diff --git a/advisories/unreviewed/2024/02/GHSA-6jr8-r9gw-5fg7/GHSA-6jr8-r9gw-5fg7.json b/advisories/unreviewed/2024/02/GHSA-6jr8-r9gw-5fg7/GHSA-6jr8-r9gw-5fg7.json index 8d15f7b6de7..8910128324c 100644 --- a/advisories/unreviewed/2024/02/GHSA-6jr8-r9gw-5fg7/GHSA-6jr8-r9gw-5fg7.json +++ b/advisories/unreviewed/2024/02/GHSA-6jr8-r9gw-5fg7/GHSA-6jr8-r9gw-5fg7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json b/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json index 8aa56b843b0..1fca55beb7c 100644 --- a/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json +++ b/advisories/unreviewed/2024/02/GHSA-89r2-jh3p-h38p/GHSA-89r2-jh3p-h38p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89r2-jh3p-h38p", - "modified": "2024-02-26T18:30:29Z", + "modified": "2025-01-16T15:32:07Z", "published": "2024-02-26T18:30:29Z", "aliases": [ "CVE-2024-1165" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c2jj-rr3q-vvv8/GHSA-c2jj-rr3q-vvv8.json b/advisories/unreviewed/2024/02/GHSA-c2jj-rr3q-vvv8/GHSA-c2jj-rr3q-vvv8.json index cd6242edaf0..c843c709222 100644 --- a/advisories/unreviewed/2024/02/GHSA-c2jj-rr3q-vvv8/GHSA-c2jj-rr3q-vvv8.json +++ b/advisories/unreviewed/2024/02/GHSA-c2jj-rr3q-vvv8/GHSA-c2jj-rr3q-vvv8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jpph-v56f-mxcx/GHSA-jpph-v56f-mxcx.json b/advisories/unreviewed/2024/02/GHSA-jpph-v56f-mxcx/GHSA-jpph-v56f-mxcx.json index 61bf77eb2eb..3f0ebb2195c 100644 --- a/advisories/unreviewed/2024/02/GHSA-jpph-v56f-mxcx/GHSA-jpph-v56f-mxcx.json +++ b/advisories/unreviewed/2024/02/GHSA-jpph-v56f-mxcx/GHSA-jpph-v56f-mxcx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pf5w-4v9j-2h6f/GHSA-pf5w-4v9j-2h6f.json b/advisories/unreviewed/2024/02/GHSA-pf5w-4v9j-2h6f/GHSA-pf5w-4v9j-2h6f.json index be591237016..bab66b6119e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pf5w-4v9j-2h6f/GHSA-pf5w-4v9j-2h6f.json +++ b/advisories/unreviewed/2024/02/GHSA-pf5w-4v9j-2h6f/GHSA-pf5w-4v9j-2h6f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q7j6-j275-rpp9/GHSA-q7j6-j275-rpp9.json b/advisories/unreviewed/2024/02/GHSA-q7j6-j275-rpp9/GHSA-q7j6-j275-rpp9.json index 9824fc22408..6aea8711292 100644 --- a/advisories/unreviewed/2024/02/GHSA-q7j6-j275-rpp9/GHSA-q7j6-j275-rpp9.json +++ b/advisories/unreviewed/2024/02/GHSA-q7j6-j275-rpp9/GHSA-q7j6-j275-rpp9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3hwx-j4f5-4679/GHSA-3hwx-j4f5-4679.json b/advisories/unreviewed/2024/03/GHSA-3hwx-j4f5-4679/GHSA-3hwx-j4f5-4679.json index 5d6079569fb..9e9d568e6cd 100644 --- a/advisories/unreviewed/2024/03/GHSA-3hwx-j4f5-4679/GHSA-3hwx-j4f5-4679.json +++ b/advisories/unreviewed/2024/03/GHSA-3hwx-j4f5-4679/GHSA-3hwx-j4f5-4679.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hwx-j4f5-4679", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-16T15:32:08Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1311" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mhhx-6fx9-j9g3/GHSA-mhhx-6fx9-j9g3.json b/advisories/unreviewed/2024/03/GHSA-mhhx-6fx9-j9g3/GHSA-mhhx-6fx9-j9g3.json index b60b1bdf02c..53c2ca42cef 100644 --- a/advisories/unreviewed/2024/03/GHSA-mhhx-6fx9-j9g3/GHSA-mhhx-6fx9-j9g3.json +++ b/advisories/unreviewed/2024/03/GHSA-mhhx-6fx9-j9g3/GHSA-mhhx-6fx9-j9g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhhx-6fx9-j9g3", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-16T15:32:07Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1291" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pmxm-fxfv-x7fm/GHSA-pmxm-fxfv-x7fm.json b/advisories/unreviewed/2024/03/GHSA-pmxm-fxfv-x7fm/GHSA-pmxm-fxfv-x7fm.json index 2323e8b15c3..ab20945f974 100644 --- a/advisories/unreviewed/2024/03/GHSA-pmxm-fxfv-x7fm/GHSA-pmxm-fxfv-x7fm.json +++ b/advisories/unreviewed/2024/03/GHSA-pmxm-fxfv-x7fm/GHSA-pmxm-fxfv-x7fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmxm-fxfv-x7fm", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-16T15:32:07Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1293" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wfjc-qm6c-mf24/GHSA-wfjc-qm6c-mf24.json b/advisories/unreviewed/2024/03/GHSA-wfjc-qm6c-mf24/GHSA-wfjc-qm6c-mf24.json index 6b589535bae..c4a42e3dc86 100644 --- a/advisories/unreviewed/2024/03/GHSA-wfjc-qm6c-mf24/GHSA-wfjc-qm6c-mf24.json +++ b/advisories/unreviewed/2024/03/GHSA-wfjc-qm6c-mf24/GHSA-wfjc-qm6c-mf24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfjc-qm6c-mf24", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-16T15:32:07Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1296" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-64xx-mg7j-4q4c/GHSA-64xx-mg7j-4q4c.json