From a2765465f2db88edabf5485ce6fc898699d4212b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 7 Mar 2025 18:32:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cg2v-9v73-ccwp.json | 10 ++++- .../GHSA-3xqx-95w6-xjv4.json | 6 ++- .../GHSA-82v2-v4p5-fg34.json | 2 +- .../GHSA-86xc-fp29-26g2.json | 4 +- .../GHSA-86xh-6qhg-p6c2.json | 6 ++- .../GHSA-fm6r-qcm7-79pj.json | 4 +- .../GHSA-fr68-cm8v-7vv6.json | 2 +- .../GHSA-m789-8jxv-f7m3.json | 2 +- .../GHSA-pcwc-3rj4-gj54.json | 6 ++- .../GHSA-qc7r-x584-w555.json | 1 + .../GHSA-xcc8-3vrq-wjg2.json | 14 ++++++- .../GHSA-69v8-v8v7-vv42.json | 6 ++- .../GHSA-vxmc-w576-mqxx.json | 6 ++- .../GHSA-8jh7-gcv4-cq6q.json | 19 +++++++-- .../GHSA-chw9-726p-m659.json | 4 +- .../GHSA-ffg2-5fg9-qrwc.json | 4 +- .../GHSA-g7g4-7563-37xc.json | 6 ++- .../GHSA-g477-g2gm-cjmf.json | 6 ++- .../GHSA-58m7-hfr6-rrx2.json | 10 ++++- .../GHSA-gh27-x7g8-9fv7.json | 6 ++- .../GHSA-mh8w-gxgh-8grm.json | 6 ++- .../GHSA-qq67-p454-7jfc.json | 6 ++- .../GHSA-6gmm-x3pr-vhmf.json | 6 ++- .../GHSA-g3c8-2g4x-qq2h.json | 6 ++- .../GHSA-gjv6-pfh4-3rff.json | 10 ++++- .../GHSA-c82f-pmfx-x3vv.json | 6 ++- .../GHSA-j98h-85cg-gvmj.json | 6 ++- .../GHSA-j992-gmv8-p6vw.json | 6 ++- .../GHSA-qc22-v4cr-4rv7.json | 6 ++- .../GHSA-vq63-h845-wgm6.json | 6 ++- .../GHSA-24g2-6vx6-3vf6.json | 36 ++++++++++++++++ .../GHSA-3243-w5fh-rcj8.json | 40 ++++++++++++++++++ .../GHSA-3p6v-922c-mrw6.json | 36 ++++++++++++++++ .../GHSA-3xx8-jmfq-qf34.json | 41 +++++++++++++++++++ .../GHSA-42qm-8j3v-68c9.json | 36 ++++++++++++++++ .../GHSA-55g6-rmp8-f2fq.json | 15 +++++-- .../GHSA-56j5-vwwf-v97g.json | 36 ++++++++++++++++ .../GHSA-69r2-5wxm-3hf6.json | 18 +++++++- .../GHSA-6r8h-8x56-2jqr.json | 41 +++++++++++++++++++ .../GHSA-73vc-g45m-99m9.json | 36 ++++++++++++++++ .../GHSA-744j-f9r9-w6h7.json | 41 +++++++++++++++++++ .../GHSA-9973-9x4h-pfgx.json | 36 ++++++++++++++++ .../GHSA-9h49-4vx3-2m5r.json | 6 ++- .../GHSA-c346-qq93-pfrw.json | 15 +++++-- .../GHSA-fgjx-56hm-4qrp.json | 6 ++- .../GHSA-gqcv-8xh2-hqvg.json | 11 +++-- .../GHSA-gv88-vwqw-9qgj.json | 36 ++++++++++++++++ .../GHSA-h877-4279-qcfv.json | 36 ++++++++++++++++ .../GHSA-j79q-5fqv-hj78.json | 36 ++++++++++++++++ .../GHSA-p293-86cr-rj34.json | 36 ++++++++++++++++ .../GHSA-pcj4-9fcj-56c8.json | 6 ++- .../GHSA-pppp-mqfr-xwwh.json | 6 ++- .../GHSA-q469-433j-8xc2.json | 36 ++++++++++++++++ .../GHSA-rfr3-g285-rggj.json | 36 ++++++++++++++++ .../GHSA-rh3q-7g79-rp3x.json | 6 ++- .../GHSA-v5xf-gj23-85jx.json | 6 ++- .../GHSA-vj79-3hwh-jcf7.json | 36 ++++++++++++++++ .../GHSA-w6xj-4jx7-p88w.json | 40 ++++++++++++++++++ .../GHSA-x5m3-m392-xf85.json | 15 +++++-- .../GHSA-xvw8-mqg6-cchx.json | 36 ++++++++++++++++ 60 files changed, 950 insertions(+), 55 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-24g2-6vx6-3vf6/GHSA-24g2-6vx6-3vf6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3243-w5fh-rcj8/GHSA-3243-w5fh-rcj8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3p6v-922c-mrw6/GHSA-3p6v-922c-mrw6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3xx8-jmfq-qf34/GHSA-3xx8-jmfq-qf34.json create mode 100644 advisories/unreviewed/2025/03/GHSA-42qm-8j3v-68c9/GHSA-42qm-8j3v-68c9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-56j5-vwwf-v97g/GHSA-56j5-vwwf-v97g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6r8h-8x56-2jqr/GHSA-6r8h-8x56-2jqr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-73vc-g45m-99m9/GHSA-73vc-g45m-99m9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-744j-f9r9-w6h7/GHSA-744j-f9r9-w6h7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9973-9x4h-pfgx/GHSA-9973-9x4h-pfgx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gv88-vwqw-9qgj/GHSA-gv88-vwqw-9qgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h877-4279-qcfv/GHSA-h877-4279-qcfv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j79q-5fqv-hj78/GHSA-j79q-5fqv-hj78.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p293-86cr-rj34/GHSA-p293-86cr-rj34.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q469-433j-8xc2/GHSA-q469-433j-8xc2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rfr3-g285-rggj/GHSA-rfr3-g285-rggj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vj79-3hwh-jcf7/GHSA-vj79-3hwh-jcf7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6xj-4jx7-p88w/GHSA-w6xj-4jx7-p88w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xvw8-mqg6-cchx/GHSA-xvw8-mqg6-cchx.json diff --git a/advisories/unreviewed/2022/10/GHSA-cg2v-9v73-ccwp/GHSA-cg2v-9v73-ccwp.json b/advisories/unreviewed/2022/10/GHSA-cg2v-9v73-ccwp/GHSA-cg2v-9v73-ccwp.json index e10b9db8c08..883dde77a8d 100644 --- a/advisories/unreviewed/2022/10/GHSA-cg2v-9v73-ccwp/GHSA-cg2v-9v73-ccwp.json +++ b/advisories/unreviewed/2022/10/GHSA-cg2v-9v73-ccwp/GHSA-cg2v-9v73-ccwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg2v-9v73-ccwp", - "modified": "2025-01-02T21:31:39Z", + "modified": "2025-03-07T18:30:53Z", "published": "2022-10-04T00:00:25Z", "aliases": [ "CVE-2022-41082" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://www.secpod.com/blog/microsoft-november-2022-patch-tuesday-patches-65-vulnerabilities-including-6-zero-days" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-mitigation-script" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-Execution.html" diff --git a/advisories/unreviewed/2023/03/GHSA-3xqx-95w6-xjv4/GHSA-3xqx-95w6-xjv4.json b/advisories/unreviewed/2023/03/GHSA-3xqx-95w6-xjv4/GHSA-3xqx-95w6-xjv4.json index 02e222d95ea..57152fba4e0 100644 --- a/advisories/unreviewed/2023/03/GHSA-3xqx-95w6-xjv4/GHSA-3xqx-95w6-xjv4.json +++ b/advisories/unreviewed/2023/03/GHSA-3xqx-95w6-xjv4/GHSA-3xqx-95w6-xjv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xqx-95w6-xjv4", - "modified": "2023-03-10T06:30:21Z", + "modified": "2025-03-07T18:30:54Z", "published": "2023-03-02T18:30:26Z", "aliases": [ "CVE-2022-38734" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-82v2-v4p5-fg34/GHSA-82v2-v4p5-fg34.json b/advisories/unreviewed/2023/03/GHSA-82v2-v4p5-fg34/GHSA-82v2-v4p5-fg34.json index 78793fbe8df..39f6f4849f5 100644 --- a/advisories/unreviewed/2023/03/GHSA-82v2-v4p5-fg34/GHSA-82v2-v4p5-fg34.json +++ b/advisories/unreviewed/2023/03/GHSA-82v2-v4p5-fg34/GHSA-82v2-v4p5-fg34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82v2-v4p5-fg34", - "modified": "2023-03-13T18:30:41Z", + "modified": "2025-03-07T18:30:57Z", "published": "2023-03-06T00:30:16Z", "aliases": [ "CVE-2023-22424" diff --git a/advisories/unreviewed/2023/03/GHSA-86xc-fp29-26g2/GHSA-86xc-fp29-26g2.json b/advisories/unreviewed/2023/03/GHSA-86xc-fp29-26g2/GHSA-86xc-fp29-26g2.json index 366d66eecc4..5caac342d43 100644 --- a/advisories/unreviewed/2023/03/GHSA-86xc-fp29-26g2/GHSA-86xc-fp29-26g2.json +++ b/advisories/unreviewed/2023/03/GHSA-86xc-fp29-26g2/GHSA-86xc-fp29-26g2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-86xh-6qhg-p6c2/GHSA-86xh-6qhg-p6c2.json b/advisories/unreviewed/2023/03/GHSA-86xh-6qhg-p6c2/GHSA-86xh-6qhg-p6c2.json index 48221f104fc..ad796f6df8b 100644 --- a/advisories/unreviewed/2023/03/GHSA-86xh-6qhg-p6c2/GHSA-86xh-6qhg-p6c2.json +++ b/advisories/unreviewed/2023/03/GHSA-86xh-6qhg-p6c2/GHSA-86xh-6qhg-p6c2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86xh-6qhg-p6c2", - "modified": "2023-03-10T15:30:43Z", + "modified": "2025-03-07T18:30:57Z", "published": "2023-03-04T00:30:16Z", "aliases": [ "CVE-2023-23313" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23313" }, + { + "type": "WEB", + "url": "https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-%28cve-2023-23313%29" + }, { "type": "WEB", "url": "https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-(cve-2023-23313)" diff --git a/advisories/unreviewed/2023/03/GHSA-fm6r-qcm7-79pj/GHSA-fm6r-qcm7-79pj.json b/advisories/unreviewed/2023/03/GHSA-fm6r-qcm7-79pj/GHSA-fm6r-qcm7-79pj.json index 766d85172d6..a866dcf1958 100644 --- a/advisories/unreviewed/2023/03/GHSA-fm6r-qcm7-79pj/GHSA-fm6r-qcm7-79pj.json +++ b/advisories/unreviewed/2023/03/GHSA-fm6r-qcm7-79pj/GHSA-fm6r-qcm7-79pj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-fr68-cm8v-7vv6/GHSA-fr68-cm8v-7vv6.json b/advisories/unreviewed/2023/03/GHSA-fr68-cm8v-7vv6/GHSA-fr68-cm8v-7vv6.json index 9cb2309692b..7cedbb3ab79 100644 --- a/advisories/unreviewed/2023/03/GHSA-fr68-cm8v-7vv6/GHSA-fr68-cm8v-7vv6.json +++ b/advisories/unreviewed/2023/03/GHSA-fr68-cm8v-7vv6/GHSA-fr68-cm8v-7vv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr68-cm8v-7vv6", - "modified": "2023-03-14T15:30:16Z", + "modified": "2025-03-07T18:30:55Z", "published": "2023-03-03T18:30:27Z", "aliases": [ "CVE-2022-41862" diff --git a/advisories/unreviewed/2023/03/GHSA-m789-8jxv-f7m3/GHSA-m789-8jxv-f7m3.json b/advisories/unreviewed/2023/03/GHSA-m789-8jxv-f7m3/GHSA-m789-8jxv-f7m3.json index f56e04e4fbf..59febb694eb 100644 --- a/advisories/unreviewed/2023/03/GHSA-m789-8jxv-f7m3/GHSA-m789-8jxv-f7m3.json +++ b/advisories/unreviewed/2023/03/GHSA-m789-8jxv-f7m3/GHSA-m789-8jxv-f7m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m789-8jxv-f7m3", - "modified": "2023-03-10T15:30:42Z", + "modified": "2025-03-07T18:30:56Z", "published": "2023-03-04T00:30:16Z", "aliases": [ "CVE-2023-26213" diff --git a/advisories/unreviewed/2023/03/GHSA-pcwc-3rj4-gj54/GHSA-pcwc-3rj4-gj54.json b/advisories/unreviewed/2023/03/GHSA-pcwc-3rj4-gj54/GHSA-pcwc-3rj4-gj54.json index e2e1a131211..fac4d964358 100644 --- a/advisories/unreviewed/2023/03/GHSA-pcwc-3rj4-gj54/GHSA-pcwc-3rj4-gj54.json +++ b/advisories/unreviewed/2023/03/GHSA-pcwc-3rj4-gj54/GHSA-pcwc-3rj4-gj54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcwc-3rj4-gj54", - "modified": "2023-03-14T15:30:17Z", + "modified": "2025-03-07T18:30:58Z", "published": "2023-03-07T00:30:25Z", "aliases": [ "CVE-2022-3707" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz%40163.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz@163.com" diff --git a/advisories/unreviewed/2023/03/GHSA-qc7r-x584-w555/GHSA-qc7r-x584-w555.json b/advisories/unreviewed/2023/03/GHSA-qc7r-x584-w555/GHSA-qc7r-x584-w555.json index f01b2f88796..815feb443cc 100644 --- a/advisories/unreviewed/2023/03/GHSA-qc7r-x584-w555/GHSA-qc7r-x584-w555.json +++ b/advisories/unreviewed/2023/03/GHSA-qc7r-x584-w555/GHSA-qc7r-x584-w555.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-732" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-xcc8-3vrq-wjg2/GHSA-xcc8-3vrq-wjg2.json b/advisories/unreviewed/2023/03/GHSA-xcc8-3vrq-wjg2/GHSA-xcc8-3vrq-wjg2.json index 857d0b0248c..c23dc094a83 100644 --- a/advisories/unreviewed/2023/03/GHSA-xcc8-3vrq-wjg2/GHSA-xcc8-3vrq-wjg2.json +++ b/advisories/unreviewed/2023/03/GHSA-xcc8-3vrq-wjg2/GHSA-xcc8-3vrq-wjg2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcc8-3vrq-wjg2", - "modified": "2023-03-14T18:30:22Z", + "modified": "2025-03-07T18:30:54Z", "published": "2023-03-02T15:30:17Z", "aliases": [ "CVE-2023-25358" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://bugs.webkit.org/show_bug.cgi?id=242683" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OKKVEUQAAGH3NHMX3WHWKRPYU4QFKTQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QL5OGMSHRQ26FTYWZUXVNWB2VHOSVXK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC7DMUX37BRCLAI4VPQYHDUVEGTNYN5A" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OKKVEUQAAGH3NHMX3WHWKRPYU4QFKTQ" diff --git a/advisories/unreviewed/2024/02/GHSA-69v8-v8v7-vv42/GHSA-69v8-v8v7-vv42.json b/advisories/unreviewed/2024/02/GHSA-69v8-v8v7-vv42/GHSA-69v8-v8v7-vv42.json index 8d1dd69c7d7..489c535d8b5 100644 --- a/advisories/unreviewed/2024/02/GHSA-69v8-v8v7-vv42/GHSA-69v8-v8v7-vv42.json +++ b/advisories/unreviewed/2024/02/GHSA-69v8-v8v7-vv42/GHSA-69v8-v8v7-vv42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69v8-v8v7-vv42", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-03-07T18:30:58Z", "published": "2024-02-12T03:30:24Z", "aliases": [ "CVE-2024-25739" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html" }, + { + "type": "WEB", + "url": "https://web.git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/drivers/mtd/ubi/vtbl.c?h=v6.6.24&id=d1b505c988b7" + }, { "type": "WEB", "url": "https://www.spinics.net/lists/kernel/msg5074816.html" diff --git a/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json b/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json index a92880c3abf..36ec41592ff 100644 --- a/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json +++ b/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxmc-w576-mqxx", - "modified": "2025-02-27T15:31:49Z", + "modified": "2025-03-07T18:30:58Z", "published": "2024-04-03T18:30:43Z", "aliases": [ "CVE-2024-26767" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/0484e05d048b66d01d1f3c1d2306010bb57d8738" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/070fda699dfdce560755379bc428d9edada7a54e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/71783d1ff65204d69207fd156d4b2eb1d3882375" diff --git a/advisories/unreviewed/2024/05/GHSA-8jh7-gcv4-cq6q/GHSA-8jh7-gcv4-cq6q.json b/advisories/unreviewed/2024/05/GHSA-8jh7-gcv4-cq6q/GHSA-8jh7-gcv4-cq6q.json index 88cd3e969b4..b2deae409a9 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jh7-gcv4-cq6q/GHSA-8jh7-gcv4-cq6q.json +++ b/advisories/unreviewed/2024/05/GHSA-8jh7-gcv4-cq6q/GHSA-8jh7-gcv4-cq6q.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-8jh7-gcv4-cq6q", - "modified": "2024-05-03T06:30:35Z", + "modified": "2025-03-07T18:30:58Z", "published": "2024-05-01T06:31:42Z", "aliases": [ "CVE-2024-26982" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check the inode number is not the invalid value of zero\n\nSyskiller has produced an out of bounds access in fill_meta_index().\n\nThat out of bounds access is ultimately caused because the inode\nhas an inode number with the invalid value of zero, which was not checked.\n\nThe reason this causes the out of bounds access is due to following\nsequence of events:\n\n1. Fill_meta_index() is called to allocate (via empty_meta_index())\n and fill a metadata index. It however suffers a data read error\n and aborts, invalidating the newly returned empty metadata index.\n It does this by setting the inode number of the index to zero,\n which means unused (zero is not a valid inode number).\n\n2. When fill_meta_index() is subsequently called again on another\n read operation, locate_meta_index() returns the previous index\n because it matches the inode number of 0. Because this index\n has been returned it is expected to have been filled, and because\n it hasn't been, an out of bounds access is performed.\n\nThis patch adds a sanity check which checks that the inode number\nis not zero when the inode is created and returns -EINVAL if it is.\n\n[phillip@squashfs.org.uk: whitespace fix]\n Link: https://lkml.kernel.org/r/20240409204723.446925-1-phillip@squashfs.org.uk", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26982" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b99dea79650b50909c50aba24fbae00f203f013" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5" @@ -40,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-chw9-726p-m659/GHSA-chw9-726p-m659.json b/advisories/unreviewed/2024/07/GHSA-chw9-726p-m659/GHSA-chw9-726p-m659.json index 7b70abf6afa..be28096888f 100644 --- a/advisories/unreviewed/2024/07/GHSA-chw9-726p-m659/GHSA-chw9-726p-m659.json +++ b/advisories/unreviewed/2024/07/GHSA-chw9-726p-m659/GHSA-chw9-726p-m659.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-ffg2-5fg9-qrwc/GHSA-ffg2-5fg9-qrwc.json b/advisories/unreviewed/2024/07/GHSA-ffg2-5fg9-qrwc/GHSA-ffg2-5fg9-qrwc.json index 9cfb69dc611..3062bdd95c0 100644 --- a/advisories/unreviewed/2024/07/GHSA-ffg2-5fg9-qrwc/GHSA-ffg2-5fg9-qrwc.json +++ b/advisories/unreviewed/2024/07/GHSA-ffg2-5fg9-qrwc/GHSA-ffg2-5fg9-qrwc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json b/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json index 091b73829fc..0a8b6eab74f 100644 --- a/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json +++ b/advisories/unreviewed/2024/07/GHSA-g7g4-7563-37xc/GHSA-g7g4-7563-37xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7g4-7563-37xc", - "modified": "2024-09-09T18:30:29Z", + "modified": "2025-03-07T18:30:59Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40973" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/53dbe08504442dc7ba4865c09b3bbf5fe849681b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eeb62bb4ca22db17f7dfe8fb8472e0442df3d92f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f066882293b5ad359e44c4ed24ab1811ffb0b354" diff --git a/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json b/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json index 18093974aa5..ba2c69b768c 100644 --- a/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json +++ b/advisories/unreviewed/2024/09/GHSA-g477-g2gm-cjmf/GHSA-g477-g2gm-cjmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g477-g2gm-cjmf", - "modified": "2024-09-06T18:31:28Z", + "modified": "2025-03-07T18:31:00Z", "published": "2024-09-04T21:30:31Z", "aliases": [ "CVE-2024-44953" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4921b76bc9421d3838e167f6a17ea3112d8fe62" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5" diff --git a/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json