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2048" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-93jj-pg4p-vc4v/GHSA-93jj-pg4p-vc4v.json b/advisories/unreviewed/2025/01/GHSA-93jj-pg4p-vc4v/GHSA-93jj-pg4p-vc4v.json new file mode 100644 index 00000000000..40562e98e2a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-93jj-pg4p-vc4v/GHSA-93jj-pg4p-vc4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93jj-pg4p-vc4v", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21299" + ], + "details": "Windows Kerberos Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21299" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21299" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json b/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json index 1e567a93014..c427a78b3db 100644 --- a/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json +++ b/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94wj-p6vq-75pv", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-36295" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2047" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2047" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-9747-347m-wjjq/GHSA-9747-347m-wjjq.json b/advisories/unreviewed/2025/01/GHSA-9747-347m-wjjq/GHSA-9747-347m-wjjq.json new file mode 100644 index 00000000000..7f5c8096486 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9747-347m-wjjq/GHSA-9747-347m-wjjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9747-347m-wjjq", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21318" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21318" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21318" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-98mp-xvw5-2fch/GHSA-98mp-xvw5-2fch.json b/advisories/unreviewed/2025/01/GHSA-98mp-xvw5-2fch/GHSA-98mp-xvw5-2fch.json new file mode 100644 index 00000000000..27744f0b9e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-98mp-xvw5-2fch/GHSA-98mp-xvw5-2fch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mp-xvw5-2fch", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13162" + ], + "details": "SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13162" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-994m-778q-r536/GHSA-994m-778q-r536.json b/advisories/unreviewed/2025/01/GHSA-994m-778q-r536/GHSA-994m-778q-r536.json new file mode 100644 index 00000000000..8ed7938a347 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-994m-778q-r536/GHSA-994m-778q-r536.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-994m-778q-r536", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21229" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21229" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json b/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json index 7abf3dc1450..3e0882efa66 100644 --- a/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json +++ b/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9953-68f2-mpwf", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39273" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2037" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2037" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-99rf-j72j-fqv4/GHSA-99rf-j72j-fqv4.json b/advisories/unreviewed/2025/01/GHSA-99rf-j72j-fqv4/GHSA-99rf-j72j-fqv4.json new file mode 100644 index 00000000000..490d30f213c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-99rf-j72j-fqv4/GHSA-99rf-j72j-fqv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rf-j72j-fqv4", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21357" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21357" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json b/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json index 486e90051fd..7c9f46f98d9 100644 --- a/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json +++ b/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ch8-4327-g6cw", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39754" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2034" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2034" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json b/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json index 4e929131bb6..7e0e6677284 100644 --- a/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json +++ b/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cmh-g466-3ph3", - "modified": "2025-01-14T15:30:52Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:52Z", "aliases": [ "CVE-2024-11864" ], "details": "Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-755" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T14:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9fhh-4gq6-pq2g/GHSA-9fhh-4gq6-pq2g.json b/advisories/unreviewed/2025/01/GHSA-9fhh-4gq6-pq2g/GHSA-9fhh-4gq6-pq2g.json new file mode 100644 index 00000000000..b1007c1d618 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9fhh-4gq6-pq2g/GHSA-9fhh-4gq6-pq2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhh-4gq6-pq2g", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21265" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21265" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9g28-fpjj-mjvm/GHSA-9g28-fpjj-mjvm.json b/advisories/unreviewed/2025/01/GHSA-9g28-fpjj-mjvm/GHSA-9g28-fpjj-mjvm.json new file mode 100644 index 00000000000..fe9f5cd90f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9g28-fpjj-mjvm/GHSA-9g28-fpjj-mjvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g28-fpjj-mjvm", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21302" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21302" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9g3c-26fp-962j/GHSA-9g3c-26fp-962j.json b/advisories/unreviewed/2025/01/GHSA-9g3c-26fp-962j/GHSA-9g3c-26fp-962j.json new file mode 100644 index 00000000000..8a4f1fb8358 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9g3c-26fp-962j/GHSA-9g3c-26fp-962j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g3c-26fp-962j", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21360" + ], + "details": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21360" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9p8g-xc5v-q956/GHSA-9p8g-xc5v-q956.json b/advisories/unreviewed/2025/01/GHSA-9p8g-xc5v-q956/GHSA-9p8g-xc5v-q956.json new file mode 100644 index 00000000000..eee72bc8642 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9p8g-xc5v-q956/GHSA-9p8g-xc5v-q956.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p8g-xc5v-q956", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21372" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21372" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qg4-92rx-rmr9/GHSA-9qg4-92rx-rmr9.json b/advisories/unreviewed/2025/01/GHSA-9qg4-92rx-rmr9/GHSA-9qg4-92rx-rmr9.json new file mode 100644 index 00000000000..0386e9cfd98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qg4-92rx-rmr9/GHSA-9qg4-92rx-rmr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qg4-92rx-rmr9", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21220" + ], + "details": "Microsoft Message Queuing Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21220" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9r3v-vhm8-65h4/GHSA-9r3v-vhm8-65h4.json b/advisories/unreviewed/2025/01/GHSA-9r3v-vhm8-65h4/GHSA-9r3v-vhm8-65h4.json new file mode 100644 index 00000000000..37f1bcecda0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9r3v-vhm8-65h4/GHSA-9r3v-vhm8-65h4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3v-vhm8-65h4", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-0458" + ], + "details": "A vulnerability classified as problematic was found in Virtual Computer Vysual RH Solution 2024.12.1. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Panel. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0458" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291475" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291475" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473865" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9rg8-84xx-j7x9/GHSA-9rg8-84xx-j7x9.json b/advisories/unreviewed/2025/01/GHSA-9rg8-84xx-j7x9/GHSA-9rg8-84xx-j7x9.json new file mode 100644 index 00000000000..f9fcef186dc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9rg8-84xx-j7x9/GHSA-9rg8-84xx-j7x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rg8-84xx-j7x9", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21266" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21266" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json b/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json index 013b907b577..151021bcbdc 100644 --- a/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json +++ b/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rjp-q43g-3644", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-37186" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2032" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2032" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-9w2r-mxjh-5657/GHSA-9w2r-mxjh-5657.json b/advisories/unreviewed/2025/01/GHSA-9w2r-mxjh-5657/GHSA-9w2r-mxjh-5657.json new file mode 100644 index 00000000000..bb56b78f9f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9w2r-mxjh-5657/GHSA-9w2r-mxjh-5657.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w2r-mxjh-5657", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21274" + ], + "details": "Windows Event Tracing Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21274" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21274" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9wqj-2cgj-cmq7/GHSA-9wqj-2cgj-cmq7.json b/advisories/unreviewed/2025/01/GHSA-9wqj-2cgj-cmq7/GHSA-9wqj-2cgj-cmq7.json new file mode 100644 index 00000000000..59f878ab883 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9wqj-2cgj-cmq7/GHSA-9wqj-2cgj-cmq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wqj-2cgj-cmq7", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21219" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21219" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json b/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json new file mode 100644 index 00000000000..a3bfec3da70 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x68-7qq6-v523", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-12087" + ], + "details": "A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12087" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12087" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c3h5-h73c-29hq/GHSA-c3h5-h73c-29hq.json b/advisories/unreviewed/2025/01/GHSA-c3h5-h73c-29hq/GHSA-c3h5-h73c-29hq.json new file mode 100644 index 00000000000..a1569e82e9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c3h5-h73c-29hq/GHSA-c3h5-h73c-29hq.