diff --git a/advisories/unreviewed/2022/09/GHSA-2g9m-cfmh-9r83/GHSA-2g9m-cfmh-9r83.json b/advisories/unreviewed/2022/09/GHSA-2g9m-cfmh-9r83/GHSA-2g9m-cfmh-9r83.json index fa023038013..1b327c0316f 100644 --- a/advisories/unreviewed/2022/09/GHSA-2g9m-cfmh-9r83/GHSA-2g9m-cfmh-9r83.json +++ b/advisories/unreviewed/2022/09/GHSA-2g9m-cfmh-9r83/GHSA-2g9m-cfmh-9r83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g9m-cfmh-9r83", - "modified": "2022-09-27T00:00:17Z", + "modified": "2025-05-27T21:32:03Z", "published": "2022-09-22T00:00:22Z", "aliases": [ "CVE-2022-28802" diff --git a/advisories/unreviewed/2022/09/GHSA-637r-47cq-j74p/GHSA-637r-47cq-j74p.json b/advisories/unreviewed/2022/09/GHSA-637r-47cq-j74p/GHSA-637r-47cq-j74p.json index 588ea36409d..cabf52e52c4 100644 --- a/advisories/unreviewed/2022/09/GHSA-637r-47cq-j74p/GHSA-637r-47cq-j74p.json +++ b/advisories/unreviewed/2022/09/GHSA-637r-47cq-j74p/GHSA-637r-47cq-j74p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-637r-47cq-j74p", - "modified": "2022-09-25T00:00:20Z", + "modified": "2025-05-27T21:32:03Z", "published": "2022-09-22T00:00:23Z", "aliases": [ "CVE-2022-29799" diff --git a/advisories/unreviewed/2024/08/GHSA-725x-5972-gm8m/GHSA-725x-5972-gm8m.json b/advisories/unreviewed/2024/08/GHSA-725x-5972-gm8m/GHSA-725x-5972-gm8m.json index 173289131a2..f016b540e66 100644 --- a/advisories/unreviewed/2024/08/GHSA-725x-5972-gm8m/GHSA-725x-5972-gm8m.json +++ b/advisories/unreviewed/2024/08/GHSA-725x-5972-gm8m/GHSA-725x-5972-gm8m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-m33h-5r55-c5g3/GHSA-m33h-5r55-c5g3.json b/advisories/unreviewed/2024/08/GHSA-m33h-5r55-c5g3/GHSA-m33h-5r55-c5g3.json index c04865bcb2f..e0abf9d33d0 100644 --- a/advisories/unreviewed/2024/08/GHSA-m33h-5r55-c5g3/GHSA-m33h-5r55-c5g3.json +++ b/advisories/unreviewed/2024/08/GHSA-m33h-5r55-c5g3/GHSA-m33h-5r55-c5g3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json b/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json index de1cbc5108c..eaf19b7756d 100644 --- a/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json +++ b/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json b/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json index d5ef2cabbb6..99793d4ae83 100644 --- a/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json +++ b/advisories/unreviewed/2024/08/GHSA-q636-fx55-gfr2/GHSA-q636-fx55-gfr2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-532" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json b/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json index e5080c02217..bb8d39ef2c1 100644 --- a/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json +++ b/advisories/unreviewed/2024/08/GHSA-r3cc-j4fw-h337/GHSA-r3cc-j4fw-h337.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json b/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json index a53ea262174..838b0d1a7e1 100644 --- a/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json +++ b/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3gr-45jc-g2rp", - "modified": "2024-11-01T18:31:26Z", + "modified": "2025-05-27T21:32:09Z", "published": "2024-10-14T09:30:54Z", "aliases": [ "CVE-2024-46911" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/6m0ghjo9j92qty00t2qb6qf2spds0p5t" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/10/12/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json b/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json index 0435ff7a2a1..ab5a4921fea 100644 --- a/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json +++ b/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qjj-4522-pjgp", - "modified": "2025-04-01T12:30:34Z", + "modified": "2025-05-27T21:32:10Z", "published": "2025-04-01T12:30:34Z", "aliases": [ "CVE-2024-13553" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json b/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json index 88e88c14f79..82c6ee2f5bb 100644 --- a/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json +++ b/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-706", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-j26j-7rmc-jxf2/GHSA-j26j-7rmc-jxf2.json b/advisories/unreviewed/2025/04/GHSA-j26j-7rmc-jxf2/GHSA-j26j-7rmc-jxf2.json index c57ceb3e6e0..d7cf4e3df2f 100644 --- a/advisories/unreviewed/2025/04/GHSA-j26j-7rmc-jxf2/GHSA-j26j-7rmc-jxf2.json +++ b/advisories/unreviewed/2025/04/GHSA-j26j-7rmc-jxf2/GHSA-j26j-7rmc-jxf2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json b/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json index 679be2caf83..bff463f9a28 100644 --- a/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json +++ b/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-706", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json index aedddf27661..a71df3fa613 100644 --- a/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json +++ b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqxv-v2vg-q37x", - "modified": "2025-05-05T15:30:53Z", + "modified": "2025-05-27T21:32:11Z", "published": "2025-04-25T18:31:12Z", "aliases": [ "CVE-2025-3928" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic" + }, + { + "type": "WEB", + "url": "https://www.commvault.com/blogs/customer-security-update" + }, { "type": "WEB", "url": "https://www.commvault.com/blogs/notice-security-advisory-update" diff --git a/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json index 676c796895d..2e2a7519345 100644 --- a/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json +++ b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2qvr-7jvg-p9jj/GHSA-2qvr-7jvg-p9jj.json b/advisories/unreviewed/2025/05/GHSA-2qvr-7jvg-p9jj/GHSA-2qvr-7jvg-p9jj.json index cdaf6918a74..a8b8025999a 100644 --- a/advisories/unreviewed/2025/05/GHSA-2qvr-7jvg-p9jj/GHSA-2qvr-7jvg-p9jj.json +++ b/advisories/unreviewed/2025/05/GHSA-2qvr-7jvg-p9jj/GHSA-2qvr-7jvg-p9jj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3mmp-9r95-wfp8/GHSA-3mmp-9r95-wfp8.json b/advisories/unreviewed/2025/05/GHSA-3mmp-9r95-wfp8/GHSA-3mmp-9r95-wfp8.json index 23a13dd312d..a7454a545ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-3mmp-9r95-wfp8/GHSA-3mmp-9r95-wfp8.json +++ b/advisories/unreviewed/2025/05/GHSA-3mmp-9r95-wfp8/GHSA-3mmp-9r95-wfp8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json b/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json new file mode 100644 index 00000000000..ae4c0e57407 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4g9c-v26v-gp27/GHSA-4g9c-v26v-gp27.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g9c-v26v-gp27", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2025-5064" + ], + "details": "Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5064" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40058068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v9p-4hw8-6h36/GHSA-4v9p-4hw8-6h36.json b/advisories/unreviewed/2025/05/GHSA-4v9p-4hw8-6h36/GHSA-4v9p-4hw8-6h36.json index b4e6345e9ee..856590dddde 100644 --- a/advisories/unreviewed/2025/05/GHSA-4v9p-4hw8-6h36/GHSA-4v9p-4hw8-6h36.json +++ b/advisories/unreviewed/2025/05/GHSA-4v9p-4hw8-6h36/GHSA-4v9p-4hw8-6h36.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json index 8594d449227..40b836436b0 100644 --- a/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json +++ b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json b/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json new file mode 100644 index 00000000000..fb5101740c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-78m4-4wrg-v443/GHSA-78m4-4wrg-v443.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78m4-4wrg-v443", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2025-5065" + ], + "details": "Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5065" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40059071" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7pxh-wvx3-744g/GHSA-7pxh-wvx3-744g.json b/advisories/unreviewed/2025/05/GHSA-7pxh-wvx3-744g/GHSA-7pxh-wvx3-744g.json index 62b197c13cc..9db06568aff 100644 --- a/advisories/unreviewed/2025/05/GHSA-7pxh-wvx3-744g/GHSA-7pxh-wvx3-744g.json +++ b/advisories/unreviewed/2025/05/GHSA-7pxh-wvx3-744g/GHSA-7pxh-wvx3-744g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-89j4-2255-gq9x/GHSA-89j4-2255-gq9x.json b/advisories/unreviewed/2025/05/GHSA-89j4-2255-gq9x/GHSA-89j4-2255-gq9x.json new file mode 100644 index 00000000000..373b3c0ea92 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89j4-2255-gq9x/GHSA-89j4-2255-gq9x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89j4-2255-gq9x", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2025-45529" + ], + "details": "An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45529" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sec-Kode/000fbab6dc649888bc196e76a4076b57" + }, + { + "type": "WEB", + "url": "https://github.com/sec-Kode/cve/blob/main/cve2.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8c2v-67pw-jv95/GHSA-8c2v-67pw-jv95.json b/advisories/unreviewed/2025/05/GHSA-8c2v-67pw-jv95/GHSA-8c2v-67pw-jv95.json index f50ddcf4d6e..e5f73093ac3 100644 --- a/advisories/unreviewed/2025/05/GHSA-8c2v-67pw-jv95/GHSA-8c2v-67pw-jv95.json +++ b/advisories/unreviewed/2025/05/GHSA-8c2v-67pw-jv95/GHSA-8c2v-67pw-jv95.