b/advisories/unreviewed/2024/05/GHSA-64xx-mg7j-4q4c/GHSA-64xx-mg7j-4q4c.json index fc6893c1a59..5747172c7db 100644 --- a/advisories/unreviewed/2024/05/GHSA-64xx-mg7j-4q4c/GHSA-64xx-mg7j-4q4c.json +++ b/advisories/unreviewed/2024/05/GHSA-64xx-mg7j-4q4c/GHSA-64xx-mg7j-4q4c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-72pg-72hh-vvpx/GHSA-72pg-72hh-vvpx.json b/advisories/unreviewed/2024/05/GHSA-72pg-72hh-vvpx/GHSA-72pg-72hh-vvpx.json index c82466e7c93..5ceab0e2ab2 100644 --- a/advisories/unreviewed/2024/05/GHSA-72pg-72hh-vvpx/GHSA-72pg-72hh-vvpx.json +++ b/advisories/unreviewed/2024/05/GHSA-72pg-72hh-vvpx/GHSA-72pg-72hh-vvpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72pg-72hh-vvpx", - "modified": "2024-06-03T18:56:20Z", + "modified": "2025-01-16T15:32:08Z", "published": "2024-05-23T06:30:45Z", "aliases": [ "CVE-2024-3711" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2r6x-62fv-h4q4/GHSA-2r6x-62fv-h4q4.json b/advisories/unreviewed/2024/07/GHSA-2r6x-62fv-h4q4/GHSA-2r6x-62fv-h4q4.json index 0f4523017f6..e7df33b07d8 100644 --- a/advisories/unreviewed/2024/07/GHSA-2r6x-62fv-h4q4/GHSA-2r6x-62fv-h4q4.json +++ b/advisories/unreviewed/2024/07/GHSA-2r6x-62fv-h4q4/GHSA-2r6x-62fv-h4q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r6x-62fv-h4q4", - "modified": "2024-07-16T09:30:39Z", + "modified": "2025-01-16T15:32:08Z", "published": "2024-07-16T09:30:39Z", "aliases": [ "CVE-2024-1937" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2r9v-8q3m-99hf/GHSA-2r9v-8q3m-99hf.json b/advisories/unreviewed/2024/07/GHSA-2r9v-8q3m-99hf/GHSA-2r9v-8q3m-99hf.json index c2719604879..047044b5d85 100644 --- a/advisories/unreviewed/2024/07/GHSA-2r9v-8q3m-99hf/GHSA-2r9v-8q3m-99hf.json +++ b/advisories/unreviewed/2024/07/GHSA-2r9v-8q3m-99hf/GHSA-2r9v-8q3m-99hf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-2r8x-hvqm-j9xf/GHSA-2r8x-hvqm-j9xf.json b/advisories/unreviewed/2025/01/GHSA-2r8x-hvqm-j9xf/GHSA-2r8x-hvqm-j9xf.json index b84ee5a94a6..f8b7cea9351 100644 --- a/advisories/unreviewed/2025/01/GHSA-2r8x-hvqm-j9xf/GHSA-2r8x-hvqm-j9xf.json +++ b/advisories/unreviewed/2025/01/GHSA-2r8x-hvqm-j9xf/GHSA-2r8x-hvqm-j9xf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r8x-hvqm-j9xf", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:08Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-54460" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: iso: Fix circular lock in iso_listen_bis\n\nThis fixes the circular locking dependency warning below, by\nreleasing the socket lock before enterning iso_listen_bis, to\navoid any potential deadlock with hdev lock.\n\n[ 75.307983] ======================================================\n[ 75.307984] WARNING: possible circular locking dependency detected\n[ 75.307985] 6.12.0-rc6+ #22 Not tainted\n[ 75.307987] ------------------------------------------------------\n[ 75.307987] kworker/u81:2/2623 is trying to acquire lock:\n[ 75.307988] ffff8fde1769da58 (sk_lock-AF_BLUETOOTH-BTPROTO_ISO)\n at: iso_connect_cfm+0x253/0x840 [bluetooth]\n[ 75.308021]\n but task is already holding lock:\n[ 75.308022] ffff8fdd61a10078 (&hdev->lock)\n at: hci_le_per_adv_report_evt+0x47/0x2f0 [bluetooth]\n[ 75.308053]\n which lock already depends on the new lock.\n\n[ 75.308054]\n the existing dependency chain (in reverse order) is:\n[ 75.308055]\n -> #1 (&hdev->lock){+.+.}-{3:3}:\n[ 75.308057] __mutex_lock+0xad/0xc50\n[ 75.308061] mutex_lock_nested+0x1b/0x30\n[ 75.308063] iso_sock_listen+0x143/0x5c0 [bluetooth]\n[ 75.308085] __sys_listen_socket+0x49/0x60\n[ 75.308088] __x64_sys_listen+0x4c/0x90\n[ 75.308090] x64_sys_call+0x2517/0x25f0\n[ 75.308092] do_syscall_64+0x87/0x150\n[ 75.308095] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 75.308098]\n -> #0 (sk_lock-AF_BLUETOOTH-BTPROTO_ISO){+.+.}-{0:0}:\n[ 75.308100] __lock_acquire+0x155e/0x25f0\n[ 75.308103] lock_acquire+0xc9/0x300\n[ 75.308105] lock_sock_nested+0x32/0x90\n[ 75.308107] iso_connect_cfm+0x253/0x840 [bluetooth]\n[ 75.308128] hci_connect_cfm+0x6c/0x190 [bluetooth]\n[ 75.308155] hci_le_per_adv_report_evt+0x27b/0x2f0 [bluetooth]\n[ 75.308180] hci_le_meta_evt+0xe7/0x200 [bluetooth]\n[ 75.308206] hci_event_packet+0x21f/0x5c0 [bluetooth]\n[ 75.308230] hci_rx_work+0x3ae/0xb10 [bluetooth]\n[ 75.308254] process_one_work+0x212/0x740\n[ 75.308256] worker_thread+0x1bd/0x3a0\n[ 75.308258] kthread+0xe4/0x120\n[ 75.308259] ret_from_fork+0x44/0x70\n[ 75.308261] ret_from_fork_asm+0x1a/0x30\n[ 75.308263]\n other info that might help us debug this:\n\n[ 75.308264] Possible unsafe locking scenario:\n\n[ 75.308264] CPU0 CPU1\n[ 75.308265] ---- ----\n[ 75.308265] lock(&hdev->lock);\n[ 75.308267] lock(sk_lock-\n AF_BLUETOOTH-BTPROTO_ISO);\n[ 75.308268] lock(&hdev->lock);\n[ 75.308269] lock(sk_lock-AF_BLUETOOTH-BTPROTO_ISO);\n[ 75.308270]\n *** DEADLOCK ***\n\n[ 75.308271] 4 locks held by kworker/u81:2/2623:\n[ 75.308272] #0: ffff8fdd66e52148 ((wq_completion)hci0#2){+.