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3h5-h73c-29hq", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2025-23081" + ], + "details": "Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects Mediawiki - DataTransfer Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23081" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/DataTransfer/+/1080451" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/DataTransfer/+/1093931" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I5e1538a3bf66378810f905834c05626e1d2c82f0" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I773c616db781d2f3f30893ad01ef503bf251a2b3" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I7c9de4c8dcdb3276ba923c6bc7c8eef3531324c7" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I9223c31f02f31f1e06e1a8cddf7d539cc8d3a3d9" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T379749" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c5jj-jmhg-pcj9/GHSA-c5jj-jmhg-pcj9.json b/advisories/unreviewed/2025/01/GHSA-c5jj-jmhg-pcj9/GHSA-c5jj-jmhg-pcj9.json new file mode 100644 index 00000000000..a0c5c1f602a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5jj-jmhg-pcj9/GHSA-c5jj-jmhg-pcj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5jj-jmhg-pcj9", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21263" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21263" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json b/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json new file mode 100644 index 00000000000..1cf5f221f90 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5xq-93hx-p95r", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-10811" + ], + "details": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10811" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c6gj-jrcc-q2j8/GHSA-c6gj-jrcc-q2j8.json b/advisories/unreviewed/2025/01/GHSA-c6gj-jrcc-q2j8/GHSA-c6gj-jrcc-q2j8.json new file mode 100644 index 00000000000..e05fa758e41 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c6gj-jrcc-q2j8/GHSA-c6gj-jrcc-q2j8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6gj-jrcc-q2j8", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21310" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21310" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21310" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c6m2-mj7g-44c8/GHSA-c6m2-mj7g-44c8.json b/advisories/unreviewed/2025/01/GHSA-c6m2-mj7g-44c8/GHSA-c6m2-mj7g-44c8.json new file mode 100644 index 00000000000..82af1deda50 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c6m2-mj7g-44c8/GHSA-c6m2-mj7g-44c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6m2-mj7g-44c8", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21214" + ], + "details": "Windows BitLocker Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21214" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21214" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c735-gp9w-6hcw/GHSA-c735-gp9w-6hcw.json b/advisories/unreviewed/2025/01/GHSA-c735-gp9w-6hcw/GHSA-c735-gp9w-6hcw.json new file mode 100644 index 00000000000..4f95e77b593 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c735-gp9w-6hcw/GHSA-c735-gp9w-6hcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c735-gp9w-6hcw", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21246" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21246" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21246" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json b/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json new file mode 100644 index 00000000000..c98b2fc9e52 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfw8-99m9-5qfm", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13160" + ], + "details": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13160" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cfxg-rvg8-6h6c/GHSA-cfxg-rvg8-6h6c.json b/advisories/unreviewed/2025/01/GHSA-cfxg-rvg8-6h6c/GHSA-cfxg-rvg8-6h6c.json new file mode 100644 index 00000000000..9df6b525824 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cfxg-rvg8-6h6c/GHSA-cfxg-rvg8-6h6c.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfxg-rvg8-6h6c", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-23051" + ], + "details": "An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23051" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04723en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ch9j-hgv4-89cv/GHSA-ch9j-hgv4-89cv.json b/advisories/unreviewed/2025/01/GHSA-ch9j-hgv4-89cv/GHSA-ch9j-hgv4-89cv.json new file mode 100644 index 00000000000..7c2ddc6f9ab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ch9j-hgv4-89cv/GHSA-ch9j-hgv4-89cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch9j-hgv4-89cv", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21382" + ], + "details": "Windows Graphics Component Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21382" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21382" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cj5m-ph8r-8xxm/GHSA-cj5m-ph8r-8xxm.json b/advisories/unreviewed/2025/01/GHSA-cj5m-ph8r-8xxm/GHSA-cj5m-ph8r-8xxm.json index 79fab70cd90..46daa80d3ab 100644 --- a/advisories/unreviewed/2025/01/GHSA-cj5m-ph8r-8xxm/GHSA-cj5m-ph8r-8xxm.json +++ b/advisories/unreviewed/2025/01/GHSA-cj5m-ph8r-8xxm/GHSA-cj5m-ph8r-8xxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj5m-ph8r-8xxm", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57654" ], "details": "An issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cmq9-p2jc-99cw/GHSA-cmq9-p2jc-99cw.json b/advisories/unreviewed/2025/01/GHSA-cmq9-p2jc-99cw/GHSA-cmq9-p2jc-99cw.json new file mode 100644 index 00000000000..3d69ba8238d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cmq9-p2jc-99cw/GHSA-cmq9-p2jc-99cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmq9-p2jc-99cw", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21207" + ], + "details": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21207" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cmqq-5rp5-x675/GHSA-cmqq-5rp5-x675.json b/advisories/unreviewed/2025/01/GHSA-cmqq-5rp5-x675/GHSA-cmqq-5rp5-x675.json new file mode 100644 index 00000000000..4d42a9e0b8b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cmqq-5rp5-x675/GHSA-cmqq-5rp5-x675.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmqq-5rp5-x675", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21211" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21211" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json b/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json index 719ddce1b0d..8b972850df8 100644 --- a/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json +++ b/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv67-v84q-6c9x", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39602" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2052" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2052" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-cvcj-c937-q8wf/GHSA-cvcj-c937-q8wf.json b/advisories/unreviewed/2025/01/GHSA-cvcj-c937-q8wf/GHSA-cvcj-c937-q8wf.json new file mode 100644 index 00000000000..d375e924cf4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cvcj-c937-q8wf/GHSA-cvcj-c937-q8wf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvcj-c937-q8wf", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-13179" + ], + "details": "Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13179" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-7-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cwpx-vh5m-58gx/GHSA-cwpx-vh5m-58gx.json b/advisories/unreviewed/2025/01/GHSA-cwpx-vh5m-58gx/GHSA-cwpx-vh5m-58gx.json new file mode 100644 index 00000000000..f3e287348e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cwpx-vh5m-58gx/GHSA-cwpx-vh5m-58gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwpx-vh5m-58gx", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21309" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21309" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cww3-4gp5-qrj2/GHSA-cww3-4gp5-qrj2.json b/advisories/unreviewed/2025/01/GHSA-cww3-4gp5-qrj2/GHSA-cww3-4gp5-qrj2.json index 661011d380a..969ecc698a3 100644 --- a/advisories/unreviewed/2025/01/GHSA-cww3-4gp5-qrj2/GHSA-cww3-4gp5-qrj2.json +++ b/advisories/unreviewed/2025/01/GHSA-cww3-4gp5-qrj2/GHSA-cww3-4gp5-qrj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cww3-4gp5-qrj2", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57632" ], "details": "An issue in the is_column_unique component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cx2h-5vcq-pfj4/GHSA-cx2h-5vcq-pfj4.json b/advisories/unreviewed/2025/01/GHSA-cx2h-5vcq-pfj4/GHSA-cx2h-5vcq-pfj4.json new file mode 100644 index 00000000000..8e3aaf236cc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cx2h-5vcq-pfj4/GHSA-cx2h-5vcq-pfj4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx2h-5vcq-pfj4", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21276" + ], + "details": "Windows MapUrlToZone Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21276" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21276" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f37h-289m-fjrc/GHSA-f37h-289m-fjrc.json b/advisories/unreviewed/2025/01/GHSA-f37h-289m-fjrc/GHSA-f37h-289m-fjrc.json new file mode 100644 index 00000000000..a54d554e89c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f37h-289m-fjrc/GHSA-f37h-289m-fjrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f37h-289m-fjrc", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21234" + ], + "details": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21234" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21234" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f3f5-7m89-558c/GHSA-f3f5-7m89-558c.json b/advisories/unreviewed/2025/01/GHSA-f3f5-7m89-558c/GHSA-f3f5-7m89-558c.json index c8ce9c8281d..1fd53e8071f 100644 --- a/advisories/unreviewed/2025/01/GHSA-f3f5-7m89-558c/GHSA-f3f5-7m89-558c.json +++ b/advisories/unreviewed/2025/01/GHSA-f3f5-7m89-558c/GHSA-f3f5-7m89-558c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f3f5-7m89-558c", - "modified": "2025-01-10T21:31:27Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T21:31:27Z", "aliases": [ "CVE-2024-54998" ], "details": "MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T21:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f43p-rm7v-rh33/GHSA-f43p-rm7v-rh33.json b/advisories/unreviewed/2025/01/GHSA-f43p-rm7v-rh33/GHSA-f43p-rm7v-rh33.json new file mode 100644 index 00000000000..728a7c403d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f43p-rm7v-rh33/GHSA-f43p-rm7v-rh33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f43p-rm7v-rh33", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21344" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21344" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21344" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f6jw-ch5j-r8hr/GHSA-f6jw-ch5j-r8hr.json b/advisories/unreviewed/2025/01/GHSA-f6jw-ch5j-r8hr/GHSA-f6jw-ch5j-r8hr.json new file mode 100644 index 00000000000..50a7eba18ea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f6jw-ch5j-r8hr/GHSA-f6jw-ch5j-r8hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6jw-ch5j-r8hr", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21228" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21228" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21228" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f7p3-668r-j598/GHSA-f7p3-668r-j598.json b/advisories/unreviewed/2025/01/GHSA-f7p3-668r-j598/GHSA-f7p3-668r-j598.json new file mode 100644 index 00000000000..328db29a719 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f7p3-668r-j598/GHSA-f7p3-668r-j598.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7p3-668r-j598", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21298" + ], + "details": "Windows OLE Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21298" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21298" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fcxq-5j9x-8f72/GHSA-fcxq-5j9x-8f72.json b/advisories/unreviewed/2025/01/GHSA-fcxq-5j9x-8f72/GHSA-fcxq-5j9x-8f72.json new file mode 100644 index 00000000000..7762305daa9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fcxq-5j9x-8f72/GHSA-fcxq-5j9x-8f72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcxq-5j9x-8f72", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21324" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21324" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21324" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json b/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json new file mode 100644 index 00000000000..dcb78a6f7ee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffph-g3pc-8r3g", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-12088" + ], + "details": "A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12088" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12088" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330676" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json b/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json index 07fb0c00ea3..5b49a95a8d7 100644 --- a/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json +++ b/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fggw-c44p-x7gg", - "modified": "2025-01-14T15:30:56Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:56Z", "aliases": [ "CVE-2024-55000" ], "details": "Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T15:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fhhj-f5rc-qp5f/GHSA-fhhj-f5rc-qp5f.json