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json index 4bef8f0520d..48dbc40b29c 100644 --- a/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json +++ b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json b/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json new file mode 100644 index 00000000000..bd49a60cae5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c82m-4wjj-w8fw/GHSA-c82m-4wjj-w8fw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c82m-4wjj-w8fw", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5280" + ], + "details": "Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5280" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/417169470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json new file mode 100644 index 00000000000..94656572e7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ch64-4x3c-w3jq/GHSA-ch64-4x3c-w3jq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch64-4x3c-w3jq", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5278" + ], + "details": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5278" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368764" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cvpf-j6q6-97mx/GHSA-cvpf-j6q6-97mx.json b/advisories/unreviewed/2025/05/GHSA-cvpf-j6q6-97mx/GHSA-cvpf-j6q6-97mx.json new file mode 100644 index 00000000000..042b987defb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cvpf-j6q6-97mx/GHSA-cvpf-j6q6-97mx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpf-j6q6-97mx", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2025-46173" + ], + "details": "code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46173" + }, + { + "type": "WEB", + "url": "https://github.com/pruthuraut/CVE-2025-46173" + }, + { + "type": "WEB", + "url": "https://www.invicti.com/learn/blind-cross-site-scripting" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f8f2-g968-4xpm/GHSA-f8f2-g968-4xpm.json b/advisories/unreviewed/2025/05/GHSA-f8f2-g968-4xpm/GHSA-f8f2-g968-4xpm.json index 4656fe6ba07..99ff7f346ea 100644 --- a/advisories/unreviewed/2025/05/GHSA-f8f2-g968-4xpm/GHSA-f8f2-g968-4xpm.json +++ b/advisories/unreviewed/2025/05/GHSA-f8f2-g968-4xpm/GHSA-f8f2-g968-4xpm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-fcj3-9fc8-9489/GHSA-fcj3-9fc8-9489.json b/advisories/unreviewed/2025/05/GHSA-fcj3-9fc8-9489/GHSA-fcj3-9fc8-9489.json new file mode 100644 index 00000000000..0836f150d81 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fcj3-9fc8-9489/GHSA-fcj3-9fc8-9489.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcj3-9fc8-9489", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5198" + ], + "details": "A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5198" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5198" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368568" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fqmr-rqgw-fg3q/GHSA-fqmr-rqgw-fg3q.json b/advisories/unreviewed/2025/05/GHSA-fqmr-rqgw-fg3q/GHSA-fqmr-rqgw-fg3q.json new file mode 100644 index 00000000000..241876e2961 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fqmr-rqgw-fg3q/GHSA-fqmr-rqgw-fg3q.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqmr-rqgw-fg3q", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2024-13966" + ], + "details": "ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as \"Self-Password\").", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13966" + }, + { + "type": "WEB", + "url": "https://krashconsulting.com/fury-of-fingers-biotime-rce" + }, + { + "type": "WEB", + "url": "https://zkteco-store.ru/wp-content/uploads/2023/09/ZKBio-CVSecurity-6.0.0-User-Manual_EN-v1.0_20230616.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2rv-wm65-wfxv/GHSA-g2rv-wm65-wfxv.json b/advisories/unreviewed/2025/05/GHSA-g2rv-wm65-wfxv/GHSA-g2rv-wm65-wfxv.json index 18010dae2ff..40bd67b81e0 100644 --- a/advisories/unreviewed/2025/05/GHSA-g2rv-wm65-wfxv/GHSA-g2rv-wm65-wfxv.json +++ b/advisories/unreviewed/2025/05/GHSA-g2rv-wm65-wfxv/GHSA-g2rv-wm65-wfxv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json b/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json new file mode 100644 index 00000000000..3afbce1a609 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g3gr-c6vj-5j9j/GHSA-g3gr-c6vj-5j9j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3gr-c6vj-5j9j", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5066" + ], + "details": "Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5066" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/356658477" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc2c-8qc6-4x3w/GHSA-gc2c-8qc6-4x3w.json b/advisories/unreviewed/2025/05/GHSA-gc2c-8qc6-4x3w/GHSA-gc2c-8qc6-4x3w.json index e2ce242ef39..7837c2dc875 100644 --- a/advisories/unreviewed/2025/05/GHSA-gc2c-8qc6-4x3w/GHSA-gc2c-8qc6-4x3w.json +++ b/advisories/unreviewed/2025/05/GHSA-gc2c-8qc6-4x3w/GHSA-gc2c-8qc6-4x3w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json b/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json new file mode 100644 index 00000000000..df525ca1355 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hqjf-gj2q-64ch/GHSA-hqjf-gj2q-64ch.