+.}-{0:0},\n at: process_one_work+0x443/0x740\n[ 75.308276] #1: ffffafb488b7fe48 ((work_completion)(&hdev->rx_work)),\n at: process_one_work+0x1ce/0x740\n[ 75.308280] #2: ffff8fdd61a10078 (&hdev->lock){+.+.}-{3:3}\n at: hci_le_per_adv_report_evt+0x47/0x2f0 [bluetooth]\n[ 75.308304] #3: ffffffffb6ba4900 (rcu_read_lock){....}-{1:2},\n at: hci_connect_cfm+0x29/0x190 [bluetooth]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json b/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json index ce024b8a575..96a9d01cbb2 100644 --- a/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json +++ b/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3jfq-4f5c-mp6v", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:10Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22912" ], "details": "RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4q3j-cpv6-g583/GHSA-4q3j-cpv6-g583.json b/advisories/unreviewed/2025/01/GHSA-4q3j-cpv6-g583/GHSA-4q3j-cpv6-g583.json index 542bca2d8eb..25fc02b8f4c 100644 --- a/advisories/unreviewed/2025/01/GHSA-4q3j-cpv6-g583/GHSA-4q3j-cpv6-g583.json +++ b/advisories/unreviewed/2025/01/GHSA-4q3j-cpv6-g583/GHSA-4q3j-cpv6-g583.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4q3j-cpv6-g583", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:10Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22913" ], "details": "RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4qcv-j3wr-hw24/GHSA-4qcv-j3wr-hw24.json b/advisories/unreviewed/2025/01/GHSA-4qcv-j3wr-hw24/GHSA-4qcv-j3wr-hw24.json index d083609296e..dadafc83628 100644 --- a/advisories/unreviewed/2025/01/GHSA-4qcv-j3wr-hw24/GHSA-4qcv-j3wr-hw24.json +++ b/advisories/unreviewed/2025/01/GHSA-4qcv-j3wr-hw24/GHSA-4qcv-j3wr-hw24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qcv-j3wr-hw24", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-54683" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: IDLETIMER: Fix for possible ABBA deadlock\n\nDeletion of the last rule referencing a given idletimer may happen at\nthe same time as a read of its file in sysfs:\n\n| ======================================================\n| WARNING: possible circular locking dependency detected\n| 6.12.0-rc7-01692-g5e9a28f41134-dirty #594 Not tainted\n| ------------------------------------------------------\n| iptables/3303 is trying to acquire lock:\n| ffff8881057e04b8 (kn->active#48){++++}-{0:0}, at: __kernfs_remove+0x20\n|\n| but task is already holding lock:\n| ffffffffa0249068 (list_mutex){+.+.}-{3:3}, at: idletimer_tg_destroy_v]\n|\n| which lock already depends on the new lock.\n\nA simple reproducer is:\n\n| #!/bin/bash\n|\n| while true; do\n| iptables -A INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\"\n| iptables -D INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\"\n| done &\n| while true; do\n| cat /sys/class/xt_idletimer/timers/testme >/dev/null\n| done\n\nAvoid this by freeing list_mutex right after deleting the element from\nthe list, then continuing with the teardown.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4vfx-xrp7-4c4h/GHSA-4vfx-xrp7-4c4h.json b/advisories/unreviewed/2025/01/GHSA-4vfx-xrp7-4c4h/GHSA-4vfx-xrp7-4c4h.json new file mode 100644 index 00000000000..86075319dde --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4vfx-xrp7-4c4h/GHSA-4vfx-xrp7-4c4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vfx-xrp7-4c4h", + "modified": "2025-01-16T15:32:10Z", + "published": "2025-01-16T15:32:10Z", + "aliases": [ + "CVE-2025-0473" + ], + "details": "Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoint. When a file is uploaded via this resource, the server will create a temporary file that will be deleted after the client sends a POST request to ‘/pmb/authorities/import/iimport_authorities’. This workflow is automated by the web client, however an attacker can trap and launch the second POST request to prevent the temporary file from being