b/advisories/unreviewed/2025/01/GHSA-fhhj-f5rc-qp5f/GHSA-fhhj-f5rc-qp5f.json new file mode 100644 index 00000000000..15f47f0e5d1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fhhj-f5rc-qp5f/GHSA-fhhj-f5rc-qp5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhhj-f5rc-qp5f", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21215" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21215" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21215" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmrx-6pfm-p8q6/GHSA-fmrx-6pfm-p8q6.json b/advisories/unreviewed/2025/01/GHSA-fmrx-6pfm-p8q6/GHSA-fmrx-6pfm-p8q6.json new file mode 100644 index 00000000000..e51f9b0e65a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmrx-6pfm-p8q6/GHSA-fmrx-6pfm-p8q6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmrx-6pfm-p8q6", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-0460" + ], + "details": "A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0460" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mcdruid/28124198128022a1c2b4060f74d99cd6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291477" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291477" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fqvw-g75c-3fc2/GHSA-fqvw-g75c-3fc2.json b/advisories/unreviewed/2025/01/GHSA-fqvw-g75c-3fc2/GHSA-fqvw-g75c-3fc2.json new file mode 100644 index 00000000000..7cf7088836e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fqvw-g75c-3fc2/GHSA-fqvw-g75c-3fc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqvw-g75c-3fc2", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21361" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21361" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21361" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-641" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fw67-4j8q-76gw/GHSA-fw67-4j8q-76gw.json b/advisories/unreviewed/2025/01/GHSA-fw67-4j8q-76gw/GHSA-fw67-4j8q-76gw.json new file mode 100644 index 00000000000..c9c04ac4520 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fw67-4j8q-76gw/GHSA-fw67-4j8q-76gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw67-4j8q-76gw", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21308" + ], + "details": "Windows Themes Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21308" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json b/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json index 10b368278e8..61c8a78e370 100644 --- a/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json +++ b/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g23p-hhrc-qr97", - "modified": "2025-01-14T15:30:56Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:56Z", "aliases": [ "CVE-2024-39774" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2030" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2030" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-g4jw-4wjw-mvmw/GHSA-g4jw-4wjw-mvmw.json b/advisories/unreviewed/2025/01/GHSA-g4jw-4wjw-mvmw/GHSA-g4jw-4wjw-mvmw.json new file mode 100644 index 00000000000..22cc843b9e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g4jw-4wjw-mvmw/GHSA-g4jw-4wjw-mvmw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4jw-4wjw-mvmw", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21301" + ], + "details": "Windows Geolocation Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21301" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21301" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g4pp-wpp3-gj6f/GHSA-g4pp-wpp3-gj6f.json b/advisories/unreviewed/2025/01/GHSA-g4pp-wpp3-gj6f/GHSA-g4pp-wpp3-gj6f.json new file mode 100644 index 00000000000..521f1d23576 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g4pp-wpp3-gj6f/GHSA-g4pp-wpp3-gj6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4pp-wpp3-gj6f", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2025-23080" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23080" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ic9448312fa7f1cbc8feac3f852bc8720568522e2" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T381220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json b/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json index f133318838b..9d28dee0e1d 100644 --- a/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json +++ b/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5cp-69v7-5p9h", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-36272" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2045" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2045" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-g5xq-ccc5-74p4/GHSA-g5xq-ccc5-74p4.json b/advisories/unreviewed/2025/01/GHSA-g5xq-ccc5-74p4/GHSA-g5xq-ccc5-74p4.json new file mode 100644 index 00000000000..a2603e97f1c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5xq-ccc5-74p4/GHSA-g5xq-ccc5-74p4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5xq-ccc5-74p4", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13164" + ], + "details": "An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13164" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json b/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json index a308f572379..4732bf9f7af 100644 --- a/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json +++ b/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g94w-vc32-h449", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13272" ], "details": "Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1220" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g98c-v7wv-8hq9/GHSA-g98c-v7wv-8hq9.json b/advisories/unreviewed/2025/01/GHSA-g98c-v7wv-8hq9/GHSA-g98c-v7wv-8hq9.json new file mode 100644 index 00000000000..4663ce5e2a0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g98c-v7wv-8hq9/GHSA-g98c-v7wv-8hq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g98c-v7wv-8hq9", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21341" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21341" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gg3w-r79x-787f/GHSA-gg3w-r79x-787f.json b/advisories/unreviewed/2025/01/GHSA-gg3w-r79x-787f/GHSA-gg3w-r79x-787f.json new file mode 100644 index 00000000000..9a0c335a026 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gg3w-r79x-787f/GHSA-gg3w-r79x-787f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg3w-r79x-787f", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13168" + ], + "details": "An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13168" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json b/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json new file mode 100644 index 00000000000..2bfe224fa8c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjv6-pfh4-3rff", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21333" + ], + "details": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21333" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21333" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gp2m-qfgf-hrqw/GHSA-gp2m-qfgf-hrqw.json b/advisories/unreviewed/2025/01/GHSA-gp2m-qfgf-hrqw/GHSA-gp2m-qfgf-hrqw.json index c264ff9e215..9d6fcab37e9 100644 --- a/advisories/unreviewed/2025/01/GHSA-gp2m-qfgf-hrqw/GHSA-gp2m-qfgf-hrqw.json +++ b/advisories/unreviewed/2025/01/GHSA-gp2m-qfgf-hrqw/GHSA-gp2m-qfgf-hrqw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gp2m-qfgf-hrqw", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57629" ], "details": "An issue in the tail_type component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json b/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json new file mode 100644 index 00000000000..f050570ebdc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp7r-m4cc-qhwq", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-12747" + ], + "details": "A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12747" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12747" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2332968" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json b/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json index 658c2812b31..14c01ff07d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json +++ b/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gpgg-3g65-72cm", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13267" ], "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-96" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:35Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gqc7-gjgf-xvmg/GHSA-gqc7-gjgf-xvmg.json b/advisories/unreviewed/2025/01/GHSA-gqc7-gjgf-xvmg/GHSA-gqc7-gjgf-xvmg.json new file mode 100644 index 00000000000..7470e4eb71f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gqc7-gjgf-xvmg/GHSA-gqc7-gjgf-xvmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqc7-gjgf-xvmg", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21251" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21251" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json b/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json index 10356a41f65..47f217ed6b8 100644 --- a/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json +++ b/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqrr-9m6w-6qhc", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-37357" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2029" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2029" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-gwpx-4h2q-gxjq/GHSA-gwpx-4h2q-gxjq.json b/advisories/unreviewed/2025/01/GHSA-gwpx-4h2q-gxjq/GHSA-gwpx-4h2q-gxjq.json new file mode 100644 index 00000000000..20146316f63 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gwpx-4h2q-gxjq/GHSA-gwpx-4h2q-gxjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwpx-4h2q-gxjq", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13170" + ], + "details": "An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13170" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json b/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json index 36ca2c78e34..8204272b474 100644 --- a/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json +++ b/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx3h-wj7q-54q9", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39358" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2027" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2027" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-h2xr-qjc7-cxj8/GHSA-h2xr-qjc7-cxj8.json b/advisories/unreviewed/2025/01/GHSA-h2xr-qjc7-cxj8/GHSA-h2xr-qjc7-cxj8.json new file mode 100644 index 00000000000..8677134a1c7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h2xr-qjc7-cxj8/GHSA-h2xr-qjc7-cxj8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2xr-qjc7-cxj8", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2025-0463" + ], + "details": "A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minipro_const_type=1&related_module=Singin. The manipulation of the argument name leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0463" + }, + { + "type": "WEB", + "url": "https://github.com/BxYQ/ld/blob/main/File_Upload_vul.doc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h36c-wpf3-58xp/GHSA-h36c-wpf3-58xp.json b/advisories/unreviewed/2025/01/GHSA-h36c-wpf3-58xp/GHSA-h36c-wpf3-58xp.json new file mode 100644 index 00000000000..d0a5da7d113 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h36c-wpf3-58xp/GHSA-h36c-wpf3-58xp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h36c-wpf3-58xp", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2025-0464" + ], + "details": "A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Section. The manipulation of the argument System Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0464" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291481" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291481" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474280" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h4x8-pvww-m327/GHSA-h4x8-pvww-m327.json b/advisories/unreviewed/2025/01/GHSA-h4x8-pvww-m327/GHSA-h4x8-pvww-m327.json new file mode 100644 index 00000000000..1e7662656ab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h4x8-pvww-m327/GHSA-h4x8-pvww-m327.