b/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json index b5f34f9d5f8..aeca5f02b8d 100644 --- a/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json +++ b/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58m7-hfr6-rrx2", - "modified": "2024-11-22T21:32:12Z", + "modified": "2025-03-07T18:31:00Z", "published": "2024-10-23T06:31:19Z", "aliases": [ "CVE-2024-50066" @@ -34,6 +34,14 @@ { "type": "WEB", "url": "https://project-zero.issues.chromium.org/issues/371047675" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-detection-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-mitigation-vulnerability" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json b/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json index c500b636190..3633555d2ac 100644 --- a/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json +++ b/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh27-x7g8-9fv7", - "modified": "2024-10-22T18:32:10Z", + "modified": "2025-03-07T18:31:00Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-47754" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/9be85491619f1953b8a29590ca630be571941ffa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d48890ef8765001caff732ac6ec80a3b2e470215" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json index 3e13d977153..79fc0a77838 100644 --- a/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json +++ b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh8w-gxgh-8grm", - "modified": "2024-11-25T21:30:49Z", + "modified": "2025-03-07T18:31:01Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53067" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/54c814c8b23bc7617be3d46abdb896937695dbfa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e34b9d7caa5a4c831b74bdfed5ef86fa0c03316" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json b/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json index 92a2abc8a3a..fcb107d1564 100644 --- a/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json +++ b/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq67-p454-7jfc", - "modified": "2024-11-22T21:32:13Z", + "modified": "2025-03-07T18:31:01Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53053" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53053" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9aa1f0da237d6b16e36e0a0cc9f746d1d78396ed" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a128cfec44709ab1bd1f01d158569bcb2386f54f" diff --git a/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json b/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json index 55ab1535a9c..0d31c496998 100644 --- a/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json +++ b/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gmm-x3pr-vhmf", - "modified": "2025-01-16T18:30:58Z", + "modified": "2025-03-07T18:31:02Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53166" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/906cdbdd3b018ff69cc830173bce277a847d4fdc" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ada4ca5fd5a9d5212f28164d49a4885951c979c9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/dcaa738afde55085ac6056252e319479cf23cde2" diff --git a/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json b/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json index b2b095e10b9..f988de186c7 100644 --- a/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json +++ b/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3c8-2g4x-qq2h", - "modified": "2025-01-08T18:30:47Z", + "modified": "2025-03-07T18:31:02Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56621" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/2e7a3bb0331efb292e0fb022c36bc592137f0520" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57479e37d3f69efee2f0678568274db773284bc8" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json b/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json index 2bfe224fa8c..a90cd6794e6 100644 --- a/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json +++ b/advisories/unreviewed/2025/01/GHSA-gjv6-pfh4-3rff/GHSA-gjv6-pfh4-3rff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjv6-pfh4-3rff", - "modified": "2025-01-14T18:32:05Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-01-14T18:32:05Z", "aliases": [ "CVE-2025-21333" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21333" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21333-elevated-privilege-exposure-in-windows-hyper-v-by-microsoft-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21333-elevated-privilege-exposure-in-windows-hyper-v-by-microsoft-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json b/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json index 2a302fe67ef..e7450f05717 100644 --- a/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json +++ b/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c82f-pmfx-x3vv", - "modified": "2025-02-18T15:31:08Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-02-18T15:31:08Z", "aliases": [ "CVE-2025-21702" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21702" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/020ecb76812a0526f4130ab5aeb6dc7c773e7ab9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/647cef20e649c576dff271e018d5d15d998b629d" diff --git a/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json b/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json index b8ef8f20b89..cf18f7f4069 100644 --- a/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json +++ b/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j98h-85cg-gvmj", - "modified": "2025-02-27T15:31:50Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-02-27T03:33:58Z", "aliases": [ "CVE-2024-57977" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57977" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a09d56e1682c951046bf15542b3e9553046c9f6" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/46576834291869457d4772bb7df72d7c2bb3d57f" diff --git a/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json b/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json index 962b7a468a9..4ce0997c9e3 100644 --- a/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json +++ b/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j992-gmv8-p6vw", - "modified": "2025-03-06T15:34:42Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-02-27T03:34:03Z", "aliases": [ "CVE-2024-58005" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/50365a6304a57266e8f4d3078060743c3b7a1e0d" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/77779d1258a287f2c5c2c6aeae203e0996209c77" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a3a860bc0fd6c07332e4911cf9a238d20de90173" diff --git a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json index a3928038484..e71b87e0aff 100644 --- a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json +++ b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc22-v4cr-4rv7", - "modified": "2025-03-06T15:34:42Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2024-58002" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/9edc7d25f7e49c33a1ce7a5ffadea2222065516c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac18d781466252cd35a3e311e0a4b264260fd927" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json b/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json index 3cf0ef500b3..23dde524607 100644 --- a/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json +++ b/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq63-h845-wgm6", - "modified": "2025-02-27T15:31:50Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-02-27T03:34:01Z", "aliases": [ "CVE-2025-21712" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21712" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/032fa54f486eac5507976e7e31f079a767bc13a8" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/237e19519c8ff6949f0ef57c4a0243f5b2b0fa18" diff --git a/advisories/unreviewed/2025/03/GHSA-24g2-6vx6-3vf6/GHSA-24g2-6vx6-3vf6.json b/advisories/unreviewed/2025/03/GHSA-24g2-6vx6-3vf6/GHSA-24g2-6vx6-3vf6.json new file mode 100644 index 00000000000..79bd70f2c3c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-24g2-6vx6-3vf6/GHSA-24g2-6vx6-3vf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24g2-6vx6-3vf6", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53697" + ], + "details": "An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53697" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3243-w5fh-rcj8/GHSA-3243-w5fh-rcj8.json b/advisories/unreviewed/2025/03/GHSA-3243-w5fh-rcj8/GHSA-3243-w5fh-rcj8.json new file mode 100644 index 00000000000..a6b5eb996fa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3243-w5fh-rcj8/GHSA-3243-w5fh-rcj8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3243-w5fh-rcj8", + "modified": "2025-03-07T18:31:04Z", + "published": "2025-03-07T18:31:04Z", + "aliases": [ + "CVE-2025-25617" + ], + "details": "Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25617" + }, + { + "type": "WEB", + "url": "https://github.com/armaansidana2003/CVE-2025-25617" + }, + { + "type": "WEB", + "url": "https://github.com/changeweb/Unifiedtransform" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3p6v-922c-mrw6/GHSA-3p6v-922c-mrw6.json b/advisories/unreviewed/2025/03/GHSA-3p6v-922c-mrw6/GHSA-3p6v-922c-mrw6.json new file mode 100644 index 00000000000..72250d2b0b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3p6v-922c-mrw6/GHSA-3p6v-922c-mrw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p6v-922c-mrw6", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53699" + ], + "details": "An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53699" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xx8-jmfq-qf34/GHSA-3xx8-jmfq-qf34.json b/advisories/unreviewed/2025/03/GHSA-3xx8-jmfq-qf34/GHSA-3xx8-jmfq-qf34.json new file mode 100644 index 00000000000..9ad21cf392f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3xx8-jmfq-qf34/GHSA-3xx8-jmfq-qf34.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xx8-jmfq-qf34", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-53693" + ], + "details": "An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53693" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-93", + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42qm-8j3v-68c9/GHSA-42qm-8j3v-68c9.json b/advisories/unreviewed/2025/03/GHSA-42qm-8j3v-68c9/GHSA-42qm-8j3v-68c9.json new file mode 100644 index 00000000000..25e5862d6a9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-42qm-8j3v-68c9/GHSA-42qm-8j3v-68c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42qm-8j3v-68c9", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53698" + ], + "details": "A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53698" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json b/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json index b91aeb00396..e327fd4d88d 100644 --- a/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json +++ b/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-55g6-rmp8-f2fq", - "modified": "2025-03-06T15:34:47Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-06T15:34:47Z", "aliases": [ "CVE-2025-25451" ], "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the \"2fa_authorized\" Local Storage key", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T15:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-56j5-vwwf-v97g/GHSA-56j5-vwwf-v97g.json b/advisories/unreviewed/2025/03/GHSA-56j5-vwwf-v97g/GHSA-56j5-vwwf-v97g.json new file mode 100644 index 00000000000..dfdf3fb651c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-56j5-vwwf-v97g/GHSA-56j5-vwwf-v97g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56j5-vwwf-v97g", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53695" + ], + "details": "A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes.\n\nWe have already fixed the vulnerability in the following version:\nHBS 3 Hybrid Backup Sync 25.1.4.952 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53695" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-25-06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69r2-5wxm-3hf6/GHSA-69r2-5wxm-3hf6.json b/advisories/unreviewed/2025/03/GHSA-69r2-5wxm-3hf6/GHSA-69r2-5wxm-3hf6.json index b0f8820e156..4047f0a889a 100644 --- a/advisories/unreviewed/2025/03/GHSA-69r2-5wxm-3hf6/GHSA-69r2-5wxm-3hf6.json +++ b/advisories/unreviewed/2025/03/GHSA-69r2-5wxm-3hf6/GHSA-69r2-5wxm-3hf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69r2-5wxm-3hf6", - "modified": "2025-03-07T06:30:33Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-07T06:30:33Z", "aliases": [ "CVE-2025-27795" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27795" }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387" + }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280" + }, + { + "type": "WEB", + "url": "https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42" + }, + { + "type": "WEB", + "url": "https://issues.oss-fuzz.com/issues/42536330#comment6" + }, { "type": "WEB", "url": "http://www.graphicsmagick.org/NEWS.html" diff --git a/advisories/unreviewed/2025/03/GHSA-6r8h-8x56-2jqr/GHSA-6r8h-8x56-2jqr.json b/advisories/unreviewed/2025/03/GHSA-6r8h-8x56-2jqr/GHSA-6r8h-8x56-2jqr.json new file mode 100644 index 00000000000..b697c68cb2f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6r8h-8x56-2jqr/GHSA-6r8h-8x56-2jqr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r8h-8x56-2jqr", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-53692" + ], + "details": "A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53692" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77", + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-73vc-g45m-99m9/GHSA-73vc-g45m-99m9.json b/advisories/unreviewed/2025/03/GHSA-73vc-g45m-99m9/GHSA-73vc-g45m-99m9.json new file mode 100644 index 00000000000..fa40a5823d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-73vc-g45m-99m9/GHSA-73vc-g45m-99m9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73vc-g45m-99m9", + "modified": "2025-03-07T18:31:05Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-38638" + ], + "details": "An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.\n\nQTS 5.2.x/QuTS hero h5.2.x are not affected.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.9.2954 build 20241120 and later\nQuTS hero h5.1.9.2954 build 20241120 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38638" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-52" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-744j-f9r9-w6h7/GHSA-744j-f9r9-w6h7.json b/advisories/unreviewed/2025/03/GHSA-744j-f9r9-w6h7/GHSA-744j-f9r9-w6h7.json new file mode 100644 index 00000000000..3bd06d32f3f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-744j-f9r9-w6h7/GHSA-744j-f9r9-w6h7.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-744j-f9r9-w6h7", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-50405" + ], + "details": "An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.3.3006 build 20250108 and later\nQuTS hero h5.2.3.3006 build 20250108 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50405" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-93", + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9973-9x4h-pfgx/GHSA-9973-9x4h-pfgx.json b/advisories/unreviewed/2025/03/GHSA-9973-9x4h-pfgx/GHSA-9973-9x4h-pfgx.json new file mode 100644 index 00000000000..0b9975b5c01 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9973-9x4h-pfgx/GHSA-9973-9x4h-pfgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9973-9x4h-pfgx", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-50394" + ], + "details": "An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.\n\nWe have already fixed the vulnerability in the following version:\nHelpdesk 3.3.3 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50394" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-25-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9h49-4vx3-2m5r/GHSA-9h49-4vx3-2m5r.json b/advisories/unreviewed/2025/03/GHSA-9h49-4vx3-2m5r/GHSA-9h49-4vx3-2m5r.json index 9789411794d..3f463c87c21 100644 --- a/advisories/unreviewed/2025/03/GHSA-9h49-4vx3-2m5r/GHSA-9h49-4vx3-2m5r.json +++ b/advisories/unreviewed/2025/03/GHSA-9h49-4vx3-2m5r/GHSA-9h49-4vx3-2m5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h49-4vx3-2m5r", - "modified": "2025-03-07T09:30:35Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-07T09:30:35Z", "aliases": [ "CVE-2025-21838" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/97695b5a1b5467a4f91194db12160f56da445dfe" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3bc1a9a67ce33a2e761e6e7b7c2afc6cb9b7266" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f894448f3904d7ad66fecef8f01fe0172629e091" diff --git a/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json b/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json index f1753f5c7dd..556fab99127 100644 --- a/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json +++ b/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c346-qq93-pfrw", - "modified": "2025-03-06T15:34:47Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-03-06T15:34:47Z", "aliases": [ "CVE-2025-25450" ], "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T15:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fgjx-56hm-4qrp/GHSA-fgjx-56hm-4qrp.json b/advisories/unreviewed/2025/03/GHSA-fgjx-56hm-4qrp/GHSA-fgjx-56hm-4qrp.json index c34bf681fea..cbd941a8718 100644 --- a/advisories/unreviewed/2025/03/GHSA-fgjx-56hm-4qrp/GHSA-fgjx-56hm-4qrp.json +++ b/advisories/unreviewed/2025/03/GHSA-fgjx-56hm-4qrp/GHSA-fgjx-56hm-4qrp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgjx-56hm-4qrp", - "modified": "2025-03-06T18:31:11Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-06T18:31:11Z", "aliases": [ "CVE-2024-58079" @@ -18,6 +18,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/0b5e0445bc8384c18bd35cb9fe87f6258c6271d9" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c00e94d00ca079bef7906d6f39d1091bccfedd3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5d2e65cbe53d0141ed095cf31c2dcf3d8668c11d" diff --git a/advisories/unreviewed/2025/03/GHSA-gqcv-8xh2-hqvg/GHSA-gqcv-8xh2-hqvg.json b/advisories/unreviewed/2025/03/GHSA-gqcv-8xh2-hqvg/GHSA-gqcv-8xh2-hqvg.json index b9e9d68fd9c..0c6643305d8 100644 --- a/advisories/unreviewed/2025/03/GHSA-gqcv-8xh2-hqvg/GHSA-gqcv-8xh2-hqvg.json +++ b/advisories/unreviewed/2025/03/GHSA-gqcv-8xh2-hqvg/GHSA-gqcv-8xh2-hqvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqcv-8xh2-hqvg", - "modified": "2025-03-07T09:30:34Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-07T09:30:34Z", "aliases": [ "CVE-2024-12837" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-07T08:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gv88-vwqw-9qgj/GHSA-gv88-vwqw-9qgj.json b/advisories/unreviewed/2025/03/GHSA-gv88-vwqw-9qgj/GHSA-gv88-vwqw-9qgj.json new file mode 100644 index 00000000000..44a69083532 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gv88-vwqw-9qgj/GHSA-gv88-vwqw-9qgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv88-vwqw-9qgj", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53700" + ], + "details": "A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands.\n\nWe have already fixed the vulnerability in the following version:\nQuRouter 2.4.6.028 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53700" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-25-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h877-4279-qcfv/GHSA-h877-4279-qcfv.json b/advisories/unreviewed/2025/03/GHSA-h877-4279-qcfv/GHSA-h877-4279-qcfv.json new file mode 100644 index 00000000000..1528703c727 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h877-4279-qcfv/GHSA-h877-4279-qcfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h877-4279-qcfv", + "modified": "2025-03-07T18:31:05Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-48864" + ], + "details": "A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories.\n\nWe have already fixed the vulnerability in the following versions:\nFile Station 5 5.5.6.4741 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48864" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-55" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j79q-5fqv-hj78/GHSA-j79q-5fqv-hj78.json b/advisories/unreviewed/2025/03/GHSA-j79q-5fqv-hj78/GHSA-j79q-5fqv-hj78.json new file mode 100644 index 00000000000..1b1945d90a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j79q-5fqv-hj78/GHSA-j79q-5fqv-hj78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j79q-5fqv-hj78", + "modified": "2025-03-07T18:31:05Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2023-35894" + ], + "details": "IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35894" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p293-86cr-rj34/GHSA-p293-86cr-rj34.json b/advisories/unreviewed/2025/03/GHSA-p293-86cr-rj34/GHSA-p293-86cr-rj34.json new file mode 100644 index 00000000000..c634ef3c3a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p293-86cr-rj34/GHSA-p293-86cr-rj34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p293-86cr-rj34", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-53694" + ], + "details": "A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.\n\nWe have already fixed the vulnerability in the following versions:\nQVPN Device Client for Mac 2.2.5 and later\nQsync for Mac 5.1.3 and later\nQfinder Pro Mac 7.11.1 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53694" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-51" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json b/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json index 8d7e1f53903..4abc886ea5f 100644 --- a/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json +++ b/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcj4-9fcj-56c8", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-03-03T18:31:29Z", "aliases": [ "CVE-2025-27370" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27370" }, + { + "type": "WEB", + "url": "https://github.com/OWASP/ASVS/issues/2678" + }, { "type": "WEB", "url": "https://openid.net/notice-of-a-security-vulnerability" diff --git a/advisories/unreviewed/2025/03/GHSA-pppp-mqfr-xwwh/GHSA-pppp-mqfr-xwwh.json b/advisories/unreviewed/2025/03/GHSA-pppp-mqfr-xwwh/GHSA-pppp-mqfr-xwwh.json index 45fcdd049ea..162da2afec6 100644 --- a/advisories/unreviewed/2025/03/GHSA-pppp-mqfr-xwwh/GHSA-pppp-mqfr-xwwh.json +++ b/advisories/unreviewed/2025/03/GHSA-pppp-mqfr-xwwh/GHSA-pppp-mqfr-xwwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pppp-mqfr-xwwh", - "modified": "2025-03-07T09:30:34Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-07T09:30:34Z", "aliases": [ "CVE-2025-26331" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.dell.com/support/kbdoc/en-us/000289886/dsa-2025-107" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-26331" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-q469-433j-8xc2/GHSA-q469-433j-8xc2.json