deleted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0473" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-pmb-platform" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-16T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json b/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json index 024a765744c..060950e260d 100644 --- a/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json +++ b/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-55ww-9933-hhf5", - "modified": "2025-01-15T21:31:41Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T21:31:41Z", "aliases": [ "CVE-2024-27856" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T20:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6jqj-g976-vcvw/GHSA-6jqj-g976-vcvw.json b/advisories/unreviewed/2025/01/GHSA-6jqj-g976-vcvw/GHSA-6jqj-g976-vcvw.json index 5ee60d2042a..36e97eb8be3 100644 --- a/advisories/unreviewed/2025/01/GHSA-6jqj-g976-vcvw/GHSA-6jqj-g976-vcvw.json +++ b/advisories/unreviewed/2025/01/GHSA-6jqj-g976-vcvw/GHSA-6jqj-g976-vcvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6jqj-g976-vcvw", - "modified": "2025-01-11T15:30:30Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:30Z", "aliases": [ "CVE-2024-57872" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()\n\nThis will ensure that the scsi host is cleaned up properly using\nscsi_host_dev_release(). Otherwise, it may lead to memory leaks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T15:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6mfj-59wv-v5jx/GHSA-6mfj-59wv-v5jx.json b/advisories/unreviewed/2025/01/GHSA-6mfj-59wv-v5jx/GHSA-6mfj-59wv-v5jx.json index ecf96646be4..e9d847e406f 100644 --- a/advisories/unreviewed/2025/01/GHSA-6mfj-59wv-v5jx/GHSA-6mfj-59wv-v5jx.json +++ b/advisories/unreviewed/2025/01/GHSA-6mfj-59wv-v5jx/GHSA-6mfj-59wv-v5jx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6mfj-59wv-v5jx", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-55642" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Prevent potential deadlocks in zone write plug error recovery\n\nZone write plugging for handling writes to zones of a zoned block\ndevice always execute a zone report whenever a write BIO to a zone\nfails. The intent of this is to ensure that the tracking of a zone write\npointer is always correct to ensure that the alignment to a zone write\npointer of write BIOs can be checked on submission and that we can\nalways correctly emulate zone append operations using regular write\nBIOs.\n\nHowever, this error recovery scheme introduces a potential deadlock if a\ndevice queue freeze is initiated while BIOs are still plugged in a zone\nwrite plug and one of these write operation fails. In such case, the\ndisk zone write plug error recovery work is scheduled and executes a\nreport zone. This in turn can result in a request allocation in the\nunderlying driver to issue the report zones command to the device. But\nwith the device queue freeze already started, this allocation will\nblock, preventing the report zone execution and the continuation of the\nprocessing of the plugged BIOs. As plugged BIOs hold a queue usage\nreference, the queue freeze itself will never complete, resulting in a\ndeadlock.\n\nAvoid this problem by completely removing from the zone write plugging\ncode the use of report zones operations after a failed write operation,\ninstead relying on the device user to either execute a report zones,\nreset the zone, finish the zone, or give up writing to the device (which\nis a fairly common pattern for file systems which degrade to read-only\nafter write failures). This is not an unreasonnable requirement as all\nwell-behaved applications, FSes and device mapper already use report\nzones to recover from write errors whenever possible by comparing the\ncurrent position of a zone write pointer with what their assumption\nabout the position is.\n\nThe changes to remove the automatic error recovery are as follows:\n - Completely remove the error recovery work and its associated\n resources (zone write plug list head, disk error list, and disk\n zone_wplugs_work work struct). This also removes the functions\n disk_zone_wplug_set_error() and disk_zone_wplug_clear_error().\n\n - Change the BLK_ZONE_WPLUG_ERROR zone write plug flag into\n BLK_ZONE_WPLUG_NEED_WP_UPDATE. This new flag is set for a zone write\n plug whenever a write opration targetting the zone of the zone write\n plug fails. This flag indicates that the zone write pointer offset is\n not reliable and that it must be updated when the next report zone,\n reset zone, finish zone or disk revalidation is executed.