diff --git a/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json b/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json index c5a7b49d0f5..94ba13d0460 100644 --- a/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json +++ b/advisories/github-reviewed/2024/10/GHSA-3h3x-2hwv-hr52/GHSA-3h3x-2hwv-hr52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h3x-2hwv-hr52", - "modified": "2025-05-13T09:31:08Z", + "modified": "2025-05-13T21:30:27Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9355" @@ -44,57 +44,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9355" }, - { - "type": "WEB", - "url": "https://github.com/github/advisory-database/pull/4950" - }, { "type": "WEB", "url": "https://github.com/golang-fips/openssl/pull/198" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:10133" + "url": "https://github.com/github/advisory-database/pull/4950" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:7502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:7550" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8327" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8678" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8847" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9551" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2416" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7118" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/CVE-2024-9355" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315719" + "url": "https://pkg.go.dev/vuln/GO-2024-3167" }, { "type": "PACKAGE", @@ -102,7 +62,51 @@ }, { "type": "WEB", - "url": "https://pkg.go.dev/vuln/GO-2024-3167" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315719" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9355" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7256" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7118" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2416" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9551" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8847" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8678" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8327" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7550" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10133" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-4x6r-28wm-339v/GHSA-4x6r-28wm-339v.json b/advisories/unreviewed/2022/10/GHSA-4x6r-28wm-339v/GHSA-4x6r-28wm-339v.json index 5ba27409ef3..9209d0b5f76 100644 --- a/advisories/unreviewed/2022/10/GHSA-4x6r-28wm-339v/GHSA-4x6r-28wm-339v.json +++ b/advisories/unreviewed/2022/10/GHSA-4x6r-28wm-339v/GHSA-4x6r-28wm-339v.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-c599-8gm5-c2jh/GHSA-c599-8gm5-c2jh.json b/advisories/unreviewed/2022/10/GHSA-c599-8gm5-c2jh/GHSA-c599-8gm5-c2jh.json index aca7cefb3b9..9c7d36fede9 100644 --- a/advisories/unreviewed/2022/10/GHSA-c599-8gm5-c2jh/GHSA-c599-8gm5-c2jh.json +++ b/advisories/unreviewed/2022/10/GHSA-c599-8gm5-c2jh/GHSA-c599-8gm5-c2jh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-hxc7-qjfv-5432/GHSA-hxc7-qjfv-5432.json b/advisories/unreviewed/2022/10/GHSA-hxc7-qjfv-5432/GHSA-hxc7-qjfv-5432.json index 52ba2bf142a..8e4f1f50c34 100644 --- a/advisories/unreviewed/2022/10/GHSA-hxc7-qjfv-5432/GHSA-hxc7-qjfv-5432.json +++ b/advisories/unreviewed/2022/10/GHSA-hxc7-qjfv-5432/GHSA-hxc7-qjfv-5432.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-j5p4-42cc-2j44/GHSA-j5p4-42cc-2j44.json b/advisories/unreviewed/2022/10/GHSA-j5p4-42cc-2j44/GHSA-j5p4-42cc-2j44.json index 7a54946788e..fc4211e2490 100644 --- a/advisories/unreviewed/2022/10/GHSA-j5p4-42cc-2j44/GHSA-j5p4-42cc-2j44.json +++ b/advisories/unreviewed/2022/10/GHSA-j5p4-42cc-2j44/GHSA-j5p4-42cc-2j44.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-415" + "CWE-415", + "CWE-416" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-wccp-g34r-cx74/GHSA-wccp-g34r-cx74.json b/advisories/unreviewed/2022/10/GHSA-wccp-g34r-cx74/GHSA-wccp-g34r-cx74.json index 31969d459d5..016805a2aed 100644 --- a/advisories/unreviewed/2022/10/GHSA-wccp-g34r-cx74/GHSA-wccp-g34r-cx74.json +++ b/advisories/unreviewed/2022/10/GHSA-wccp-g34r-cx74/GHSA-wccp-g34r-cx74.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-65xm-fp9j-m223/GHSA-65xm-fp9j-m223.json b/advisories/unreviewed/2022/11/GHSA-65xm-fp9j-m223/GHSA-65xm-fp9j-m223.json index af612893715..d0bf094a595 100644 --- a/advisories/unreviewed/2022/11/GHSA-65xm-fp9j-m223/GHSA-65xm-fp9j-m223.json +++ b/advisories/unreviewed/2022/11/GHSA-65xm-fp9j-m223/GHSA-65xm-fp9j-m223.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65xm-fp9j-m223", - "modified": "2022-11-19T00:30:56Z", + "modified": "2025-05-13T21:30:27Z", "published": "2022-11-15T12:00:16Z", "aliases": [ "CVE-2022-40845" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-425", "CWE-522" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-6f56-38v3-2xvq/GHSA-6f56-38v3-2xvq.json b/advisories/unreviewed/2022/11/GHSA-6f56-38v3-2xvq/GHSA-6f56-38v3-2xvq.json index d19b5c26a66..61dbdab7599 100644 --- a/advisories/unreviewed/2022/11/GHSA-6f56-38v3-2xvq/GHSA-6f56-38v3-2xvq.json +++ b/advisories/unreviewed/2022/11/GHSA-6f56-38v3-2xvq/GHSA-6f56-38v3-2xvq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-pmrf-3j56-wgg6/GHSA-pmrf-3j56-wgg6.json b/advisories/unreviewed/2022/11/GHSA-pmrf-3j56-wgg6/GHSA-pmrf-3j56-wgg6.json index 28891905d50..1983a5133cc 100644 --- a/advisories/unreviewed/2022/11/GHSA-pmrf-3j56-wgg6/GHSA-pmrf-3j56-wgg6.json +++ b/advisories/unreviewed/2022/11/GHSA-pmrf-3j56-wgg6/GHSA-pmrf-3j56-wgg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmrf-3j56-wgg6", - "modified": "2022-11-18T21:30:15Z", + "modified": "2025-05-13T21:30:27Z", "published": "2022-11-15T12:00:15Z", "aliases": [ "CVE-2022-42060" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json b/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json index fdd060b9817..849a5f50c9e 100644 --- a/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json +++ b/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mchj-fc27-3mfm", - "modified": "2024-04-04T05:29:31Z", + "modified": "2025-05-13T21:30:25Z", "published": "2023-07-06T19:24:01Z", "aliases": [ "CVE-2022-22128" diff --git a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json index d32550a94a2..b417d5ff61a 100644 --- a/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json +++ b/advisories/unreviewed/2024/10/GHSA-cjcf-6ch6-g3rx/GHSA-cjcf-6ch6-g3rx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjcf-6ch6-g3rx", - "modified": "2025-05-13T15:32:09Z", + "modified": "2025-05-13T21:30:27Z", "published": "2024-10-30T09:30:48Z", "aliases": [ "CVE-2024-9632" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9632" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7165" diff --git a/advisories/unreviewed/2025/01/GHSA-9grv-p46v-p3fp/GHSA-9grv-p46v-p3fp.json b/advisories/unreviewed/2025/01/GHSA-9grv-p46v-p3fp/GHSA-9grv-p46v-p3fp.json index 552b7111613..953eaf0142b 100644 --- a/advisories/unreviewed/2025/01/GHSA-9grv-p46v-p3fp/GHSA-9grv-p46v-p3fp.json +++ b/advisories/unreviewed/2025/01/GHSA-9grv-p46v-p3fp/GHSA-9grv-p46v-p3fp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json b/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json index 1289c3ae213..a95b5c1e2ac 100644 --- a/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json +++ b/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-mj6j-32rm-jv58/GHSA-mj6j-32rm-jv58.json b/advisories/unreviewed/2025/01/GHSA-mj6j-32rm-jv58/GHSA-mj6j-32rm-jv58.json index 0861eff372e..7a2d17e0ccb 100644 --- a/advisories/unreviewed/2025/01/GHSA-mj6j-32rm-jv58/GHSA-mj6j-32rm-jv58.json +++ b/advisories/unreviewed/2025/01/GHSA-mj6j-32rm-jv58/GHSA-mj6j-32rm-jv58.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json b/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json index 145d3e185ae..84bb47c58de 100644 --- a/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json +++ b/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-w8g9-387p-pmg5/GHSA-w8g9-387p-pmg5.json b/advisories/unreviewed/2025/01/GHSA-w8g9-387p-pmg5/GHSA-w8g9-387p-pmg5.json index 63b1a1abb63..5c3efd335e1 100644 --- a/advisories/unreviewed/2025/01/GHSA-w8g9-387p-pmg5/GHSA-w8g9-387p-pmg5.json +++ b/advisories/unreviewed/2025/01/GHSA-w8g9-387p-pmg5/GHSA-w8g9-387p-pmg5.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json index dafa672e59a..558b5476a45 100644 --- a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json +++ b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xfx-cg6v-cwqv", - "modified": "2025-02-18T21:32:51Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-18T21:32:51Z", "aliases": [ "CVE-2024-45781" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45781" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45781" diff --git a/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json b/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json index ca9c609f88a..972f11623db 100644 --- a/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json +++ b/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wxw-3vrc-3hmh", - "modified": "2025-02-18T21:32:51Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-18T21:32:51Z", "aliases": [ "CVE-2024-45783" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45783" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45783" diff --git a/advisories/unreviewed/2025/02/GHSA-6g4x-g72v-hmxh/GHSA-6g4x-g72v-hmxh.json b/advisories/unreviewed/2025/02/GHSA-6g4x-g72v-hmxh/GHSA-6g4x-g72v-hmxh.json index 064628214f9..65eef86f6eb 100644 --- a/advisories/unreviewed/2025/02/GHSA-6g4x-g72v-hmxh/GHSA-6g4x-g72v-hmxh.json +++ b/advisories/unreviewed/2025/02/GHSA-6g4x-g72v-hmxh/GHSA-6g4x-g72v-hmxh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-6ph7-q98h-prvf/GHSA-6ph7-q98h-prvf.json b/advisories/unreviewed/2025/02/GHSA-6ph7-q98h-prvf/GHSA-6ph7-q98h-prvf.json index 0cbc0636e9f..f6e1304257f 100644 --- a/advisories/unreviewed/2025/02/GHSA-6ph7-q98h-prvf/GHSA-6ph7-q98h-prvf.json +++ b/advisories/unreviewed/2025/02/GHSA-6ph7-q98h-prvf/GHSA-6ph7-q98h-prvf.