b/advisories/unreviewed/2025/03/GHSA-q469-433j-8xc2/GHSA-q469-433j-8xc2.json new file mode 100644 index 00000000000..e10d69175e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q469-433j-8xc2/GHSA-q469-433j-8xc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q469-433j-8xc2", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2024-53696" + ], + "details": "A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQuLog Center 1.7.0.829 ( 2024/10/01 ) and later\nQuLog Center 1.8.0.888 ( 2024/10/15 ) and later\nQTS 4.5.4.2957 build 20241119 and later\nQuTS hero h4.5.4.2956 build 20241119 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53696" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-24-53" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rfr3-g285-rggj/GHSA-rfr3-g285-rggj.json b/advisories/unreviewed/2025/03/GHSA-rfr3-g285-rggj/GHSA-rfr3-g285-rggj.json new file mode 100644 index 00000000000..010b15f0bd3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rfr3-g285-rggj/GHSA-rfr3-g285-rggj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfr3-g285-rggj", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-13086" + ], + "details": "An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.\n\nWe have already fixed the vulnerability in the following version:\nQTS 5.2.0.2851 build 20240808 and later\nQuTS hero h5.2.0.2851 build 20240808 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13086" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-25-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json b/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json index ffe1d55edb0..3f3e15f3d2a 100644 --- a/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json +++ b/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh3q-7g79-rp3x", - "modified": "2025-03-03T18:31:30Z", + "modified": "2025-03-07T18:31:03Z", "published": "2025-03-03T18:31:30Z", "aliases": [ "CVE-2025-27371" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27371" }, + { + "type": "WEB", + "url": "https://github.com/OWASP/ASVS/issues/2678" + }, { "type": "WEB", "url": "https://openid.net/notice-of-a-security-vulnerability" diff --git a/advisories/unreviewed/2025/03/GHSA-v5xf-gj23-85jx/GHSA-v5xf-gj23-85jx.json b/advisories/unreviewed/2025/03/GHSA-v5xf-gj23-85jx/GHSA-v5xf-gj23-85jx.json index df18ab12a4b..104ccdd56c6 100644 --- a/advisories/unreviewed/2025/03/GHSA-v5xf-gj23-85jx/GHSA-v5xf-gj23-85jx.json +++ b/advisories/unreviewed/2025/03/GHSA-v5xf-gj23-85jx/GHSA-v5xf-gj23-85jx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5xf-gj23-85jx", - "modified": "2025-03-07T06:30:33Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-07T06:30:33Z", "aliases": [ "CVE-2025-27796" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27796" }, + { + "type": "WEB", + "url": "https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/883ebf8cae6dfa5873d975fe3476b1a188ef3f9f" + }, { "type": "WEB", "url": "https://sourceforge.net/p/graphicsmagick/bugs/750" diff --git a/advisories/unreviewed/2025/03/GHSA-vj79-3hwh-jcf7/GHSA-vj79-3hwh-jcf7.json b/advisories/unreviewed/2025/03/GHSA-vj79-3hwh-jcf7/GHSA-vj79-3hwh-jcf7.json new file mode 100644 index 00000000000..23d3f740a88 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vj79-3hwh-jcf7/GHSA-vj79-3hwh-jcf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj79-3hwh-jcf7", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-50390" + ], + "details": "A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.\n\nWe have already fixed the vulnerability in the following version:\nQuRouter 2.4.5.032 and later", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50390" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-25-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w6xj-4jx7-p88w/GHSA-w6xj-4jx7-p88w.json b/advisories/unreviewed/2025/03/GHSA-w6xj-4jx7-p88w/GHSA-w6xj-4jx7-p88w.json new file mode 100644 index 00000000000..f4e5e728744 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6xj-4jx7-p88w/GHSA-w6xj-4jx7-p88w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xj-4jx7-p88w", + "modified": "2025-03-07T18:31:05Z", + "published": "2025-03-07T18:31:05Z", + "aliases": [ + "CVE-2024-12975" + ], + "details": "A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12975" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm00000LWXMeIAP" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/simplicity_sdk/releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json b/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json index a418fe25916..168bf8a4018 100644 --- a/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json +++ b/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5m3-m392-xf85", - "modified": "2025-03-06T15:34:47Z", + "modified": "2025-03-07T18:31:04Z", "published": "2025-03-06T15:34:47Z", "aliases": [ "CVE-2025-25452" ], "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the \"/user\" endpoint", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T15:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xvw8-mqg6-cchx/GHSA-xvw8-mqg6-cchx.json b/advisories/unreviewed/2025/03/GHSA-xvw8-mqg6-cchx/GHSA-xvw8-mqg6-cchx.json new file mode 100644 index 00000000000..f0dd47aa6fd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xvw8-mqg6-cchx/GHSA-xvw8-mqg6-cchx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvw8-mqg6-cchx", + "modified": "2025-03-07T18:31:06Z", + "published": "2025-03-07T18:31:06Z", + "aliases": [ + "CVE-2025-0162" + ], + "details": "IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0162" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185096" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T17:15:21Z" + } +} \ No newline at end of file