\n\n - Modify blk_zone_write_plug_bio_endio() to set the\n BLK_ZONE_WPLUG_NEED_WP_UPDATE flag for the target zone of a failed\n write BIO.\n\n - Modify the function disk_zone_wplug_set_wp_offset() to clear this\n new flag, thus implementing recovery of a correct write pointer\n offset with the reset (all) zone and finish zone operations.\n\n - Modify blkdev_report_zones() to always use the disk_report_zones_cb()\n callback so that disk_zone_wplug_sync_wp_offset() can be called for\n any zone marked with the BLK_ZONE_WPLUG_NEED_WP_UPDATE flag.\n This implements recovery of a correct write pointer offset for zone\n write plugs marked with BLK_ZONE_WPLUG_NEED_WP_UPDATE and within\n the range of the report zones operation executed by the user.\n\n - Modify blk_revalidate_seq_zone() to call\n disk_zone_wplug_sync_wp_offset() for all sequential write required\n zones when a zoned block device is revalidated, thus always resolving\n any inconsistency between the write pointer offset of zone write\n plugs and the actual write pointer position of sequential zones.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7x5p-5275-mmvg/GHSA-7x5p-5275-mmvg.json b/advisories/unreviewed/2025/01/GHSA-7x5p-5275-mmvg/GHSA-7x5p-5275-mmvg.json index 3c890c22903..266e0f92e39 100644 --- a/advisories/unreviewed/2025/01/GHSA-7x5p-5275-mmvg/GHSA-7x5p-5275-mmvg.json +++ b/advisories/unreviewed/2025/01/GHSA-7x5p-5275-mmvg/GHSA-7x5p-5275-mmvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x5p-5275-mmvg", - "modified": "2025-01-11T18:30:33Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T18:30:33Z", "aliases": [ "CVE-2024-57881" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: don't call pfn_to_page() on possibly non-existent PFN in split_large_buddy()\n\nIn split_large_buddy(), we might call pfn_to_page() on a PFN that might\nnot exist. In corner cases, such as when freeing the highest pageblock in\nthe last memory section, this could result with CONFIG_SPARSEMEM &&\n!CONFIG_SPARSEMEM_EXTREME in __pfn_to_section() returning NULL and and\n__section_mem_map_addr() dereferencing that NULL pointer.\n\nLet's fix it, and avoid doing a pfn_to_page() call for the first\niteration, where we already have the page.\n\nSo far this was found by code inspection, but let's just CC stable as the\nfix is easy.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T16:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8wj4-7hpq-qj4h/GHSA-8wj4-7hpq-qj4h.json b/advisories/unreviewed/2025/01/GHSA-8wj4-7hpq-qj4h/GHSA-8wj4-7hpq-qj4h.json index f7af9959234..b4039ce61dc 100644 --- a/advisories/unreviewed/2025/01/GHSA-8wj4-7hpq-qj4h/GHSA-8wj4-7hpq-qj4h.json +++ b/advisories/unreviewed/2025/01/GHSA-8wj4-7hpq-qj4h/GHSA-8wj4-7hpq-qj4h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8wj4-7hpq-qj4h", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22906" ], "details": "RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json b/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json index 0e97156aae2..02129ff77c4 100644 --- a/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json +++ b/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pv3-7hg6-7xj7", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57014" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"recHour\" parameter in setScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9v96-cvr8-jw8x/GHSA-9v96-cvr8-jw8x.json b/advisories/unreviewed/2025/01/GHSA-9v96-cvr8-jw8x/GHSA-9v96-cvr8-jw8x.json index 55e50d1675f..c5bb8773a3f 100644 --- a/advisories/unreviewed/2025/01/GHSA-9v96-cvr8-jw8x/GHSA-9v96-cvr8-jw8x.json +++ b/advisories/unreviewed/2025/01/GHSA-9v96-cvr8-jw8x/GHSA-9v96-cvr8-jw8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9v96-cvr8-jw8x", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-57799" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: rockchip: samsung-hdptx: Set drvdata before enabling runtime PM\n\nIn some cases, rk_hdptx_phy_runtime_resume() may be invoked before\nplatform_set_drvdata() is executed in ->probe(), leading to a NULL\npointer dereference when using the return of dev_get_drvdata().\n\nEnsure platform_set_drvdata() is called before devm_pm_runtime_enable().