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json index 6924e884c86..e25b30914f6 100644 --- a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json +++ b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q4p-93g6-4wf9", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:29Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26600" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345252" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345252" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json index c44b45e2e95..4b275919a78 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json +++ b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qjx-378m-p8hm", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:29Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26597" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345255" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345255" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json b/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json index c83322d3e6c..5ce410dc0db 100644 --- a/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json +++ b/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8852-57vj-5pjq", - "modified": "2025-02-18T21:32:51Z", + "modified": "2025-05-13T21:30:27Z", "published": "2025-02-18T21:32:51Z", "aliases": [ "CVE-2024-45776" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45776" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45776" diff --git a/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json b/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json index b51877a8714..03e6b3005cb 100644 --- a/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json +++ b/advisories/unreviewed/2025/02/GHSA-9fg2-2f57-9p5h/GHSA-9fg2-2f57-9p5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fg2-2f57-9p5h", - "modified": "2025-03-05T21:32:05Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-24T09:35:45Z", "aliases": [ "CVE-2025-0690" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0690" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0690" diff --git a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json index 83d54e3f69f..3f065657c6f 100644 --- a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json +++ b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c28h-3w95-v6xg", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:29Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26598" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345254" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345254" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json index efa36ed9dc7..08da514fb85 100644 --- a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json +++ b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c52f-45m8-h2r6", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26596" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345256" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345256" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json b/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json index fa189027365..06448ea0fda 100644 --- a/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json +++ b/advisories/unreviewed/2025/02/GHSA-cqj4-fp95-jqxq/GHSA-cqj4-fp95-jqxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqj4-fp95-jqxq", - "modified": "2025-04-23T12:31:25Z", + "modified": "2025-05-13T21:30:27Z", "published": "2025-02-10T18:30:46Z", "aliases": [ "CVE-2024-12243" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4051" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7076" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12243" diff --git a/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json index 36dfd09ca46..4bc826288a6 100644 --- a/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json +++ b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5v2-rhg6-jmg7", - "modified": "2025-03-05T21:32:04Z", + "modified": "2025-05-13T21:30:27Z", "published": "2025-02-18T21:32:50Z", "aliases": [ "CVE-2024-45774" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45774" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45774" diff --git a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json index b89d3bfe0f6..3e57a2c5407 100644 --- a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json +++ b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc32-fmf5-c742", - "modified": "2025-05-13T15:32:09Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26594" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345248" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345248" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json index 63d8d6760d1..bf167869700 100644 --- a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json +++ b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf8x-6jh7-3mjv", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:30Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26601" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345251" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345251" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-h592-gmp8-rvr7/GHSA-h592-gmp8-rvr7.json b/advisories/unreviewed/2025/02/GHSA-h592-gmp8-rvr7/GHSA-h592-gmp8-rvr7.json index 246a41394d0..070285d83d9 100644 --- a/advisories/unreviewed/2025/02/GHSA-h592-gmp8-rvr7/GHSA-h592-gmp8-rvr7.json +++ b/advisories/unreviewed/2025/02/GHSA-h592-gmp8-rvr7/GHSA-h592-gmp8-rvr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h592-gmp8-rvr7", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2025-0677" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0677" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0677" diff --git a/advisories/unreviewed/2025/02/GHSA-hjwv-258c-v5pc/GHSA-hjwv-258c-v5pc.json b/advisories/unreviewed/2025/02/GHSA-hjwv-258c-v5pc/GHSA-hjwv-258c-v5pc.json index eccc5abab8a..8ca3766ab76 100644 --- a/advisories/unreviewed/2025/02/GHSA-hjwv-258c-v5pc/GHSA-hjwv-258c-v5pc.json +++ b/advisories/unreviewed/2025/02/GHSA-hjwv-258c-v5pc/GHSA-hjwv-258c-v5pc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json index 0548f1c667d..5bd3218a34d 100644 --- a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json +++ b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp9r-wcfh-72pr", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26595" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345257" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345257" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json b/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json index 42bf9c450a8..d437dc802dd 100644 --- a/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json +++ b/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf8f-3pq9-mrv7", - "modified": "2025-02-18T21:32:51Z", + "modified": "2025-05-13T21:30:27Z", "published": "2025-02-18T21:32:51Z", "aliases": [ "CVE-2024-45775" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45775" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45775" diff --git a/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json b/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json index 3c4e80a2eb6..f1d619bfbdf 100644 --- a/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json +++ b/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json b/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json index 184f8dbb10e..c069fc9a24c 100644 --- a/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json +++ b/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vjmw-pmxv-8c6w", - "modified": "2025-02-18T21:32:52Z", + "modified": "2025-05-13T21:30:28Z", "published": "2025-02-18T21:32:52Z", "aliases": [ "CVE-2025-0622" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0622" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:6990" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0622" diff --git a/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json b/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json index 13dbb2325e2..0778acd3c74 100644 --- a/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json +++ b/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json index 6b431a09434..3914da47aea 100644 --- a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json +++ b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv34-xcj8-f3mq", - "modified": "2025-05-13T15:32:10Z", + "modified": "2025-05-13T21:30:29Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26599" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2500" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2502" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2861" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2862" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2865" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2866" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2873" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2874" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2875" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2879" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:2880" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7163" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2025:7165" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345253" }, { "type": "WEB", @@ -77,7 +29,59 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345253" + "url": "https://access.redhat.com/errata/RHSA-2025:7458" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7165" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7163" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2874" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2865" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2862" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2502" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2500" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-786r-6wgw-4g8f/GHSA-786r-6wgw-4g8f.json b/advisories/unreviewed/2025/03/GHSA-786r-6wgw-4g8f/GHSA-786r-6wgw-4g8f.json index da8a61525a9..72261ddc515 100644 --- a/advisories/unreviewed/2025/03/GHSA-786r-6wgw-4g8f/GHSA-786r-6wgw-4g8f.json +++ b/advisories/unreviewed/2025/03/GHSA-786r-6wgw-4g8f/GHSA-786r-6wgw-4g8f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-c3jh-vcp9-f2mx/GHSA-c3jh-vcp9-f2mx.json b/advisories/unreviewed/2025/03/GHSA-c3jh-vcp9-f2mx/GHSA-c3jh-vcp9-f2mx.json index 49aae1630e7..9abbe16c092 100644 --- a/advisories/unreviewed/2025/03/GHSA-c3jh-vcp9-f2mx/GHSA-c3jh-vcp9-f2mx.json +++ b/advisories/unreviewed/2025/03/GHSA-c3jh-vcp9-f2mx/GHSA-c3jh-vcp9-f2mx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-g4fg-5mvh-6qmq/GHSA-g4fg-5mvh-6qmq.json b/advisories/unreviewed/2025/03/GHSA-g4fg-5mvh-6qmq/GHSA-g4fg-5mvh-6qmq.json index 5ca558e2c38..08dcaba4055 100644 --- a/advisories/unreviewed/2025/03/GHSA-g4fg-5mvh-6qmq/GHSA-g4fg-5mvh-6qmq.json +++ b/advisories/unreviewed/2025/03/GHSA-g4fg-5mvh-6qmq/GHSA-g4fg-5mvh-6qmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-h4x2-jm7q-pxc7/GHSA-h4x2-jm7q-pxc7.json b/advisories/unreviewed/2025/03/GHSA-h4x2-jm7q-pxc7/GHSA-h4x2-jm7q-pxc7.json index bdbdfb966cb..f80c659b317 100644 --- a/advisories/unreviewed/2025/03/GHSA-h4x2-jm7q-pxc7/GHSA-h4x2-jm7q-pxc7.json +++ b/advisories/unreviewed/2025/03/GHSA-h4x2-jm7q-pxc7/GHSA-h4x2-jm7q-pxc7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json b/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json index f56189034d8..e2698987a83 100644 --- a/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json +++ b/advisories/unreviewed/2025/03/GHSA-hhgh-4vpc-8c58/GHSA-hhgh-4vpc-8c58.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-548" + "CWE-548", + "CWE-552" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-pm5x-24p9-5g68/GHSA-pm5x-24p9-5g68.json b/advisories/unreviewed/2025/03/GHSA-pm5x-24p9-5g68/GHSA-pm5x-24p9-5g68.json index 8b30b15fae0..a144b6a2cf0 100644 --- a/advisories/unreviewed/2025/03/GHSA-pm5x-24p9-5g68/GHSA-pm5x-24p9-5g68.json +++ b/advisories/unreviewed/2025/03/GHSA-pm5x-24p9-5g68/GHSA-pm5x-24p9-5g68.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-rhx8-3xr8-54x3/GHSA-rhx8-3xr8-54x3.json b/advisories/unreviewed/2025/03/GHSA-rhx8-3xr8-54x3/GHSA-rhx8-3xr8-54x3.json index cbdf36a797e..1af793c3d5e 100644 --- a/advisories/unreviewed/2025/03/GHSA-rhx8-3xr8-54x3/GHSA-rhx8-3xr8-54x3.json +++ b/advisories/unreviewed/2025/03/GHSA-rhx8-3xr8-54x3/GHSA-rhx8-3xr8-54x3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wjh6-8rr9-qvq6/GHSA-wjh6-8rr9-qvq6.json b/advisories/unreviewed/2025/03/GHSA-wjh6-8rr9-qvq6/GHSA-wjh6-8rr9-qvq6.json index 620251b15c3..b8aada01419 100644 --- a/advisories/unreviewed/2025/03/GHSA-wjh6-8rr9-qvq6/GHSA-wjh6-8rr9-qvq6.json +++ b/advisories/unreviewed/2025/03/GHSA-wjh6-8rr9-qvq6/GHSA-wjh6-8rr9-qvq6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json index 18b97aaf5af..6c620747d95 100644 --- a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json +++ b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54qp-w9cp-g8g3", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32053" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32053" diff --git a/advisories/unreviewed/2025/04/GHSA-77gw-gg73-wpfg/GHSA-77gw-gg73-wpfg.json b/advisories/unreviewed/2025/04/GHSA-77gw-gg73-wpfg/GHSA-77gw-gg73-wpfg.json index 775c78da51d..27eda949d33 100644 --- a/advisories/unreviewed/2025/04/GHSA-77gw-gg73-wpfg/GHSA-77gw-gg73-wpfg.json +++ b/advisories/unreviewed/2025/04/GHSA-77gw-gg73-wpfg/GHSA-77gw-gg73-wpfg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json b/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json index 0355c364ed0..9f252d00b91 100644 --- a/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json +++ b/advisories/unreviewed/2025/04/GHSA-7hqq-7crg-xr49/GHSA-7hqq-7crg-xr49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hqq-7crg-xr49", - "modified": "2025-04-14T15:31:58Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32908" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32908" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32908" diff --git a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json index 3cebe4702a7..305ae61fe0e 100644 --- a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json +++ b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wfq-7p2f-6344", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32907" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4508" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32907" diff --git a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json index 4679189b74f..d90187b5008 100644 --- a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json +++ b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99xf-gcww-2c64", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32050" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32050" diff --git a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json index 3d9b4a5841c..a024812443c 100644 --- a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json +++ b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qwg-ch53-9rxw", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32052" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32052" diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json index a1a65014c26..77324dc180e 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json +++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-qjpg-x8wq", - "modified": "2025-05-13T15:32:11Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32906" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32906" diff --git a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json index ad535c3d350..6fa911d3854 100644 --- a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json +++ b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr7v-prvv-52v8", - "modified": "2025-05-07T09:31:17Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46421" @@ -51,6 +51,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46421" diff --git a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json index 59bcb51fb42..037d6b1cc42 100644 --- a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json +++ b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv37-78jj-hvqv", - "modified": "2025-05-07T09:31:17Z", + "modified": "2025-05-13T21:30:31Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46420" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4624" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7436" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46420" diff --git a/advisories/unreviewed/2025/04/GHSA-q66q-qwxm-vgrg/GHSA-q66q-qwxm-vgrg.json b/advisories/unreviewed/2025/04/GHSA-q66q-qwxm-vgrg/GHSA-q66q-qwxm-vgrg.json index bf5ce0d1c89..66cf162c05f 100644 --- a/advisories/unreviewed/2025/04/GHSA-q66q-qwxm-vgrg/GHSA-q66q-qwxm-vgrg.json +++ b/advisories/unreviewed/2025/04/GHSA-q66q-qwxm-vgrg/GHSA-q66q-qwxm-vgrg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2352-3wgr-hhm6/GHSA-2352-3wgr-hhm6.json b/advisories/unreviewed/2025/05/GHSA-2352-3wgr-hhm6/GHSA-2352-3wgr-hhm6.json new file mode 100644 index 00000000000..69adf5bcd1d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2352-3wgr-hhm6/GHSA-2352-3wgr-hhm6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2352-3wgr-hhm6", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20031" + ], + "details": "Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20031" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-299w-8x68-px6h/GHSA-299w-8x68-px6h.json b/advisories/unreviewed/2025/05/GHSA-299w-8x68-px6h/GHSA-299w-8x68-px6h.json new file mode 100644 index 00000000000..7672b596e37 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-299w-8x68-px6h/GHSA-299w-8x68-px6h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-299w-8x68-px6h", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20039" + ], + "details": "Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20039" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2c88-8r97-2vcx/GHSA-2c88-8r97-2vcx.json b/advisories/unreviewed/2025/05/GHSA-2c88-8r97-2vcx/GHSA-2c88-8r97-2vcx.json new file mode 100644 index 00000000000..ac3da7935d3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2c88-8r97-2vcx/GHSA-2c88-8r97-2vcx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c88-8r97-2vcx", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43551" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43551" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2g45-3h8m-p4q4/GHSA-2g45-3h8m-p4q4.json b/advisories/unreviewed/2025/05/GHSA-2g45-3h8m-p4q4/GHSA-2g45-3h8m-p4q4.json index cccc17d512c..1a355ac7b69 100644 --- a/advisories/unreviewed/2025/05/GHSA-2g45-3h8m-p4q4/GHSA-2g45-3h8m-p4q4.json +++ b/advisories/unreviewed/2025/05/GHSA-2g45-3h8m-p4q4/GHSA-2g45-3h8m-p4q4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2h3w-wpc8-4ggf/GHSA-2h3w-wpc8-4ggf.json b/advisories/unreviewed/2025/05/GHSA-2h3w-wpc8-4ggf/GHSA-2h3w-wpc8-4ggf.json new file mode 100644 index 00000000000..9098fd17751 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2h3w-wpc8-4ggf/GHSA-2h3w-wpc8-4ggf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h3w-wpc8-4ggf", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-31073" + ], + "details": "Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31073" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01274.