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4x8-pvww-m327", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21413" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21413" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21413" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h723-vq6q-mqgg/GHSA-h723-vq6q-mqgg.json b/advisories/unreviewed/2025/01/GHSA-h723-vq6q-mqgg/GHSA-h723-vq6q-mqgg.json new file mode 100644 index 00000000000..5ec9b83953b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h723-vq6q-mqgg/GHSA-h723-vq6q-mqgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h723-vq6q-mqgg", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21232" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21232" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hccc-2mf3-43xx/GHSA-hccc-2mf3-43xx.json b/advisories/unreviewed/2025/01/GHSA-hccc-2mf3-43xx/GHSA-hccc-2mf3-43xx.json index af4641f8ec4..cdad0e1022d 100644 --- a/advisories/unreviewed/2025/01/GHSA-hccc-2mf3-43xx/GHSA-hccc-2mf3-43xx.json +++ b/advisories/unreviewed/2025/01/GHSA-hccc-2mf3-43xx/GHSA-hccc-2mf3-43xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hccc-2mf3-43xx", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57635" ], "details": "An issue in the chash_array component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hf5r-fmgp-v332/GHSA-hf5r-fmgp-v332.json b/advisories/unreviewed/2025/01/GHSA-hf5r-fmgp-v332/GHSA-hf5r-fmgp-v332.json new file mode 100644 index 00000000000..a901c010c72 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hf5r-fmgp-v332/GHSA-hf5r-fmgp-v332.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf5r-fmgp-v332", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21402" + ], + "details": "Microsoft Office OneNote Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21402" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21402" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-641" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgjf-cqqh-7c7c/GHSA-hgjf-cqqh-7c7c.json b/advisories/unreviewed/2025/01/GHSA-hgjf-cqqh-7c7c/GHSA-hgjf-cqqh-7c7c.json new file mode 100644 index 00000000000..cd8f6da52ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hgjf-cqqh-7c7c/GHSA-hgjf-cqqh-7c7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgjf-cqqh-7c7c", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21252" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21252" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hh4p-gcj4-3gx8/GHSA-hh4p-gcj4-3gx8.json b/advisories/unreviewed/2025/01/GHSA-hh4p-gcj4-3gx8/GHSA-hh4p-gcj4-3gx8.json new file mode 100644 index 00000000000..848db0f41aa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hh4p-gcj4-3gx8/GHSA-hh4p-gcj4-3gx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh4p-gcj4-3gx8", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21345" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21345" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21345" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json b/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json index 8fae968455b..9458300fcf5 100644 --- a/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json +++ b/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhjp-322f-hh5x", - "modified": "2025-01-14T15:30:56Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39608" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2036" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2036" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-hj9f-h3qv-vpjm/GHSA-hj9f-h3qv-vpjm.json b/advisories/unreviewed/2025/01/GHSA-hj9f-h3qv-vpjm/GHSA-hj9f-h3qv-vpjm.json index f56e5a08818..0a8186e9320 100644 --- a/advisories/unreviewed/2025/01/GHSA-hj9f-h3qv-vpjm/GHSA-hj9f-h3qv-vpjm.json +++ b/advisories/unreviewed/2025/01/GHSA-hj9f-h3qv-vpjm/GHSA-hj9f-h3qv-vpjm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json b/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json index 8a44a08466c..487d5d65d7d 100644 --- a/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json +++ b/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpf7-2hg3-3g3h", - "modified": "2025-01-14T15:30:54Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:54Z", "aliases": [ "CVE-2024-21797" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2028" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2028" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-hphq-5232-xjcf/GHSA-hphq-5232-xjcf.json b/advisories/unreviewed/2025/01/GHSA-hphq-5232-xjcf/GHSA-hphq-5232-xjcf.json new file mode 100644 index 00000000000..035ccbe6e15 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hphq-5232-xjcf/GHSA-hphq-5232-xjcf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hphq-5232-xjcf", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21326" + ], + "details": "Internet Explorer Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21326" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21326" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hrqr-g8jf-f28f/GHSA-hrqr-g8jf-f28f.json b/advisories/unreviewed/2025/01/GHSA-hrqr-g8jf-f28f/GHSA-hrqr-g8jf-f28f.json new file mode 100644 index 00000000000..7440d421d50 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hrqr-g8jf-f28f/GHSA-hrqr-g8jf-f28f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrqr-g8jf-f28f", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21237" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21237" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21237" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hxqj-2w4q-6p3c/GHSA-hxqj-2w4q-6p3c.json b/advisories/unreviewed/2025/01/GHSA-hxqj-2w4q-6p3c/GHSA-hxqj-2w4q-6p3c.json new file mode 100644 index 00000000000..dfd9375c246 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hxqj-2w4q-6p3c/GHSA-hxqj-2w4q-6p3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxqj-2w4q-6p3c", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21242" + ], + "details": "Windows Kerberos Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21242" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21242" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hxxh-jpvq-vr5x/GHSA-hxxh-jpvq-vr5x.json b/advisories/unreviewed/2025/01/GHSA-hxxh-jpvq-vr5x/GHSA-hxxh-jpvq-vr5x.json new file mode 100644 index 00000000000..75f0b95dd9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hxxh-jpvq-vr5x/GHSA-hxxh-jpvq-vr5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxh-jpvq-vr5x", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21223" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21223" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j3cc-8qj5-mgjv/GHSA-j3cc-8qj5-mgjv.json b/advisories/unreviewed/2025/01/GHSA-j3cc-8qj5-mgjv/GHSA-j3cc-8qj5-mgjv.json new file mode 100644 index 00000000000..9b5205713b4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j3cc-8qj5-mgjv/GHSA-j3cc-8qj5-mgjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3cc-8qj5-mgjv", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21239" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21239" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j58w-j7x2-v25v/GHSA-j58w-j7x2-v25v.json b/advisories/unreviewed/2025/01/GHSA-j58w-j7x2-v25v/GHSA-j58w-j7x2-v25v.json new file mode 100644 index 00000000000..683c9b9811b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j58w-j7x2-v25v/GHSA-j58w-j7x2-v25v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j58w-j7x2-v25v", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21258" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21258" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21258" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j5g5-c424-7xqg/GHSA-j5g5-c424-7xqg.json b/advisories/unreviewed/2025/01/GHSA-j5g5-c424-7xqg/GHSA-j5g5-c424-7xqg.json index 69bb9c2fba1..805d01e96b1 100644 --- a/advisories/unreviewed/2025/01/GHSA-j5g5-c424-7xqg/GHSA-j5g5-c424-7xqg.json +++ b/advisories/unreviewed/2025/01/GHSA-j5g5-c424-7xqg/GHSA-j5g5-c424-7xqg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-j9w9-6jj7-c2px/GHSA-j9w9-6jj7-c2px.json b/advisories/unreviewed/2025/01/GHSA-j9w9-6jj7-c2px/GHSA-j9w9-6jj7-c2px.json new file mode 100644 index 00000000000..08762211238 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j9w9-6jj7-c2px/GHSA-j9w9-6jj7-c2px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9w9-6jj7-c2px", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21307" + ], + "details": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21307" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21307" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jf83-84h5-5cc4/GHSA-jf83-84h5-5cc4.json b/advisories/unreviewed/2025/01/GHSA-jf83-84h5-5cc4/GHSA-jf83-84h5-5cc4.json new file mode 100644 index 00000000000..b4d00df3e1e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jf83-84h5-5cc4/GHSA-jf83-84h5-5cc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf83-84h5-5cc4", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21269" + ], + "details": "Windows HTML Platforms Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21269" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jf89-rq94-wxx7/GHSA-jf89-rq94-wxx7.json b/advisories/unreviewed/2025/01/GHSA-jf89-rq94-wxx7/GHSA-jf89-rq94-wxx7.json new file mode 100644 index 00000000000..c0b983a1a08 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jf89-rq94-wxx7/GHSA-jf89-rq94-wxx7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf89-rq94-wxx7", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21226" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21226" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json b/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json index cd0113a53a0..b4fa18a0579 100644 --- a/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json +++ b/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfmv-87hc-q689", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39360" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2054" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2054" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json b/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json index 272287ceba4..fc3f6f18f11 100644 --- a/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json +++ b/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhvv-hwq8-7rx2", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39756" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2024" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2024" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json b/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json index 6df96892366..0268aedacd0 100644 --- a/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json +++ b/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jjvf-4cxj-rqv4", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13275" ], "details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json b/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json index ed32694ea29..0f200c55f31 100644 --- a/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json +++ b/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw4w-2rjj-x8jv", - "modified": "2025-01-14T15:30:56Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:56Z", "aliases": [ "CVE-2024-39757" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2043" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2043" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-m2jj-8q9j-7xxg/GHSA-m2jj-8q9j-7xxg.json b/advisories/unreviewed/2025/01/GHSA-m2jj-8q9j-7xxg/GHSA-m2jj-8q9j-7xxg.json index 591a9c855d0..b84056da85a 100644 --- a/advisories/unreviewed/2025/01/GHSA-m2jj-8q9j-7xxg/GHSA-m2jj-8q9j-7xxg.json +++ b/advisories/unreviewed/2025/01/GHSA-m2jj-8q9j-7xxg/GHSA-m2jj-8q9j-7xxg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2jj-8q9j-7xxg", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57634" ], "details": "An issue in the exp_copy component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m35h-5xhm-6j2c/GHSA-m35h-5xhm-6j2c.json b/advisories/unreviewed/2025/01/GHSA-m35h-5xhm-6j2c/GHSA-m35h-5xhm-6j2c.json new file mode 100644 index 00000000000..fedf3d67652 