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c7pw-v853-4qp9/GHSA-c7pw-v853-4qp9.json b/advisories/unreviewed/2025/01/GHSA-c7pw-v853-4qp9/GHSA-c7pw-v853-4qp9.json index ec625fb801e..813d28319c7 100644 --- a/advisories/unreviewed/2025/01/GHSA-c7pw-v853-4qp9/GHSA-c7pw-v853-4qp9.json +++ b/advisories/unreviewed/2025/01/GHSA-c7pw-v853-4qp9/GHSA-c7pw-v853-4qp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c7pw-v853-4qp9", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:10Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22916" ], "details": "RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cr25-mcg8-cfvp/GHSA-cr25-mcg8-cfvp.json b/advisories/unreviewed/2025/01/GHSA-cr25-mcg8-cfvp/GHSA-cr25-mcg8-cfvp.json index df50b5320bb..7825b75f0a3 100644 --- a/advisories/unreviewed/2025/01/GHSA-cr25-mcg8-cfvp/GHSA-cr25-mcg8-cfvp.json +++ b/advisories/unreviewed/2025/01/GHSA-cr25-mcg8-cfvp/GHSA-cr25-mcg8-cfvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr25-mcg8-cfvp", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-57807" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: megaraid_sas: Fix for a potential deadlock\n\nThis fixes a 'possible circular locking dependency detected' warning\n CPU0 CPU1\n ---- ----\n lock(&instance->reset_mutex);\n lock(&shost->scan_mutex);\n lock(&instance->reset_mutex);\n lock(&shost->scan_mutex);\n\nFix this by temporarily releasing the reset_mutex.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:30Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json index 573e2f2aff5..7a12316bb40 100644 --- a/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json +++ b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f69c-c87p-g4rh", - "modified": "2025-01-15T21:31:42Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T21:31:42Z", "aliases": [ "CVE-2024-44136" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T20:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json b/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json index b146613713e..9beb513488f 100644 --- a/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json +++ b/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3x2-jq2q-7r55", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:57Z", "aliases": [ "CVE-2024-57013" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"switch\" parameter in setScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json b/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json index 2297a57e79c..d8de5957ef2 100644 --- a/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json +++ b/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hg7g-25jg-2gmw", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:57Z", "aliases": [ "CVE-2024-57012" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"week\" parameter in setScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jqw4-2625-36jw/GHSA-jqw4-2625-36jw.json b/advisories/unreviewed/2025/01/GHSA-jqw4-2625-36jw/GHSA-jqw4-2625-36jw.json index cdc56f12a5a..56e5726ca94 100644 --- a/advisories/unreviewed/2025/01/GHSA-jqw4-2625-36jw/GHSA-jqw4-2625-36jw.json +++ b/advisories/unreviewed/2025/01/GHSA-jqw4-2625-36jw/GHSA-jqw4-2625-36jw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqw4-2625-36jw", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22905" ], "details": "RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json b/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json index 5ef93009259..d52d5a98f83 100644 --- a/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json +++ b/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jw5g-j894-hv7p", - "modified": "2025-01-15T21:31:42Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T21:31:42Z", "aliases": [ "CVE-2024-54540" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mg8f-gmvx-pvjj/GHSA-mg8f-gmvx-pvjj.json b/advisories/unreviewed/2025/01/GHSA-mg8f-gmvx-pvjj/GHSA-mg8f-gmvx-pvjj.json index 3d27a6553f4..efbd6e01bfb 100644 --- a/advisories/unreviewed/2025/01/GHSA-mg8f-gmvx-pvjj/GHSA-mg8f-gmvx-pvjj.json +++ b/advisories/unreviewed/2025/01/GHSA-mg8f-gmvx-pvjj/GHSA-mg8f-gmvx-pvjj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mg8f-gmvx-pvjj", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-56369" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/modes: Avoid divide by zero harder in drm_mode_vrefresh()\n\ndrm_mode_vrefresh() is trying to avoid divide by zero\nby checking whether htotal or vtotal are zero. But we may\nstill end up with a div-by-zero of vtotal*htotal*...", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json b/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json index 65417f73936..60176275670 100644 --- a/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json +++ b/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mx37-rcg6-jwqh", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57016" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"user\" parameter in setVpnAccountCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qcvg-j4c3-wxh2/GHSA-qcvg-j4c3-wxh2.json b/advisories/unreviewed/2025/01/GHSA-qcvg-j4c3-wxh2/GHSA-qcvg-j4c3-wxh2.json new file mode 100644 index 00000000000..615f18ce2de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcvg-j4c3-wxh2/GHSA-qcvg-j4c3-wxh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcvg-j4c3-wxh2", + "modified": "2025-01-16T15:32:10Z", + "published": "2025-01-16T15:32:10Z", + "aliases": [ + "CVE-2025-0471" + ], + "details": "Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0471" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-pmb-platform" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-16T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json b/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json index 103614fe33a..24eec985d26 100644 --- a/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json +++ b/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrj7-mr7g-fh9r", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:57Z", "aliases": [ "CVE-2024-57011" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"minute\" parameters in setScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r35m-8jf8-g83g/GHSA-r35m-8jf8-g83g.json b/advisories/unreviewed/2025/01/GHSA-r35m-8jf8-g83g/GHSA-r35m-8jf8-g83g.json index 52d62066c5e..c800cd28ee7 100644 --- a/advisories/unreviewed/2025/01/GHSA-r35m-8jf8-g83g/GHSA-r35m-8jf8-g83g.json +++ b/advisories/unreviewed/2025/01/GHSA-r35m-8jf8-g83g/GHSA-r35m-8jf8-g83g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r35m-8jf8-g83g", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-55916" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: util: Avoid accessing a ringbuffer not initialized yet\n\nIf the KVP (or VSS) daemon starts before the VMBus channel's ringbuffer is\nfully initialized, we can hit the panic below:\n\nhv_utils: Registering HyperV Utility Driver\nhv_vmbus: registering driver hv_utils\n...\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nCPU: 44 UID: 0 PID: 2552 Comm: hv_kvp_daemon Tainted: G E 6.11.0-rc3+ #1\nRIP: 0010:hv_pkt_iter_first+0x12/0xd0\nCall Trace:\n...\n vmbus_recvpacket\n hv_kvp_onchannelcallback\n vmbus_on_event\n tasklet_action_common\n tasklet_action\n handle_softirqs\n irq_exit_rcu\n sysvec_hyperv_stimer0\n \n \n asm_sysvec_hyperv_stimer0\n...\n kvp_register_done\n hvt_op_read\n vfs_read\n ksys_read\n __x64_sys_read\n\nThis can happen because the KVP/VSS channel callback can be invoked\neven before the channel is fully opened:\n1) as soon as hv_kvp_init() -> hvutil_transport_init() creates\n/dev/vmbus/hv_kvp, the kvp daemon can open the device file immediately and\nregister itself to the driver by writing a message KVP_OP_REGISTER1 to the\nfile (which is handled by kvp_on_msg() ->kvp_handle_handshake()) and\nreading the file for the driver's response, which is handled by\nhvt_op_read(), which calls hvt->on_read(), i.e. kvp_register_done().\n\n2) the problem with kvp_register_done() is that it can cause the\nchannel callback to be called even before the channel is fully opened,\nand when the channel callback is starting to run, util_probe()->\nvmbus_open() may have not initialized the ringbuffer yet, so the\ncallback can hit the panic of NULL pointer dereference.\n\nTo reproduce the panic consistently, we can add a \"ssleep(10)\" for KVP in\n__vmbus_open(), just before the first hv_ringbuffer_init(), and then we\nunload and reload the driver hv_utils, and run the daemon manually within\nthe 10 seconds.\n\nFix the panic by reordering the steps in util_probe() so the char dev\nentry used by the KVP or VSS daemon is not created until after\nvmbus_open() has completed. This reordering prevents the race condition\nfrom happening.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v5ff-x4g7-3gqc/GHSA-v5ff-x4g7-3gqc.json b/advisories/unreviewed/2025/01/GHSA-v5ff-x4g7-3gqc/GHSA-v5ff-x4g7-3gqc.json new file mode 100644 index 00000000000..b702f3e372f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v5ff-x4g7-3gqc/GHSA-v5ff-x4g7-3gqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5ff-x4g7-3gqc", + "modified": "2025-01-16T15:32:10Z", + "published": "2025-01-16T15:32:10Z", + "aliases": [ + "CVE-2025-0472" + ], + "details": "Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0472" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-pmb-platform" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-16T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vcjx-5pw3-c283/GHSA-vcjx-5pw3-c283.json b/advisories/unreviewed/2025/01/GHSA-vcjx-5pw3-c283/GHSA-vcjx-5pw3-c283.json index 55ecc304fc7..2eb94862900 100644 --- a/advisories/unreviewed/2025/01/GHSA-vcjx-5pw3-c283/GHSA-vcjx-5pw3-c283.json +++ b/advisories/unreviewed/2025/01/GHSA-vcjx-5pw3-c283/GHSA-vcjx-5pw3-c283.