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2rmv-pmj6-727m/GHSA-2rmv-pmj6-727m.json b/advisories/unreviewed/2025/05/GHSA-2rmv-pmj6-727m/GHSA-2rmv-pmj6-727m.json new file mode 100644 index 00000000000..8e717f547e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2rmv-pmj6-727m/GHSA-2rmv-pmj6-727m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rmv-pmj6-727m", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20012" + ], + "details": "Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable information disclosure via physical access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20012" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-696" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json b/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json index c60c06df61f..779c8cae61e 100644 --- a/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json +++ b/advisories/unreviewed/2025/05/GHSA-2xqw-mg48-p4j5/GHSA-2xqw-mg48-p4j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xqw-mg48-p4j5", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31232" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json b/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json index 852b8753671..b29d0a16e05 100644 --- a/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json +++ b/advisories/unreviewed/2025/05/GHSA-33xq-rr72-hjfj/GHSA-33xq-rr72-hjfj.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-35fx-99jc-mf6j/GHSA-35fx-99jc-mf6j.json b/advisories/unreviewed/2025/05/GHSA-35fx-99jc-mf6j/GHSA-35fx-99jc-mf6j.json index c51fed3405a..6c7859bba3b 100644 --- a/advisories/unreviewed/2025/05/GHSA-35fx-99jc-mf6j/GHSA-35fx-99jc-mf6j.json +++ b/advisories/unreviewed/2025/05/GHSA-35fx-99jc-mf6j/GHSA-35fx-99jc-mf6j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-36hv-3xjg-vwph/GHSA-36hv-3xjg-vwph.json b/advisories/unreviewed/2025/05/GHSA-36hv-3xjg-vwph/GHSA-36hv-3xjg-vwph.json index a3c849ed98c..9c4a319f18f 100644 --- a/advisories/unreviewed/2025/05/GHSA-36hv-3xjg-vwph/GHSA-36hv-3xjg-vwph.json +++ b/advisories/unreviewed/2025/05/GHSA-36hv-3xjg-vwph/GHSA-36hv-3xjg-vwph.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-374v-mj9j-3hr8/GHSA-374v-mj9j-3hr8.json b/advisories/unreviewed/2025/05/GHSA-374v-mj9j-3hr8/GHSA-374v-mj9j-3hr8.json new file mode 100644 index 00000000000..af6a2784f89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-374v-mj9j-3hr8/GHSA-374v-mj9j-3hr8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-374v-mj9j-3hr8", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20084" + ], + "details": "Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20084" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hvr-6xxw-86vv/GHSA-3hvr-6xxw-86vv.json b/advisories/unreviewed/2025/05/GHSA-3hvr-6xxw-86vv/GHSA-3hvr-6xxw-86vv.json new file mode 100644 index 00000000000..7a74bf631b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hvr-6xxw-86vv/GHSA-3hvr-6xxw-86vv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hvr-6xxw-86vv", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2024-48869" + ], + "details": "Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48869" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01268.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json b/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json index 42965cacfeb..a82eab53974 100644 --- a/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json +++ b/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3r9g-279m-hx9j/GHSA-3r9g-279m-hx9j.json b/advisories/unreviewed/2025/05/GHSA-3r9g-279m-hx9j/GHSA-3r9g-279m-hx9j.json new file mode 100644 index 00000000000..996bfe94241 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3r9g-279m-hx9j/GHSA-3r9g-279m-hx9j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r9g-279m-hx9j", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20009" + ], + "details": "Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20009" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43ff-74cr-2r98/GHSA-43ff-74cr-2r98.json b/advisories/unreviewed/2025/05/GHSA-43ff-74cr-2r98/GHSA-43ff-74cr-2r98.json new file mode 100644 index 00000000000..ac794a83be6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43ff-74cr-2r98/GHSA-43ff-74cr-2r98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43ff-74cr-2r98", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43568" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43568" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-44r5-8x6q-27jq/GHSA-44r5-8x6q-27jq.json b/advisories/unreviewed/2025/05/GHSA-44r5-8x6q-27jq/GHSA-44r5-8x6q-27jq.json index d420a0be520..bdc5a25fec8 100644 --- a/advisories/unreviewed/2025/05/GHSA-44r5-8x6q-27jq/GHSA-44r5-8x6q-27jq.json +++ b/advisories/unreviewed/2025/05/GHSA-44r5-8x6q-27jq/GHSA-44r5-8x6q-27jq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json b/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json index a9982077d7a..926cf4e1c4c 100644 --- a/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json +++ b/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-606" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-4f7p-jr5x-cg78/GHSA-4f7p-jr5x-cg78.json b/advisories/unreviewed/2025/05/GHSA-4f7p-jr5x-cg78/GHSA-4f7p-jr5x-cg78.json new file mode 100644 index 00000000000..e8aef3d9d6e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4f7p-jr5x-cg78/GHSA-4f7p-jr5x-cg78.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f7p-jr5x-cg78", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20083" + ], + "details": "Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20083" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01290.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4mx4-f8wv-q9f5/GHSA-4mx4-f8wv-q9f5.json b/advisories/unreviewed/2025/05/GHSA-4mx4-f8wv-q9f5/GHSA-4mx4-f8wv-q9f5.json new file mode 100644 index 00000000000..a57f030f7e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4mx4-f8wv-q9f5/GHSA-4mx4-f8wv-q9f5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mx4-f8wv-q9f5", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20008" + ], + "details": "Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20008" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01297.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4r6r-mmgf-vrgj/GHSA-4r6r-mmgf-vrgj.json b/advisories/unreviewed/2025/05/GHSA-4r6r-mmgf-vrgj/GHSA-4r6r-mmgf-vrgj.json new file mode 100644 index 00000000000..8b401dfb064 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4r6r-mmgf-vrgj/GHSA-4r6r-mmgf-vrgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r6r-mmgf-vrgj", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43560" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43560" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4rpv-g3qv-3mfr/GHSA-4rpv-g3qv-3mfr.json b/advisories/unreviewed/2025/05/GHSA-4rpv-g3qv-3mfr/GHSA-4rpv-g3qv-3mfr.json index 5139dfe9ff5..336a60dff67 100644 --- a/advisories/unreviewed/2025/05/GHSA-4rpv-g3qv-3mfr/GHSA-4rpv-g3qv-3mfr.json +++ b/advisories/unreviewed/2025/05/GHSA-4rpv-g3qv-3mfr/GHSA-4rpv-g3qv-3mfr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4vhh-62fm-h9p4/GHSA-4vhh-62fm-h9p4.json b/advisories/unreviewed/2025/05/GHSA-4vhh-62fm-h9p4/GHSA-4vhh-62fm-h9p4.json new file mode 100644 index 00000000000..d7c5e2271cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4vhh-62fm-h9p4/GHSA-4vhh-62fm-h9p4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhh-62fm-h9p4", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20026" + ], + "details": "Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20026" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json b/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json index 87637d3074a..d198580d5f7 100644 --- a/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json +++ b/advisories/unreviewed/2025/05/GHSA-4x3p-5fw4-h8vm/GHSA-4x3p-5fw4-h8vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4x3p-5fw4-h8vm", - "modified": "2025-05-05T18:32:54Z", + "modified": "2025-05-13T21:30:32Z", "published": "2025-05-05T18:32:54Z", "aliases": [ "CVE-2025-45239" ], "details": "An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T18:15:43Z" diff --git a/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json b/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json index 290ea38b8ae..0997303f4d1 100644 --- a/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json +++ b/advisories/unreviewed/2025/05/GHSA-53qx-2hww-8c99/GHSA-53qx-2hww-8c99.