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqjf-gj2q-64ch", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5281" + ], + "details": "Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5281" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/417215501" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json index cfddde4ed1d..588712e3cfd 100644 --- a/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json +++ b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json b/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json new file mode 100644 index 00000000000..ae54acbe511 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j84v-78j2-55gh/GHSA-j84v-78j2-55gh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j84v-78j2-55gh", + "modified": "2025-05-27T21:32:18Z", + "published": "2025-05-27T21:32:18Z", + "aliases": [ + "CVE-2025-5283" + ], + "details": "Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5283" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/419467315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json b/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json index 1bc4e8f27af..d3d41cf3585 100644 --- a/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json +++ b/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p2hm-v956-rfwp/GHSA-p2hm-v956-rfwp.json b/advisories/unreviewed/2025/05/GHSA-p2hm-v956-rfwp/GHSA-p2hm-v956-rfwp.json index 696c4028def..ff77f7d2fc4 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2hm-v956-rfwp/GHSA-p2hm-v956-rfwp.json +++ b/advisories/unreviewed/2025/05/GHSA-p2hm-v956-rfwp/GHSA-p2hm-v956-rfwp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json index 6f04a1afcb3..6bb999b3f48 100644 --- a/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json +++ b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json index cfea318b2ad..65ca857900c 100644 --- a/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json +++ b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json index bc8fbfe704c..e946d60a4cb 100644 --- a/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json +++ b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json index 4d56335d92a..ef346fe19b3 100644 --- a/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json +++ b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json b/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json index 97ac1ce14a0..471eb34c10a 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json +++ b/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json index da3b6854333..bd6ce9bc8d0 100644 --- a/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json +++ b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json b/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json new file mode 100644 index 00000000000..33c1bcb504a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcfj-m4g8-j8jv/GHSA-vcfj-m4g8-j8jv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcfj-m4g8-j8jv", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5067" + ], + "details": "Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5067" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40075024" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json b/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json new file mode 100644 index 00000000000..99149e34411 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w87c-v4h6-r3wj/GHSA-w87c-v4h6-r3wj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87c-v4h6-r3wj", + "modified": "2025-05-27T21:32:16Z", + "published": "2025-05-27T21:32:16Z", + "aliases": [ + "CVE-2025-5063" + ], + "details": "Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5063" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/411573532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wv79-2fc4-v4hj/GHSA-wv79-2fc4-v4hj.json b/advisories/unreviewed/2025/05/GHSA-wv79-2fc4-v4hj/GHSA-wv79-2fc4-v4hj.json new file mode 100644 index 00000000000..6ab60ca4cdf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wv79-2fc4-v4hj/GHSA-wv79-2fc4-v4hj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv79-2fc4-v4hj", + "modified": "2025-05-27T21:32:17Z", + "published": "2025-05-27T21:32:17Z", + "aliases": [ + "CVE-2025-5222" + ], + "details": "A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5222" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5222" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x37m-q3cw-3j2c/GHSA-x37m-q3cw-3j2c.json b/advisories/unreviewed/2025/05/GHSA-x37m-q3cw-3j2c/GHSA-x37m-q3cw-3j2c.json index 9b2aaf782b6..e6beecb81b7 100644 --- a/advisories/unreviewed/2025/05/GHSA-x37m-q3cw-3j2c/GHSA-x37m-q3cw-3j2c.json +++ b/advisories/unreviewed/2025/05/GHSA-x37m-q3cw-3j2c/GHSA-x37m-q3cw-3j2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x37m-q3cw-3j2c", - "modified": "2025-05-27T18:30:51Z", + "modified": "2025-05-27T21:32:16Z", "published": "2025-05-27T18:30:51Z", "aliases": [ "CVE-2025-27701" ], "details": "In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB Read, leading to information disclosure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-27T16:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xrxr-xwxg-4g42/GHSA-xrxr-xwxg-4g42.json b/advisories/unreviewed/2025/05/GHSA-xrxr-xwxg-4g42/GHSA-xrxr-xwxg-4g42.json index 87e9e0b8754..b2a0e40e71e 100644 --- a/advisories/unreviewed/2025/05/GHSA-xrxr-xwxg-4g42/GHSA-xrxr-xwxg-4g42.json +++ b/advisories/unreviewed/2025/05/GHSA-xrxr-xwxg-4g42/GHSA-xrxr-xwxg-4g42.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,