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m35h-5xhm-6j2c/GHSA-m35h-5xhm-6j2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m35h-5xhm-6j2c", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21272" + ], + "details": "Windows COM Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21272" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21272" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m3px-rvr6-8pj6/GHSA-m3px-rvr6-8pj6.json b/advisories/unreviewed/2025/01/GHSA-m3px-rvr6-8pj6/GHSA-m3px-rvr6-8pj6.json new file mode 100644 index 00000000000..1934199f8de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m3px-rvr6-8pj6/GHSA-m3px-rvr6-8pj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3px-rvr6-8pj6", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21393" + ], + "details": "Microsoft SharePoint Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21393" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json b/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json index 8b510ab411e..2fefa9cd809 100644 --- a/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json +++ b/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m477-ghq9-m3j8", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39359" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2040" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2040" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json b/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json index d1c5d2ae831..ab1856d079b 100644 --- a/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json +++ b/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8j3-m4jx-2rhw", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13266" ], "details": "Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:35Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json b/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json index de2c3c3d287..822587d1313 100644 --- a/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json +++ b/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcpf-9j38-2vmq", - "modified": "2025-01-14T15:30:56Z", + "modified": "2025-01-14T18:31:57Z", "published": "2025-01-14T15:30:56Z", "aliases": [ "CVE-2024-39773" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2035" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2035" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-mfpq-3jm4-gh33/GHSA-mfpq-3jm4-gh33.json b/advisories/unreviewed/2025/01/GHSA-mfpq-3jm4-gh33/GHSA-mfpq-3jm4-gh33.json new file mode 100644 index 00000000000..974071df3b0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mfpq-3jm4-gh33/GHSA-mfpq-3jm4-gh33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfpq-3jm4-gh33", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21317" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21317" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mmw4-f58v-gj6m/GHSA-mmw4-f58v-gj6m.json b/advisories/unreviewed/2025/01/GHSA-mmw4-f58v-gj6m/GHSA-mmw4-f58v-gj6m.json new file mode 100644 index 00000000000..858e6cef2a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mmw4-f58v-gj6m/GHSA-mmw4-f58v-gj6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmw4-f58v-gj6m", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21319" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21319" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21319" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json b/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json new file mode 100644 index 00000000000..6fe318debdb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvph-h5j7-4h2g", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21173" + ], + "details": ".NET Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21173" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mwq3-xjfp-cjg3/GHSA-mwq3-xjfp-cjg3.json b/advisories/unreviewed/2025/01/GHSA-mwq3-xjfp-cjg3/GHSA-mwq3-xjfp-cjg3.json new file mode 100644 index 00000000000..9c808fa9fd3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mwq3-xjfp-cjg3/GHSA-mwq3-xjfp-cjg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwq3-xjfp-cjg3", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21303" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21303" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mwvv-h2v8-35j6/GHSA-mwvv-h2v8-35j6.json b/advisories/unreviewed/2025/01/GHSA-mwvv-h2v8-35j6/GHSA-mwvv-h2v8-35j6.json new file mode 100644 index 00000000000..d53f1c7f963 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mwvv-h2v8-35j6/GHSA-mwvv-h2v8-35j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwvv-h2v8-35j6", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21261" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21261" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21261" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json b/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json index 6e374c33575..0f8bc515306 100644 --- a/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json +++ b/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mxgx-9cvp-m653", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13290" ], "details": "Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mxq3-vwh4-3gfm/GHSA-mxq3-vwh4-3gfm.json b/advisories/unreviewed/2025/01/GHSA-mxq3-vwh4-3gfm/GHSA-mxq3-vwh4-3gfm.json new file mode 100644 index 00000000000..e5299b3be85 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mxq3-vwh4-3gfm/GHSA-mxq3-vwh4-3gfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxq3-vwh4-3gfm", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21370" + ], + "details": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21370" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21370" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p246-2wqm-73pp/GHSA-p246-2wqm-73pp.json b/advisories/unreviewed/2025/01/GHSA-p246-2wqm-73pp/GHSA-p246-2wqm-73pp.json new file mode 100644 index 00000000000..5726f360835 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p246-2wqm-73pp/GHSA-p246-2wqm-73pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p246-2wqm-73pp", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21411" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21411" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21411" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p2p3-g25h-5x84/GHSA-p2p3-g25h-5x84.json b/advisories/unreviewed/2025/01/GHSA-p2p3-g25h-5x84/GHSA-p2p3-g25h-5x84.json new file mode 100644 index 00000000000..b44ac8b89cd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p2p3-g25h-5x84/GHSA-p2p3-g25h-5x84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2p3-g25h-5x84", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21284" + ], + "details": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21284" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p4q7-3j6p-6gv6/GHSA-p4q7-3j6p-6gv6.json b/advisories/unreviewed/2025/01/GHSA-p4q7-3j6p-6gv6/GHSA-p4q7-3j6p-6gv6.json new file mode 100644 index 00000000000..d35d44fe039 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p4q7-3j6p-6gv6/GHSA-p4q7-3j6p-6gv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4q7-3j6p-6gv6", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21403" + ], + "details": "On-Premises Data Gateway Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21403" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p5m4-xqjq-89q2/GHSA-p5m4-xqjq-89q2.json b/advisories/unreviewed/2025/01/GHSA-p5m4-xqjq-89q2/GHSA-p5m4-xqjq-89q2.json new file mode 100644 index 00000000000..23ddb1b149c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p5m4-xqjq-89q2/GHSA-p5m4-xqjq-89q2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5m4-xqjq-89q2", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-53561" + ], + "details": "A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53561" + }, + { + "type": "WEB", + "url": "https://github.com/Mrnmap/mrnmap-cve/blob/main/CVE-2024-53561" + }, + { + "type": "WEB", + "url": "https://www.arcadyan.com/en-us/solutions/idea/fiveG" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p5r3-46vv-rccq/GHSA-p5r3-46vv-rccq.json b/advisories/unreviewed/2025/01/GHSA-p5r3-46vv-rccq/GHSA-p5r3-46vv-rccq.json new file mode 100644 index 00000000000..73c65be96b6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p5r3-46vv-rccq/GHSA-p5r3-46vv-rccq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5r3-46vv-rccq", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21187" + ], + "details": "Microsoft Power Automate Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21187" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pf9v-xg6h-m653/GHSA-pf9v-xg6h-m653.json b/advisories/unreviewed/2025/01/GHSA-pf9v-xg6h-m653/GHSA-pf9v-xg6h-m653.json index 2ac00926d75..ad1ccc3c78d 100644 --- a/advisories/unreviewed/2025/01/GHSA-pf9v-xg6h-m653/GHSA-pf9v-xg6h-m653.json +++ b/advisories/unreviewed/2025/01/GHSA-pf9v-xg6h-m653/GHSA-pf9v-xg6h-m653.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pf9v-xg6h-m653", - "modified": "2025-01-14T00:30:45Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T00:30:45Z", "aliases": [ "CVE-2023-42244" ], "details": "An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pfvh-3w7h-4375/GHSA-pfvh-3w7h-4375.json b/advisories/unreviewed/2025/01/GHSA-pfvh-3w7h-4375/GHSA-pfvh-3w7h-4375.json new file mode 100644 index 00000000000..57a797d9f46 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pfvh-3w7h-4375/GHSA-pfvh-3w7h-4375.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfvh-3w7h-4375", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21321" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21321" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21321" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json b/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json index 5ce34c37b7d..41afa855325 100644 --- a/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json +++ b/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp4g-pjj7-f6rj", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39288" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2021" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2021" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-pvh3-rvqg-w4qc/GHSA-pvh3-rvqg-w4qc.json b/advisories/unreviewed/2025/01/GHSA-pvh3-rvqg-w4qc/GHSA-pvh3-rvqg-w4qc.json new file mode 100644 index 00000000000..c50626b1519 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pvh3-rvqg-w4qc/GHSA-pvh3-rvqg-w4qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvh3-rvqg-w4qc", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2024-13171" + ], + "details": "Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13171" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pw5v-23mc-8w39/GHSA-pw5v-23mc-8w39.json b/advisories/unreviewed/2025/01/GHSA-pw5v-23mc-8w39/GHSA-pw5v-23mc-8w39.json new file mode 100644 index 00000000000..8c133debd37 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pw5v-23mc-8w39/GHSA-pw5v-23mc-8w39.