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53qx-2hww-8c99", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31240" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-54j5-rh7x-fmm4/GHSA-54j5-rh7x-fmm4.json b/advisories/unreviewed/2025/05/GHSA-54j5-rh7x-fmm4/GHSA-54j5-rh7x-fmm4.json new file mode 100644 index 00000000000..f5d6cd7060c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-54j5-rh7x-fmm4/GHSA-54j5-rh7x-fmm4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54j5-rh7x-fmm4", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-29222" + ], + "details": "Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29222" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json b/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json new file mode 100644 index 00000000000..263127ba55b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5cw9-h2jj-8927/GHSA-5cw9-h2jj-8927.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cw9-h2jj-8927", + "modified": "2025-05-13T21:30:53Z", + "published": "2025-05-13T21:30:53Z", + "aliases": [ + "CVE-2025-45863" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45863" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/5/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fv4-pxmr-xgp8/GHSA-5fv4-pxmr-xgp8.json b/advisories/unreviewed/2025/05/GHSA-5fv4-pxmr-xgp8/GHSA-5fv4-pxmr-xgp8.json new file mode 100644 index 00000000000..76bf7f46134 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fv4-pxmr-xgp8/GHSA-5fv4-pxmr-xgp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fv4-pxmr-xgp8", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43566" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43566" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5qwv-r493-496q/GHSA-5qwv-r493-496q.json b/advisories/unreviewed/2025/05/GHSA-5qwv-r493-496q/GHSA-5qwv-r493-496q.json new file mode 100644 index 00000000000..3f131271ef1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5qwv-r493-496q/GHSA-5qwv-r493-496q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qwv-r493-496q", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20103" + ], + "details": "Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20103" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-410" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-647j-x872-mcw4/GHSA-647j-x872-mcw4.json b/advisories/unreviewed/2025/05/GHSA-647j-x872-mcw4/GHSA-647j-x872-mcw4.json index 42f7cefdb6b..cd5adc908eb 100644 --- a/advisories/unreviewed/2025/05/GHSA-647j-x872-mcw4/GHSA-647j-x872-mcw4.json +++ b/advisories/unreviewed/2025/05/GHSA-647j-x872-mcw4/GHSA-647j-x872-mcw4.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-647j-x872-mcw4", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:34Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40620" ], "details": "SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndWS’ endpoint.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-6gp3-r6r7-wq4f/GHSA-6gp3-r6r7-wq4f.json b/advisories/unreviewed/2025/05/GHSA-6gp3-r6r7-wq4f/GHSA-6gp3-r6r7-wq4f.json new file mode 100644 index 00000000000..f22940016c6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6gp3-r6r7-wq4f/GHSA-6gp3-r6r7-wq4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gp3-r6r7-wq4f", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-43420" + ], + "details": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43420" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json b/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json index f74837a790b..fc9ac1c1869 100644 --- a/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json +++ b/advisories/unreviewed/2025/05/GHSA-6mhh-cg8v-6pjf/GHSA-6mhh-cg8v-6pjf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6mhh-cg8v-6pjf", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31225" ], "details": "A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6q96-22w8-mpwh/GHSA-6q96-22w8-mpwh.json b/advisories/unreviewed/2025/05/GHSA-6q96-22w8-mpwh/GHSA-6q96-22w8-mpwh.json new file mode 100644 index 00000000000..7cfaaeffd7e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6q96-22w8-mpwh/GHSA-6q96-22w8-mpwh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q96-22w8-mpwh", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20062" + ], + "details": "Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20062" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6vp7-fq4f-hq53/GHSA-6vp7-fq4f-hq53.json b/advisories/unreviewed/2025/05/GHSA-6vp7-fq4f-hq53/GHSA-6vp7-fq4f-hq53.json new file mode 100644 index 00000000000..4e8994eddea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6vp7-fq4f-hq53/GHSA-6vp7-fq4f-hq53.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vp7-fq4f-hq53", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-39758" + ], + "details": "Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39758" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-729f-rxmp-m7p8/GHSA-729f-rxmp-m7p8.json b/advisories/unreviewed/2025/05/GHSA-729f-rxmp-m7p8/GHSA-729f-rxmp-m7p8.json new file mode 100644 index 00000000000..f2bb433792e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-729f-rxmp-m7p8/GHSA-729f-rxmp-m7p8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-729f-rxmp-m7p8", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20079" + ], + "details": "Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20079" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01263.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75pf-6v46-5v63/GHSA-75pf-6v46-5v63.json b/advisories/unreviewed/2025/05/GHSA-75pf-6v46-5v63/GHSA-75pf-6v46-5v63.json new file mode 100644 index 00000000000..b05fc8c4ded --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-75pf-6v46-5v63/GHSA-75pf-6v46-5v63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75pf-6v46-5v63", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43570" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43570" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-76fj-53vf-7c56/GHSA-76fj-53vf-7c56.json b/advisories/unreviewed/2025/05/GHSA-76fj-53vf-7c56/GHSA-76fj-53vf-7c56.json index 6ce0b5024f2..60aed23e406 100644 --- a/advisories/unreviewed/2025/05/GHSA-76fj-53vf-7c56/GHSA-76fj-53vf-7c56.json +++ b/advisories/unreviewed/2025/05/GHSA-76fj-53vf-7c56/GHSA-76fj-53vf-7c56.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7859-xr5m-mmp7/GHSA-7859-xr5m-mmp7.json b/advisories/unreviewed/2025/05/GHSA-7859-xr5m-mmp7/GHSA-7859-xr5m-mmp7.json new file mode 100644 index 00000000000..e3c8461baaa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7859-xr5m-mmp7/GHSA-7859-xr5m-mmp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7859-xr5m-mmp7", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-30316" + ], + "details": "Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30316" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/connect/apsb25-36.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-79v3-vqfh-hqq6/GHSA-79v3-vqfh-hqq6.json b/advisories/unreviewed/2025/05/GHSA-79v3-vqfh-hqq6/GHSA-79v3-vqfh-hqq6.json new file mode 100644 index 00000000000..851f52c054c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-79v3-vqfh-hqq6/GHSA-79v3-vqfh-hqq6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79v3-vqfh-hqq6", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20076" + ], + "details": "Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20076" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7gwv-cxww-6ggg/GHSA-7gwv-cxww-6ggg.json b/advisories/unreviewed/2025/05/GHSA-7gwv-cxww-6ggg/GHSA-7gwv-cxww-6ggg.json new file mode 100644 index 00000000000..0717618f10a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7gwv-cxww-6ggg/GHSA-7gwv-cxww-6ggg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gwv-cxww-6ggg", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20047" + ], + "details": "Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20047" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01180.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7ppp-wv3j-gg8q/GHSA-7ppp-wv3j-gg8q.json b/advisories/unreviewed/2025/05/GHSA-7ppp-wv3j-gg8q/GHSA-7ppp-wv3j-gg8q.json new file mode 100644 index 00000000000..a9127a12c68 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7ppp-wv3j-gg8q/GHSA-7ppp-wv3j-gg8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ppp-wv3j-gg8q", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-24495" + ], + "details": "Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24495" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7qjw-phgv-8j23/GHSA-7qjw-phgv-8j23.json b/advisories/unreviewed/2025/05/GHSA-7qjw-phgv-8j23/GHSA-7qjw-phgv-8j23.json new file mode 100644 index 00000000000..1685f54c434 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7qjw-phgv-8j23/GHSA-7qjw-phgv-8j23.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qjw-phgv-8j23", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-31150" + ], + "details": "Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31150" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json b/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json index 018d1b78e58..42e73f083a3 100644 --- a/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json +++ b/advisories/unreviewed/2025/05/GHSA-7x75-24xr-g7wf/GHSA-7x75-24xr-g7wf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x75-24xr-g7wf", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31236" ], "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-838x-prqr-qg3c/GHSA-838x-prqr-qg3c.json b/advisories/unreviewed/2025/05/GHSA-838x-prqr-qg3c/GHSA-838x-prqr-qg3c.json new file mode 100644 index 00000000000..486497c5498 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-838x-prqr-qg3c/GHSA-838x-prqr-qg3c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-838x-prqr-qg3c", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20629" + ], + "details": "Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20629" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01295.