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcjx-5pw3-c283", - "modified": "2025-01-16T03:30:31Z", + "modified": "2025-01-16T15:32:10Z", "published": "2025-01-16T03:30:31Z", "aliases": [ "CVE-2025-22907" ], "details": "RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T03:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json b/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json index 098b599d391..0fe8a97f0f2 100644 --- a/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json +++ b/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwr4-cj7g-985f", - "modified": "2025-01-16T09:30:36Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T06:30:49Z", "aliases": [ "CVE-2025-23013" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/01/16/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/01/16/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-xfp4-237c-chrm/GHSA-xfp4-237c-chrm.json b/advisories/unreviewed/2025/01/GHSA-xfp4-237c-chrm/GHSA-xfp4-237c-chrm.json index 9cfd8c33756..1b69e414235 100644 --- a/advisories/unreviewed/2025/01/GHSA-xfp4-237c-chrm/GHSA-xfp4-237c-chrm.json +++ b/advisories/unreviewed/2025/01/GHSA-xfp4-237c-chrm/GHSA-xfp4-237c-chrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xfp4-237c-chrm", - "modified": "2025-01-11T15:30:29Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-11T15:30:29Z", "aliases": [ "CVE-2024-54680" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix TCP timers deadlock after rmmod\n\nCommit ef7134c7fc48 (\"smb: client: Fix use-after-free of network namespace.\")\nfixed a netns UAF by manually enabled socket refcounting\n(sk->sk_net_refcnt=1 and sock_inuse_add(net, 1)).\n\nThe reason the patch worked for that bug was because we now hold\nreferences to the netns (get_net_track() gets a ref internally)\nand they're properly released (internally, on __sk_destruct()),\nbut only because sk->sk_net_refcnt was set.\n\nProblem:\n(this happens regardless of CONFIG_NET_NS_REFCNT_TRACKER and regardless\nif init_net or other)\n\nSetting sk->sk_net_refcnt=1 *manually* and *after* socket creation is not\nonly out of cifs scope, but also technically wrong -- it's set conditionally\nbased on user (=1) vs kernel (=0) sockets. And net/ implementations\nseem to base their user vs kernel space operations on it.\n\ne.g. upon TCP socket close, the TCP timers are not cleared because\nsk->sk_net_refcnt=1:\n(cf. commit 151c9c724d05 (\"tcp: properly terminate timers for kernel sockets\"))\n\nnet/ipv4/tcp.c:\n void tcp_close(struct sock *sk, long timeout)\n {\n \tlock_sock(sk);\n \t__tcp_close(sk, timeout);\n \trelease_sock(sk);\n \tif (!sk->sk_net_refcnt)\n \t\tinet_csk_clear_xmit_timers_sync(sk);\n \tsock_put(sk);\n }\n\nWhich will throw a lockdep warning and then, as expected, deadlock on\ntcp_write_timer().\n\nA way to reproduce this is by running the reproducer from ef7134c7fc48\nand then 'rmmod cifs'. A few seconds later, the deadlock/lockdep\nwarning shows up.\n\nFix:\nWe shouldn't mess with socket internals ourselves, so do not set\nsk_net_refcnt manually.\n\nAlso change __sock_create() to sock_create_kern() for explicitness.\n\nAs for non-init_net network namespaces, we deal with it the best way\nwe can -- hold an extra netns reference for server->ssocket and drop it\nwhen it's released. This ensures that the netns still exists whenever\nwe need to create/destroy server->ssocket, but is not directly tied to\nit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json b/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json index 2982a67bc48..9aee3c6b751 100644 --- a/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json +++ b/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq2j-2jwj-gfcq", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-16T15:32:09Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57015" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"hour\" parameter in setScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:17Z"