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw5v-23mc-8w39", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-13180" + ], + "details": "Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13180" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-6-4-7-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json b/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json index 2a4867f71ce..69dbd439eab 100644 --- a/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json +++ b/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px43-x9c5-2gjv", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39294" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2026" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2026" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-pxf8-r239-8j9j/GHSA-pxf8-r239-8j9j.json b/advisories/unreviewed/2025/01/GHSA-pxf8-r239-8j9j/GHSA-pxf8-r239-8j9j.json new file mode 100644 index 00000000000..b2147d3301f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pxf8-r239-8j9j/GHSA-pxf8-r239-8j9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxf8-r239-8j9j", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21288" + ], + "details": "Windows COM Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21288" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21288" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q2c4-ph6r-767x/GHSA-q2c4-ph6r-767x.json b/advisories/unreviewed/2025/01/GHSA-q2c4-ph6r-767x/GHSA-q2c4-ph6r-767x.json index 92452406474..ed92484dbae 100644 --- a/advisories/unreviewed/2025/01/GHSA-q2c4-ph6r-767x/GHSA-q2c4-ph6r-767x.json +++ b/advisories/unreviewed/2025/01/GHSA-q2c4-ph6r-767x/GHSA-q2c4-ph6r-767x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q2c4-ph6r-767x", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57628" ], "details": "An issue in the exp_values_set_supertype component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q38m-5f88-27wv/GHSA-q38m-5f88-27wv.json b/advisories/unreviewed/2025/01/GHSA-q38m-5f88-27wv/GHSA-q38m-5f88-27wv.json new file mode 100644 index 00000000000..ad02e931d70 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q38m-5f88-27wv/GHSA-q38m-5f88-27wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q38m-5f88-27wv", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21227" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21227" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q4p3-fg3r-g43m/GHSA-q4p3-fg3r-g43m.json b/advisories/unreviewed/2025/01/GHSA-q4p3-fg3r-g43m/GHSA-q4p3-fg3r-g43m.json new file mode 100644 index 00000000000..fb3261fd8a9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q4p3-fg3r-g43m/GHSA-q4p3-fg3r-g43m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4p3-fg3r-g43m", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:59Z", + "aliases": [ + "CVE-2024-53563" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53563" + }, + { + "type": "WEB", + "url": "https://github.com/Mrnmap/mrnmap-cve/blob/main/CVE-2024-53563." + }, + { + "type": "WEB", + "url": "https://www.arcadyan.com/en-us/solutions/idea/fiveG" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q7w5-5jr2-5xg5/GHSA-q7w5-5jr2-5xg5.json b/advisories/unreviewed/2025/01/GHSA-q7w5-5jr2-5xg5/GHSA-q7w5-5jr2-5xg5.json new file mode 100644 index 00000000000..81a79b90fae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q7w5-5jr2-5xg5/GHSA-q7w5-5jr2-5xg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7w5-5jr2-5xg5", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21374" + ], + "details": "Windows CSC Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21374" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qccp-2vxv-82w5/GHSA-qccp-2vxv-82w5.json b/advisories/unreviewed/2025/01/GHSA-qccp-2vxv-82w5/GHSA-qccp-2vxv-82w5.json new file mode 100644 index 00000000000..88c174d6d42 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qccp-2vxv-82w5/GHSA-qccp-2vxv-82w5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qccp-2vxv-82w5", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2024-13172" + ], + "details": "Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13172" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcv4-8qfq-9w76/GHSA-qcv4-8qfq-9w76.json b/advisories/unreviewed/2025/01/GHSA-qcv4-8qfq-9w76/GHSA-qcv4-8qfq-9w76.json new file mode 100644 index 00000000000..94cc4dffa9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcv4-8qfq-9w76/GHSA-qcv4-8qfq-9w76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcv4-8qfq-9w76", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21291" + ], + "details": "Windows Direct Show Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21291" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qgf5-w7jw-p449/GHSA-qgf5-w7jw-p449.json b/advisories/unreviewed/2025/01/GHSA-qgf5-w7jw-p449/GHSA-qgf5-w7jw-p449.json new file mode 100644 index 00000000000..efc76ae9754 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qgf5-w7jw-p449/GHSA-qgf5-w7jw-p449.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgf5-w7jw-p449", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21225" + ], + "details": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21225" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qj4x-5pg7-4g2c/GHSA-qj4x-5pg7-4g2c.json b/advisories/unreviewed/2025/01/GHSA-qj4x-5pg7-4g2c/GHSA-qj4x-5pg7-4g2c.json index b70bb65588d..0169c101f41 100644 --- a/advisories/unreviewed/2025/01/GHSA-qj4x-5pg7-4g2c/GHSA-qj4x-5pg7-4g2c.json +++ b/advisories/unreviewed/2025/01/GHSA-qj4x-5pg7-4g2c/GHSA-qj4x-5pg7-4g2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qj4x-5pg7-4g2c", - "modified": "2025-01-10T21:31:27Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T21:31:27Z", "aliases": [ "CVE-2024-54994" ], "details": "MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T21:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qm6j-jqgw-8fcg/GHSA-qm6j-jqgw-8fcg.json b/advisories/unreviewed/2025/01/GHSA-qm6j-jqgw-8fcg/GHSA-qm6j-jqgw-8fcg.json new file mode 100644 index 00000000000..9a399ed5ab9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qm6j-jqgw-8fcg/GHSA-qm6j-jqgw-8fcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm6j-jqgw-8fcg", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2024-13169" + ], + "details": "An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13169" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qp84-727m-58qv/GHSA-qp84-727m-58qv.json b/advisories/unreviewed/2025/01/GHSA-qp84-727m-58qv/GHSA-qp84-727m-58qv.json new file mode 100644 index 00000000000..acb9a9834f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qp84-727m-58qv/GHSA-qp84-727m-58qv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp84-727m-58qv", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-22984" + ], + "details": "An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22984" + }, + { + "type": "WEB", + "url": "https://github.com/H3rmesk1t/vulnerability-paper/blob/main/iceCMS-2.2.0-Incorrect%20Access%20Control2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qqjh-p6qj-wj2q/GHSA-qqjh-p6qj-wj2q.json b/advisories/unreviewed/2025/01/GHSA-qqjh-p6qj-wj2q/GHSA-qqjh-p6qj-wj2q.json new file mode 100644 index 00000000000..bb881355eaa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qqjh-p6qj-wj2q/GHSA-qqjh-p6qj-wj2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqjh-p6qj-wj2q", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21378" + ], + "details": "Windows CSC Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21378" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21378" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qrj7-3jjm-h7x2/GHSA-qrj7-3jjm-h7x2.json b/advisories/unreviewed/2025/01/GHSA-qrj7-3jjm-h7x2/GHSA-qrj7-3jjm-h7x2.json new file mode 100644 index 00000000000..f1c515dd5ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qrj7-3jjm-h7x2/GHSA-qrj7-3jjm-h7x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrj7-3jjm-h7x2", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21243" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21243" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qxh8-4p4c-qchr/GHSA-qxh8-4p4c-qchr.json b/advisories/unreviewed/2025/01/GHSA-qxh8-4p4c-qchr/GHSA-qxh8-4p4c-qchr.json new file mode 100644 index 00000000000..f1665067628 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qxh8-4p4c-qchr/GHSA-qxh8-4p4c-qchr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxh8-4p4c-qchr", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21331" + ], + "details": "Windows Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21331" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21331" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r4x4-pw96-gj4q/GHSA-r4x4-pw96-gj4q.json b/advisories/unreviewed/2025/01/GHSA-r4x4-pw96-gj4q/GHSA-r4x4-pw96-gj4q.json new file mode 100644 index 00000000000..e25a4c2df7f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r4x4-pw96-gj4q/GHSA-r4x4-pw96-gj4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4x4-pw96-gj4q", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21296" + ], + "details": "BranchCache Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21296" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r6pg-vpjp-mw6r/GHSA-r6pg-vpjp-mw6r.json b/advisories/unreviewed/2025/01/GHSA-r6pg-vpjp-mw6r/GHSA-r6pg-vpjp-mw6r.json new file mode 100644 index 00000000000..96f81b76a20 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r6pg-vpjp-mw6r/GHSA-r6pg-vpjp-mw6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6pg-vpjp-mw6r", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21244" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21244" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json b/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json index 7b624f46d53..2db74c820e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json +++ b/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r79f-v7w7-jv39", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-57214" ], "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T17:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r7wm-q44r-7365/GHSA-r7wm-q44r-7365.json b/advisories/unreviewed/2025/01/GHSA-r7wm-q44r-7365/GHSA-r7wm-q44r-7365.json new file mode 100644 index 00000000000..207a02c0b1b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r7wm-q44r-7365/GHSA-r7wm-q44r-7365.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7wm-q44r-7365", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21255" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21255" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r8vg-q4g8-j937/GHSA-r8vg-q4g8-j937.json b/advisories/unreviewed/2025/01/GHSA-r8vg-q4g8-j937/GHSA-r8vg-q4g8-j937.json new file mode 100644 index 00000000000..5fe5c073bc5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r8vg-q4g8-j937/GHSA-r8vg-q4g8-j937.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8vg-q4g8-j937", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21249" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21249" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r8xh-9645-25vq/GHSA-r8xh-9645-25vq.json b/advisories/unreviewed/2025/01/GHSA-r8xh-9645-25vq/GHSA-r8xh-9645-25vq.json new file mode 100644 index 00000000000..77ec7e7c3fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r8xh-9645-25vq/GHSA-r8xh-9645-25vq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8xh-9645-25vq", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21336" + ], + "details": "Windows Cryptographic Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21336" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21336" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json b/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json index 7bd334ca785..1262d43689a 100644 --- a/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json +++ b/advisories/unreviewed/2025/01/GHSA-rf94-f4r9-6gxh/GHSA-rf94-f4r9-6gxh.