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-83gr-8r63-wvr9/GHSA-83gr-8r63-wvr9.json b/advisories/unreviewed/2025/05/GHSA-83gr-8r63-wvr9/GHSA-83gr-8r63-wvr9.json new file mode 100644 index 00000000000..9ccf3146e7d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-83gr-8r63-wvr9/GHSA-83gr-8r63-wvr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83gr-8r63-wvr9", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43567" + ], + "details": "Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43567" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/connect/apsb25-36.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8564-pmx5-55h5/GHSA-8564-pmx5-55h5.json b/advisories/unreviewed/2025/05/GHSA-8564-pmx5-55h5/GHSA-8564-pmx5-55h5.json new file mode 100644 index 00000000000..26d46178afd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8564-pmx5-55h5/GHSA-8564-pmx5-55h5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8564-pmx5-55h5", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20003" + ], + "details": "Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20003" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-869c-35xf-w582/GHSA-869c-35xf-w582.json b/advisories/unreviewed/2025/05/GHSA-869c-35xf-w582/GHSA-869c-35xf-w582.json index 595cc522e57..d5b9e0bb59b 100644 --- a/advisories/unreviewed/2025/05/GHSA-869c-35xf-w582/GHSA-869c-35xf-w582.json +++ b/advisories/unreviewed/2025/05/GHSA-869c-35xf-w582/GHSA-869c-35xf-w582.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-869c-35xf-w582", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:35Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40622" ], "details": "SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘username’ parameter of the ‘GetLastDatePasswordChange’ endpoint.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json index cad4e173284..17de2880383 100644 --- a/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json +++ b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86pc-jx85-mvrw", - "modified": "2025-05-13T18:30:59Z", + "modified": "2025-05-13T21:30:53Z", "published": "2025-05-13T18:30:58Z", "aliases": [ "CVE-2025-4660" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4660" }, + { + "type": "WEB", + "url": "https://forescout.my.site.com/support/s/article" + }, { "type": "WEB", "url": "https://forescout.my.site.com/support/s/article/High-Severity-Vulnerability-in-Secure-Connector-HPS-Inspection-Engine-v11-3-5-and-lower" diff --git a/advisories/unreviewed/2025/05/GHSA-8869-j2q7-jf8g/GHSA-8869-j2q7-jf8g.json b/advisories/unreviewed/2025/05/GHSA-8869-j2q7-jf8g/GHSA-8869-j2q7-jf8g.json new file mode 100644 index 00000000000..a70786c0b43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8869-j2q7-jf8g/GHSA-8869-j2q7-jf8g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8869-j2q7-jf8g", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-28036" + ], + "details": "Improper conditions check for some Intel(R) Arc™ GPU may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28036" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01252.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json b/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json index 639b2168616..5c21defe4ba 100644 --- a/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json +++ b/advisories/unreviewed/2025/05/GHSA-89f5-mmjh-cmgw/GHSA-89f5-mmjh-cmgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89f5-mmjh-cmgw", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31233" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8c6j-hg38-f5mx/GHSA-8c6j-hg38-f5mx.json b/advisories/unreviewed/2025/05/GHSA-8c6j-hg38-f5mx/GHSA-8c6j-hg38-f5mx.json index 1e9c3fad29c..7a645a49691 100644 --- a/advisories/unreviewed/2025/05/GHSA-8c6j-hg38-f5mx/GHSA-8c6j-hg38-f5mx.json +++ b/advisories/unreviewed/2025/05/GHSA-8c6j-hg38-f5mx/GHSA-8c6j-hg38-f5mx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8cvf-82rq-8qmg/GHSA-8cvf-82rq-8qmg.json b/advisories/unreviewed/2025/05/GHSA-8cvf-82rq-8qmg/GHSA-8cvf-82rq-8qmg.json new file mode 100644 index 00000000000..7d0bf454a83 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8cvf-82rq-8qmg/GHSA-8cvf-82rq-8qmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cvf-82rq-8qmg", + "modified": "2025-05-13T21:30:58Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43572" + ], + "details": "Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43572" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb25-45.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8g27-9xgm-rp9m/GHSA-8g27-9xgm-rp9m.json b/advisories/unreviewed/2025/05/GHSA-8g27-9xgm-rp9m/GHSA-8g27-9xgm-rp9m.json new file mode 100644 index 00000000000..7f0a60c9072 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8g27-9xgm-rp9m/GHSA-8g27-9xgm-rp9m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g27-9xgm-rp9m", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20095" + ], + "details": "Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20095" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01305.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8gjg-q649-xp4c/GHSA-8gjg-q649-xp4c.json b/advisories/unreviewed/2025/05/GHSA-8gjg-q649-xp4c/GHSA-8gjg-q649-xp4c.json index ee28345c124..5e79413bd14 100644 --- a/advisories/unreviewed/2025/05/GHSA-8gjg-q649-xp4c/GHSA-8gjg-q649-xp4c.json +++ b/advisories/unreviewed/2025/05/GHSA-8gjg-q649-xp4c/GHSA-8gjg-q649-xp4c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8gqc-p546-5pp6/GHSA-8gqc-p546-5pp6.json b/advisories/unreviewed/2025/05/GHSA-8gqc-p546-5pp6/GHSA-8gqc-p546-5pp6.json new file mode 100644 index 00000000000..488effaaa34 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8gqc-p546-5pp6/GHSA-8gqc-p546-5pp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gqc-p546-5pp6", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43554" + ], + "details": "Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43554" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-51.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p3f-99h8-4v6p/GHSA-8p3f-99h8-4v6p.json b/advisories/unreviewed/2025/05/GHSA-8p3f-99h8-4v6p/GHSA-8p3f-99h8-4v6p.json new file mode 100644 index 00000000000..7876bdb5241 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8p3f-99h8-4v6p/GHSA-8p3f-99h8-4v6p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p3f-99h8-4v6p", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20108" + ], + "details": "Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20108" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01293.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p6x-2w5r-wvv8/GHSA-8p6x-2w5r-wvv8.json b/advisories/unreviewed/2025/05/GHSA-8p6x-2w5r-wvv8/GHSA-8p6x-2w5r-wvv8.json index 3d086e4fedf..e07e84ea4ee 100644 --- a/advisories/unreviewed/2025/05/GHSA-8p6x-2w5r-wvv8/GHSA-8p6x-2w5r-wvv8.json +++ b/advisories/unreviewed/2025/05/GHSA-8p6x-2w5r-wvv8/GHSA-8p6x-2w5r-wvv8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json b/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json index e1901af523f..39ea7bd1a7e 100644 --- a/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json +++ b/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-8w3c-m76m-rh2h/GHSA-8w3c-m76m-rh2h.json b/advisories/unreviewed/2025/05/GHSA-8w3c-m76m-rh2h/GHSA-8w3c-m76m-rh2h.json index d4fa59d6a34..f2227cf5561 100644 --- a/advisories/unreviewed/2025/05/GHSA-8w3c-m76m-rh2h/GHSA-8w3c-m76m-rh2h.json +++ b/advisories/unreviewed/2025/05/GHSA-8w3c-m76m-rh2h/GHSA-8w3c-m76m-rh2h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w3c-m76m-rh2h", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:34Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40621" ], "details": "SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndGetData’ endpoint.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-923f-wx2q-466m/GHSA-923f-wx2q-466m.json b/advisories/unreviewed/2025/05/GHSA-923f-wx2q-466m/GHSA-923f-wx2q-466m.json new file mode 100644 index 00000000000..6cc95a77c2c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-923f-wx2q-466m/GHSA-923f-wx2q-466m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-923f-wx2q-466m", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20612" + ], + "details": "Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20612" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-279" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-92gx-2j9v-qqpq/GHSA-92gx-2j9v-qqpq.json b/advisories/unreviewed/2025/05/GHSA-92gx-2j9v-qqpq/GHSA-92gx-2j9v-qqpq.json new file mode 100644 index 00000000000..62e294085f9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-92gx-2j9v-qqpq/GHSA-92gx-2j9v-qqpq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92gx-2j9v-qqpq", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20071" + ], + "details": "NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20071" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json b/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json index 052920b2855..15f5c2e006b 100644 --- a/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json +++ b/advisories/unreviewed/2025/05/GHSA-92r8-8gff-fhp3/GHSA-92r8-8gff-fhp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92r8-8gff-fhp3", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:42Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31208" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json b/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json index 52cfeb06de1..8caf846b00c 100644 --- a/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json +++ b/advisories/unreviewed/2025/05/GHSA-92vp-xx8f-fhpw/GHSA-92vp-xx8f-fhpw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92vp-xx8f-fhpw", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31210" ], "details": "The issue was addressed with improved UI. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. Processing web content may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9cgr-4gfv-w8p7/GHSA-9cgr-4gfv-w8p7.json b/advisories/unreviewed/2025/05/GHSA-9cgr-4gfv-w8p7/GHSA-9cgr-4gfv-w8p7.json new file mode 100644 index 00000000000..8fcfa3f81cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9cgr-4gfv-w8p7/GHSA-9cgr-4gfv-w8p7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cgr-4gfv-w8p7", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-21081" + ], + "details": "Protection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21081" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9fjw-43mf-j5mq/GHSA-9fjw-43mf-j5mq.json b/advisories/unreviewed/2025/05/GHSA-9fjw-43mf-j5mq/GHSA-9fjw-43mf-j5mq.json new file mode 100644 index 00000000000..701c1043dc8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9fjw-43mf-j5mq/GHSA-9fjw-43mf-j5mq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fjw-43mf-j5mq", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20034" + ], + "details": "Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before version R01.02.0003 may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20034" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9hjr-wq6c-38g6/GHSA-9hjr-wq6c-38g6.json b/advisories/unreviewed/2025/05/GHSA-9hjr-wq6c-38g6/GHSA-9hjr-wq6c-38g6.json new file mode 100644 index 00000000000..dfad45034ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9hjr-wq6c-38g6/GHSA-9hjr-wq6c-38g6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hjr-wq6c-38g6", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20041" + ], + "details": "Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20041" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9p2x-2mx9-hp39/GHSA-9p2x-2mx9-hp39.json b/advisories/unreviewed/2025/05/GHSA-9p2x-2mx9-hp39/GHSA-9p2x-2mx9-hp39.json new file mode 100644 index 00000000000..cbe71ca2ec1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9p2x-2mx9-hp39/GHSA-9p2x-2mx9-hp39.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p2x-2mx9-hp39", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20043" + ], + "details": "Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20043" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01305.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9pvp-xr4h-8mvr/GHSA-9pvp-xr4h-8mvr.json b/advisories/unreviewed/2025/05/GHSA-9pvp-xr4h-8mvr/GHSA-9pvp-xr4h-8mvr.json new file mode 100644 index 00000000000..df329f6cc52 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9pvp-xr4h-8mvr/GHSA-9pvp-xr4h-8mvr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pvp-xr4h-8mvr", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20013" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20013" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json b/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json index e1d8ef80521..b37c9642092 100644 --- a/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json +++ b/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-9rqc-8g4r-hvhh/GHSA-9rqc-8g4r-hvhh.json b/advisories/unreviewed/2025/05/GHSA-9rqc-8g4r-hvhh/GHSA-9rqc-8g4r-hvhh.json new file mode 100644 index 00000000000..33c85936c08 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9rqc-8g4r-hvhh/GHSA-9rqc-8g4r-hvhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rqc-8g4r-hvhh", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43562" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43562" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json index 0a62be16cdc..26768c7021e 100644 --- a/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json +++ b/advisories/unreviewed/2025/05/GHSA-9v48-2prj-rqc9/GHSA-9v48-2prj-rqc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9v48-2prj-rqc9", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31221" ], "details": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may be able to leak memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9vr5-w737-m66g/GHSA-9vr5-w737-m66g.json b/advisories/unreviewed/2025/05/GHSA-9vr5-w737-m66g/GHSA-9vr5-w737-m66g.json new file mode 100644 index 00000000000..4fb9de39ab7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vr5-w737-m66g/GHSA-9vr5-w737-m66g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vr5-w737-m66g", + "modified": "2025-05-13T21:30:53Z", + "published": "2025-05-13T21:30:53Z", + "aliases": [ + "CVE-2025-3744" + ], + "details": "Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3744" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2025-08-nomad-enterprise-vulnerable-to-violation-of-mandatory-sentinel-policies-in-job-submissions-via-policy-override/74935" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json b/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json index 9bb25bf0025..802d1c8cab1 100644 --- a/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json +++ b/advisories/unreviewed/2025/05/GHSA-9wc3-7frf-f65v/GHSA-9wc3-7frf-f65v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9wc3-7frf-f65v", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:41Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31204" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9x98-jv6r-7jg8/GHSA-9x98-jv6r-7jg8.json b/advisories/unreviewed/2025/05/GHSA-9x98-jv6r-7jg8/GHSA-9x98-jv6r-7jg8.json index 226bb1062c7..49f3399548c 100644 --- a/advisories/unreviewed/2025/05/GHSA-9x98-jv6r-7jg8/GHSA-9x98-jv6r-7jg8.json +++ b/advisories/unreviewed/2025/05/GHSA-9x98-jv6r-7jg8/GHSA-9x98-jv6r-7jg8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c4rj-rr8q-9ffj/GHSA-c4rj-rr8q-9ffj.json b/advisories/unreviewed/2025/05/GHSA-c4rj-rr8q-9ffj/GHSA-c4rj-rr8q-9ffj.json new file mode 100644 index 00000000000..24cce489acb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c4rj-rr8q-9ffj/GHSA-c4rj-rr8q-9ffj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4rj-rr8q-9ffj", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22895" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22895" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json b/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json index 48d31283075..e5065d204b6 100644 --- a/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json +++ b/advisories/unreviewed/2025/05/GHSA-c5qx-gcrc-9fpj/GHSA-c5qx-gcrc-9fpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c5qx-gcrc-9fpj", - "modified": "2025-05-13T18:30:53Z", + "modified": "2025-05-13T21:30:48Z", "published": "2025-05-13T18:30:53Z", "aliases": [ "CVE-2025-45858" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-13T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json b/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json index f5573c39584..e980ad3aeda 100644 --- a/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json +++ b/advisories/unreviewed/2025/05/GHSA-c629-xm2q-h69v/GHSA-c629-xm2q-h69v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c629-xm2q-h69v", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:41Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31196" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c8cj-99cw-rwf2/GHSA-c8cj-99cw-rwf2.json b/advisories/unreviewed/2025/05/GHSA-c8cj-99cw-rwf2/GHSA-c8cj-99cw-rwf2.json new file mode 100644 index 00000000000..9a996078f3d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8cj-99cw-rwf2/GHSA-c8cj-99cw-rwf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8cj-99cw-rwf2", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43553" + ], + "details": "Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application relies on a search path to locate critical resources such as libraries or executables, an attacker could manipulate the search path to load a malicious resource, potentially executing arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43553" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-51.