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-rg56-4h6q-rfgq/GHSA-rg56-4h6q-rfgq.json b/advisories/unreviewed/2025/01/GHSA-rg56-4h6q-rfgq/GHSA-rg56-4h6q-rfgq.json new file mode 100644 index 00000000000..ff28a486a71 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rg56-4h6q-rfgq/GHSA-rg56-4h6q-rfgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg56-4h6q-rfgq", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13165" + ], + "details": "An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13165" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rh7v-6pc9-xcj8/GHSA-rh7v-6pc9-xcj8.json b/advisories/unreviewed/2025/01/GHSA-rh7v-6pc9-xcj8/GHSA-rh7v-6pc9-xcj8.json new file mode 100644 index 00000000000..1c118ecd363 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rh7v-6pc9-xcj8/GHSA-rh7v-6pc9-xcj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh7v-6pc9-xcj8", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21235" + ], + "details": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21235" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rpm2-368c-rjhr/GHSA-rpm2-368c-rjhr.json b/advisories/unreviewed/2025/01/GHSA-rpm2-368c-rjhr/GHSA-rpm2-368c-rjhr.json new file mode 100644 index 00000000000..0b9b47bf4cc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rpm2-368c-rjhr/GHSA-rpm2-368c-rjhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpm2-368c-rjhr", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21362" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21362" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rpr6-945p-jm7x/GHSA-rpr6-945p-jm7x.json b/advisories/unreviewed/2025/01/GHSA-rpr6-945p-jm7x/GHSA-rpr6-945p-jm7x.json new file mode 100644 index 00000000000..a154ecce2ff --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rpr6-945p-jm7x/GHSA-rpr6-945p-jm7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpr6-945p-jm7x", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21289" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21289" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rrm6-257m-2hgw/GHSA-rrm6-257m-2hgw.json b/advisories/unreviewed/2025/01/GHSA-rrm6-257m-2hgw/GHSA-rrm6-257m-2hgw.json new file mode 100644 index 00000000000..23e1141c0cf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrm6-257m-2hgw/GHSA-rrm6-257m-2hgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrm6-257m-2hgw", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21343" + ], + "details": "Windows Web Threat Defense User Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21343" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rv7m-pr5x-3rwr/GHSA-rv7m-pr5x-3rwr.json b/advisories/unreviewed/2025/01/GHSA-rv7m-pr5x-3rwr/GHSA-rv7m-pr5x-3rwr.json new file mode 100644 index 00000000000..aa87b4eacbf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rv7m-pr5x-3rwr/GHSA-rv7m-pr5x-3rwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv7m-pr5x-3rwr", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21256" + ], + "details": "Windows Digital Media Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21256" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rwr7-2j6f-mmh5/GHSA-rwr7-2j6f-mmh5.json b/advisories/unreviewed/2025/01/GHSA-rwr7-2j6f-mmh5/GHSA-rwr7-2j6f-mmh5.json new file mode 100644 index 00000000000..7d951351cbe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rwr7-2j6f-mmh5/GHSA-rwr7-2j6f-mmh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwr7-2j6f-mmh5", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21241" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21241" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rxpj-8v23-cxvr/GHSA-rxpj-8v23-cxvr.json b/advisories/unreviewed/2025/01/GHSA-rxpj-8v23-cxvr/GHSA-rxpj-8v23-cxvr.json index 85e2bfe0adb..78753ced741 100644 --- a/advisories/unreviewed/2025/01/GHSA-rxpj-8v23-cxvr/GHSA-rxpj-8v23-cxvr.json +++ b/advisories/unreviewed/2025/01/GHSA-rxpj-8v23-cxvr/GHSA-rxpj-8v23-cxvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rxpj-8v23-cxvr", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57636" ], "details": "An issue in the itc_sample_row_check component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rxwm-pw9q-mfxp/GHSA-rxwm-pw9q-mfxp.json b/advisories/unreviewed/2025/01/GHSA-rxwm-pw9q-mfxp/GHSA-rxwm-pw9q-mfxp.json new file mode 100644 index 00000000000..87708a7e8fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rxwm-pw9q-mfxp/GHSA-rxwm-pw9q-mfxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxwm-pw9q-mfxp", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-21395" + ], + "details": "Microsoft Access Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21395" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21395" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v29f-v8vv-v975/GHSA-v29f-v8vv-v975.json b/advisories/unreviewed/2025/01/GHSA-v29f-v8vv-v975/GHSA-v29f-v8vv-v975.json new file mode 100644 index 00000000000..7fcc85a1bd9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v29f-v8vv-v975/GHSA-v29f-v8vv-v975.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v29f-v8vv-v975", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2024-29980" + ], + "details": "Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29980" + }, + { + "type": "WEB", + "url": "https://www.phoenix.com/phoenix-security-notifications/cve-2024-29980" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json b/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json new file mode 100644 index 00000000000..2fbb8acb74d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v4f3-8wwc-j9x2/GHSA-v4f3-8wwc-j9x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4f3-8wwc-j9x2", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21224" + ], + "details": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21224" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v5w4-fvfm-37m6/GHSA-v5w4-fvfm-37m6.json b/advisories/unreviewed/2025/01/GHSA-v5w4-fvfm-37m6/GHSA-v5w4-fvfm-37m6.json new file mode 100644 index 00000000000..b7d99f554bf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v5w4-fvfm-37m6/GHSA-v5w4-fvfm-37m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5w4-fvfm-37m6", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21323" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21323" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21323" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v676-9fq8-rqq8/GHSA-v676-9fq8-rqq8.json b/advisories/unreviewed/2025/01/GHSA-v676-9fq8-rqq8/GHSA-v676-9fq8-rqq8.json new file mode 100644 index 00000000000..d9d2cd93f1c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v676-9fq8-rqq8/GHSA-v676-9fq8-rqq8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v676-9fq8-rqq8", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-22983" + ], + "details": "An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22983" + }, + { + "type": "WEB", + "url": "https://github.com/H3rmesk1t/vulnerability-paper/blob/main/iceCMS-2.2.0-Incorrect%20Access%20Control.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v6xj-8rhx-w2r4/GHSA-v6xj-8rhx-w2r4.json b/advisories/unreviewed/2025/01/GHSA-v6xj-8rhx-w2r4/GHSA-v6xj-8rhx-w2r4.json new file mode 100644 index 00000000000..73d989ca90b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v6xj-8rhx-w2r4/GHSA-v6xj-8rhx-w2r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6xj-8rhx-w2r4", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21273" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21273" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21273" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v77c-hvv5-38w8/GHSA-v77c-hvv5-38w8.json b/advisories/unreviewed/2025/01/GHSA-v77c-hvv5-38w8/GHSA-v77c-hvv5-38w8.json new file mode 100644 index 00000000000..e537c051a56 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v77c-hvv5-38w8/GHSA-v77c-hvv5-38w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v77c-hvv5-38w8", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21304" + ], + "details": "Microsoft DWM Core Library Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21304" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21304" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v9wq-479p-2jwm/GHSA-v9wq-479p-2jwm.json b/advisories/unreviewed/2025/01/GHSA-v9wq-479p-2jwm/GHSA-v9wq-479p-2jwm.json new file mode 100644 index 00000000000..047385ca56d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v9wq-479p-2jwm/GHSA-v9wq-479p-2jwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9wq-479p-2jwm", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21306" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21306" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21306" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfp6-f89h-v2rh/GHSA-vfp6-f89h-v2rh.json b/advisories/unreviewed/2025/01/GHSA-vfp6-f89h-v2rh/GHSA-vfp6-f89h-v2rh.json new file mode 100644 index 00000000000..766df0fbb85 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfp6-f89h-v2rh/GHSA-vfp6-f89h-v2rh.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfp6-f89h-v2rh", + "modified": "2025-01-14T18:32:06Z", + "published": "2025-01-14T18:32:06Z", + "aliases": [ + "CVE-2025-23052" + ], + "details": "Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23052" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04723en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfwj-j76c-r7mf/GHSA-vfwj-j76c-r7mf.json b/advisories/unreviewed/2025/01/GHSA-vfwj-j76c-r7mf/GHSA-vfwj-j76c-r7mf.json new file mode 100644 index 00000000000..ee2ed64c6a2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfwj-j76c-r7mf/GHSA-vfwj-j76c-r7mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfwj-j76c-r7mf", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21366" + ], + "details": "Microsoft Access Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21366" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21366" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vh7p-jh36-p55r/GHSA-vh7p-jh36-p55r.json b/advisories/unreviewed/2025/01/GHSA-vh7p-jh36-p55r/GHSA-vh7p-jh36-p55r.json new file mode 100644 index 00000000000..4dce6a350ef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vh7p-jh36-p55r/GHSA-vh7p-jh36-p55r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh7p-jh36-p55r", + "modified": "2025-01-14T18:32:01Z", + "published": "2025-01-14T18:32:01Z", + "aliases": [ + "CVE-2024-13166" + ], + "details": "An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13166" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vp5q-499v-968r/GHSA-vp5q-499v-968r.json b/advisories/unreviewed/2025/01/GHSA-vp5q-499v-968r/GHSA-vp5q-499v-968r.json new file mode 100644 index 00000000000..e416667cebf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vp5q-499v-968r/GHSA-vp5q-499v-968r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp5q-499v-968r", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21268" + ], + "details": "MapUrlToZone Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21268" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21268" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vphw-2w3h-qj8c/GHSA-vphw-2w3h-qj8c.json b/advisories/unreviewed/2025/01/GHSA-vphw-2w3h-qj8c/GHSA-vphw-2w3h-qj8c.json new file mode 100644 index 00000000000..29eb74eedbf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vphw-2w3h-qj8c/GHSA-vphw-2w3h-qj8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vphw-2w3h-qj8c", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21210" + ], + "details": "Windows BitLocker Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21210" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21210" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-636" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vr4q-g244-9x55/GHSA-vr4q-g244-9x55.json b/advisories/unreviewed/2025/01/GHSA-vr4q-g244-9x55/GHSA-vr4q-g244-9x55.json new file mode 100644 index 00000000000..8ade1ea5562 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vr4q-g244-9x55/GHSA-vr4q-g244-9x55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr4q-g244-9x55", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21186" + ], + "details": "Microsoft Access Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21186" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vrvf-5hvc-h4g2/GHSA-vrvf-5hvc-h4g2.json b/advisories/unreviewed/2025/01/GHSA-vrvf-5hvc-h4g2/GHSA-vrvf-5hvc-h4g2.json new file mode 100644 index 00000000000..348d828b156 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vrvf-5hvc-h4g2/GHSA-vrvf-5hvc-h4g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrvf-5hvc-h4g2", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21218" + ], + "details": "Windows Kerberos Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21218" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vvhx-467p-5wjq/GHSA-vvhx-467p-5wjq.json b/advisories/unreviewed/2025/01/GHSA-vvhx-467p-5wjq/GHSA-vvhx-467p-5wjq.json new file mode 100644 index 00000000000..3e3ebb425df --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vvhx-467p-5wjq/GHSA-vvhx-467p-5wjq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvhx-467p-5wjq", + "modified": "2025-01-14T18:31:59Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-0461" + ], + "details": "A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minipro_const_type=1&related_module=Singin. The manipulation of the argument pathfile leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0461" + }, + { + "type": "WEB", + "url": "https://github.com/BxYQ/ld/blob/main/downloadSocialPromotionQrcode_fileread.doc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291478" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291478" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w22v-wrfq-q6j9/GHSA-w22v-wrfq-q6j9.json b/advisories/unreviewed/2025/01/GHSA-w22v-wrfq-q6j9/GHSA-w22v-wrfq-q6j9.json new file mode 100644 index 00000000000..7c15bb912a8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w22v-wrfq-q6j9/GHSA-w22v-wrfq-q6j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w22v-wrfq-q6j9", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21364" + ], + "details": "Microsoft Excel Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21364" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w2xr-7cgg-6wx5/GHSA-w2xr-7cgg-6wx5.json b/advisories/unreviewed/2025/01/GHSA-w2xr-7cgg-6wx5/GHSA-w2xr-7cgg-6wx5.json new file mode 100644 index 00000000000..320b135f785 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w2xr-7cgg-6wx5/GHSA-w2xr-7cgg-6wx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2xr-7cgg-6wx5", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21285" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21285" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3rx-f2fq-82cx/GHSA-w3rx-f2fq-82cx.json b/advisories/unreviewed/2025/01/GHSA-w3rx-f2fq-82cx/GHSA-w3rx-f2fq-82cx.json new file mode 100644 index 00000000000..0caefcad342 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3rx-f2fq-82cx/GHSA-w3rx-f2fq-82cx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3rx-f2fq-82cx", + "modified": "2025-01-14T18:32:05Z", + "published": "2025-01-14T18:32:05Z", + "aliases": [ + "CVE-2025-21354" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21354" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21354" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w4cp-3f3m-xjx3/GHSA-w4cp-3f3m-xjx3.json b/advisories/unreviewed/2025/01/GHSA-w4cp-3f3m-xjx3/GHSA-w4cp-3f3m-xjx3.json new file mode 100644 index 00000000000..1d886d8ea8f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w4cp-3f3m-xjx3/GHSA-w4cp-3f3m-xjx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4cp-3f3m-xjx3", + "modified": "2025-01-14T18:32:02Z", + "published": "2025-01-14T18:32:02Z", + "aliases": [ + "CVE-2025-21236" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21236" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21236" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w569-9p5v-c7v7/GHSA-w569-9p5v-c7v7.json b/advisories/unreviewed/2025/01/GHSA-w569-9p5v-c7v7/GHSA-w569-9p5v-c7v7.json new file mode 100644 index 00000000000..a9463b90420 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w569-9p5v-c7v7/GHSA-w569-9p5v-c7v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w569-9p5v-c7v7", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21297" + ], + "details": "Windows Remote Desktop Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21297" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21297" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w825-mc9p-6wp6/GHSA-w825-mc9p-6wp6.json b/advisories/unreviewed/2025/01/GHSA-w825-mc9p-6wp6/GHSA-w825-mc9p-6wp6.json new file mode 100644 index 00000000000..828bb4f6452 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w825-mc9p-6wp6/GHSA-w825-mc9p-6wp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w825-mc9p-6wp6", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21290" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21290" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21290" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w8wg-643q-c36v/GHSA-w8wg-643q-c36v.json b/advisories/unreviewed/2025/01/GHSA-w8wg-643q-c36v/GHSA-w8wg-643q-c36v.json new file mode 100644 index 00000000000..08a8da86d44 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w8wg-643q-c36v/GHSA-w8wg-643q-c36v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8wg-643q-c36v", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21305" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21305" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w9m7-qmvh-fvcw/GHSA-w9m7-qmvh-fvcw.json b/advisories/unreviewed/2025/01/GHSA-w9m7-qmvh-fvcw/GHSA-w9m7-qmvh-fvcw.json new file mode 100644 index 00000000000..3217c3dd5ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w9m7-qmvh-fvcw/GHSA-w9m7-qmvh-fvcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9m7-qmvh-fvcw", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21295" + ], + "details": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21295" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21295" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json b/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json index 9237c7710c0..45bd7a561b6 100644 --- a/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json +++ b/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9pq-h9mh-jm92", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-36493" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2041" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2041" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json b/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json index 2add07ce194..336a2016547 100644 --- a/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json +++ b/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcvc-h2qg-4xqg", - "modified": "2025-01-14T15:30:55Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T15:30:55Z", "aliases": [ "CVE-2024-39357" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2039" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2039" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-wgqq-7g8w-8xm9/GHSA-wgqq-7g8w-8xm9.json b/advisories/unreviewed/2025/01/GHSA-wgqq-7g8w-8xm9/GHSA-wgqq-7g8w-8xm9.json index 243dd01e109..09182c5248f 100644 --- a/advisories/unreviewed/2025/01/GHSA-wgqq-7g8w-8xm9/GHSA-wgqq-7g8w-8xm9.json +++ b/advisories/unreviewed/2025/01/GHSA-wgqq-7g8w-8xm9/GHSA-wgqq-7g8w-8xm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgqq-7g8w-8xm9", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-14T18:31:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57661" ], "details": "An issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wjfg-g3gx-pmfx/GHSA-wjfg-g3gx-pmfx.json b/advisories/unreviewed/2025/01/GHSA-wjfg-g3gx-pmfx/GHSA-wjfg-g3gx-pmfx.json new file mode 100644 index 00000000000..38cfc8af74b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjfg-g3gx-pmfx/GHSA-wjfg-g3gx-pmfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjfg-g3gx-pmfx", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21287" + ], + "details": "Windows Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21287" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjjq-gj36-2h2c/GHSA-wjjq-gj36-2h2c.json b/advisories/unreviewed/2025/01/GHSA-wjjq-gj36-2h2c/GHSA-wjjq-gj36-2h2c.json index 1ed23871c56..752bd4ee8a8 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjjq-gj36-2h2c/GHSA-wjjq-gj36-2h2c.json +++ b/advisories/unreviewed/2025/01/GHSA-wjjq-gj36-2h2c/GHSA-wjjq-gj36-2h2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjjq-gj36-2h2c", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57631" ], "details": "An issue in the exp_ref component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wjm7-5g3p-88v2/GHSA-wjm7-5g3p-88v2.json b/advisories/unreviewed/2025/01/GHSA-wjm7-5g3p-88v2/GHSA-wjm7-5g3p-88v2.json new file mode 100644 index 00000000000..90fe6c02262 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjm7-5g3p-88v2/GHSA-wjm7-5g3p-88v2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjm7-5g3p-88v2", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21245" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21245" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wvcc-xqrc-2v2x/GHSA-wvcc-xqrc-2v2x.json b/advisories/unreviewed/2025/01/GHSA-wvcc-xqrc-2v2x/GHSA-wvcc-xqrc-2v2x.json index 817e5adf3a6..7feef479698 100644 --- a/advisories/unreviewed/2025/01/GHSA-wvcc-xqrc-2v2x/GHSA-wvcc-xqrc-2v2x.json +++ b/advisories/unreviewed/2025/01/GHSA-wvcc-xqrc-2v2x/GHSA-wvcc-xqrc-2v2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wvcc-xqrc-2v2x", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-14T18:31:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57630" ], "details": "An issue in the exps_card component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ww6w-vmf9-9rg3/GHSA-ww6w-vmf9-9rg3.json b/advisories/unreviewed/2025/01/GHSA-ww6w-vmf9-9rg3/GHSA-ww6w-vmf9-9rg3.json new file mode 100644 index 00000000000..12b98cb7191 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ww6w-vmf9-9rg3/GHSA-ww6w-vmf9-9rg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww6w-vmf9-9rg3", + "modified": "2025-01-14T18:32:04Z", + "published": "2025-01-14T18:32:04Z", + "aliases": [ + "CVE-2025-21320" + ], + "details": "Windows Kernel Memory Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21320" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21320" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x4p9-p8g9-v45f/GHSA-x4p9-p8g9-v45f.json b/advisories/unreviewed/2025/01/GHSA-x4p9-p8g9-v45f/GHSA-x4p9-p8g9-v45f.json new file mode 100644 index 00000000000..5d4946ef010 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x4p9-p8g9-v45f/GHSA-x4p9-p8g9-v45f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4p9-p8g9-v45f", + "modified": "2025-01-14T18:31:57Z", + "published": "2025-01-14T18:31:57Z", + "aliases": [ + "CVE-2024-29979" + ], + "details": "Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29979" + }, + { + "type": "WEB", + "url": "https://www.phoenix.com/phoenix-security-notifications/cve-2024-29979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x8hj-c95g-qr2q/GHSA-x8hj-c95g-qr2q.json b/advisories/unreviewed/2025/01/GHSA-x8hj-c95g-qr2q/GHSA-x8hj-c95g-qr2q.json new file mode 100644 index 00000000000..5bdb3e4911a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x8hj-c95g-qr2q/GHSA-x8hj-c95g-qr2q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8hj-c95g-qr2q", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2025-0462" + ], + "details": "A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minipro_const_type=1. The manipulation of the argument searchcontent leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0462" + }, + { + "type": "WEB", + "url": "https://github.com/BxYQ/ld/blob/main/ListView_SQL.doc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291479" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291479" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x8j8-538p-x6xv/GHSA-x8j8-538p-x6xv.json b/advisories/unreviewed/2025/01/GHSA-x8j8-538p-x6xv/GHSA-x8j8-538p-x6xv.json new file mode 100644 index 00000000000..1bc72752a14 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x8j8-538p-x6xv/GHSA-x8j8-538p-x6xv.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8j8-538p-x6xv", + "modified": "2025-01-14T18:31:58Z", + "published": "2025-01-14T18:31:58Z", + "aliases": [ + "CVE-2025-0459" + ], + "details": "A vulnerability, which was classified as problematic, has been found in libretro RetroArch up to 1.19.1 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll of the component Startup. The manipulation leads to untrusted search path. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0459" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291476" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291476" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json new file mode 100644 index 00000000000..082da399850 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh5q-pch5-g3xq", + "modified": "2025-01-14T18:32:00Z", + "published": "2025-01-14T18:32:00Z", + "aliases": [ + "CVE-2024-12085" + ], + "details": "A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12085" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12085" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330539" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xw7m-49qm-2x39/GHSA-xw7m-49qm-2x39.json b/advisories/unreviewed/2025/01/GHSA-xw7m-49qm-2x39/GHSA-xw7m-49qm-2x39.json new file mode 100644 index 00000000000..2b96d435608 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xw7m-49qm-2x39/GHSA-xw7m-49qm-2x39.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw7m-49qm-2x39", + "modified": "2025-01-14T18:32:03Z", + "published": "2025-01-14T18:32:03Z", + "aliases": [ + "CVE-2025-21275" + ], + "details": "Windows App Package Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21275" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T18:15:47Z" + } +} \ No newline at end of file