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c97h-mp76-mj2r/GHSA-c97h-mp76-mj2r.json b/advisories/unreviewed/2025/05/GHSA-c97h-mp76-mj2r/GHSA-c97h-mp76-mj2r.json new file mode 100644 index 00000000000..6281a54463d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c97h-mp76-mj2r/GHSA-c97h-mp76-mj2r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c97h-mp76-mj2r", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20054" + ], + "details": "Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20054" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cc3p-ggrq-6h5p/GHSA-cc3p-ggrq-6h5p.json b/advisories/unreviewed/2025/05/GHSA-cc3p-ggrq-6h5p/GHSA-cc3p-ggrq-6h5p.json new file mode 100644 index 00000000000..85020c33e74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cc3p-ggrq-6h5p/GHSA-cc3p-ggrq-6h5p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc3p-ggrq-6h5p", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-21094" + ], + "details": "Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21094" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cg2j-4qw3-47q9/GHSA-cg2j-4qw3-47q9.json b/advisories/unreviewed/2025/05/GHSA-cg2j-4qw3-47q9/GHSA-cg2j-4qw3-47q9.json new file mode 100644 index 00000000000..90b4a1b3c8b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cg2j-4qw3-47q9/GHSA-cg2j-4qw3-47q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg2j-4qw3-47q9", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43563" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43563" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ch2q-qq4h-hc3c/GHSA-ch2q-qq4h-hc3c.json b/advisories/unreviewed/2025/05/GHSA-ch2q-qq4h-hc3c/GHSA-ch2q-qq4h-hc3c.json new file mode 100644 index 00000000000..f1bb819fa1d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ch2q-qq4h-hc3c/GHSA-ch2q-qq4h-hc3c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch2q-qq4h-hc3c", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2024-47795" + ], + "details": "Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47795" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01243.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cpqc-wrh6-wj8j/GHSA-cpqc-wrh6-wj8j.json b/advisories/unreviewed/2025/05/GHSA-cpqc-wrh6-wj8j/GHSA-cpqc-wrh6-wj8j.json new file mode 100644 index 00000000000..ef14dc517ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cpqc-wrh6-wj8j/GHSA-cpqc-wrh6-wj8j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpqc-wrh6-wj8j", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-39833" + ], + "details": "Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39833" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01216.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cv6m-v3m4-h4px/GHSA-cv6m-v3m4-h4px.json b/advisories/unreviewed/2025/05/GHSA-cv6m-v3m4-h4px/GHSA-cv6m-v3m4-h4px.json new file mode 100644 index 00000000000..430ecc665c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cv6m-v3m4-h4px/GHSA-cv6m-v3m4-h4px.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6m-v3m4-h4px", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22844" + ], + "details": "Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22844" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json b/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json new file mode 100644 index 00000000000..91c13cc59aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cxpp-jwcw-w84c/GHSA-cxpp-jwcw-w84c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxpp-jwcw-w84c", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:53Z", + "aliases": [ + "CVE-2025-45861" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45861" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/3/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json b/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json index d50e664fb83..f6a164daf84 100644 --- a/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json +++ b/advisories/unreviewed/2025/05/GHSA-f233-mjh6-2vxg/GHSA-f233-mjh6-2vxg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f233-mjh6-2vxg", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31237" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f2hp-3fmh-2255/GHSA-f2hp-3fmh-2255.json b/advisories/unreviewed/2025/05/GHSA-f2hp-3fmh-2255/GHSA-f2hp-3fmh-2255.json new file mode 100644 index 00000000000..b53b3a96c71 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f2hp-3fmh-2255/GHSA-f2hp-3fmh-2255.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2hp-3fmh-2255", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-30315" + ], + "details": "Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30315" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/connect/apsb25-36.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json index 7cbf28dc411..fbe01541e92 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json +++ b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w6-r722-5fr8", - "modified": "2025-05-13T18:30:48Z", + "modified": "2025-05-13T21:30:37Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-47203" @@ -39,6 +39,10 @@ "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/13/1" }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/10" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/13/3" diff --git a/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json b/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json index e27884b05c6..ab4adf80443 100644 --- a/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json +++ b/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json b/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json index 0d0e5f9f555..244b1666ded 100644 --- a/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json +++ b/advisories/unreviewed/2025/05/GHSA-fcrm-wvmg-6h7p/GHSA-fcrm-wvmg-6h7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fcrm-wvmg-6h7p", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31209" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to disclosure of user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fgw6-x5fj-v6j3/GHSA-fgw6-x5fj-v6j3.json b/advisories/unreviewed/2025/05/GHSA-fgw6-x5fj-v6j3/GHSA-fgw6-x5fj-v6j3.json new file mode 100644 index 00000000000..9f7580183c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fgw6-x5fj-v6j3/GHSA-fgw6-x5fj-v6j3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgw6-x5fj-v6j3", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20101" + ], + "details": "Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20101" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json b/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json index c56d33ee665..63b2eaa04af 100644 --- a/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json +++ b/advisories/unreviewed/2025/05/GHSA-fm6m-rfgf-h7gm/GHSA-fm6m-rfgf-h7gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fm6m-rfgf-h7gm", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31247" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An attacker may gain access to protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json b/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json index c6418ef512d..96db712f0ff 100644 --- a/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json +++ b/advisories/unreviewed/2025/05/GHSA-fp6q-7cxg-f24x/GHSA-fp6q-7cxg-f24x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fp6q-7cxg-f24x", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31217" ], "details": "The issue was addressed with improved input validation. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fv2p-m3fq-rq6h/GHSA-fv2p-m3fq-rq6h.json b/advisories/unreviewed/2025/05/GHSA-fv2p-m3fq-rq6h/GHSA-fv2p-m3fq-rq6h.json new file mode 100644 index 00000000000..00a49cda01c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fv2p-m3fq-rq6h/GHSA-fv2p-m3fq-rq6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2p-m3fq-rq6h", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20623" + ], + "details": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20623" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g3mw-9fh5-mrhx/GHSA-g3mw-9fh5-mrhx.json b/advisories/unreviewed/2025/05/GHSA-g3mw-9fh5-mrhx/GHSA-g3mw-9fh5-mrhx.json new file mode 100644 index 00000000000..89c0c3e2d8c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g3mw-9fh5-mrhx/GHSA-g3mw-9fh5-mrhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3mw-9fh5-mrhx", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43569" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43569" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g4xf-2jx5-c6mr/GHSA-g4xf-2jx5-c6mr.json b/advisories/unreviewed/2025/05/GHSA-g4xf-2jx5-c6mr/GHSA-g4xf-2jx5-c6mr.json new file mode 100644 index 00000000000..330be0757ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g4xf-2jx5-c6mr/GHSA-g4xf-2jx5-c6mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4xf-2jx5-c6mr", + "modified": "2025-05-13T21:30:58Z", + "published": "2025-05-13T21:30:58Z", + "aliases": [ + "CVE-2025-43571" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43571" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json b/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json index 2c864e23871..9aa5d899440 100644 --- a/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json +++ b/advisories/unreviewed/2025/05/GHSA-gc4x-2qcw-h9vv/GHSA-gc4x-2qcw-h9vv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gc4x-2qcw-h9vv", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-13T21:30:40Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24111" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.3, visionOS 2.3, iPadOS 17.7.7, watchOS 11.3, macOS Sonoma 14.7.5, iOS 18.3 and iPadOS 18.3, tvOS 18.3, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json b/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json index 2a692ecb494..1326d3b1a9e 100644 --- a/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json +++ b/advisories/unreviewed/2025/05/GHSA-gcw6-vg32-9cqw/GHSA-gcw6-vg32-9cqw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gcw6-vg32-9cqw", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31212" ], "details": "This issue was addressed through improved state management. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:22Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gj7c-8mv4-cp6p/GHSA-gj7c-8mv4-cp6p.json b/advisories/unreviewed/2025/05/GHSA-gj7c-8mv4-cp6p/GHSA-gj7c-8mv4-cp6p.json new file mode 100644 index 00000000000..b6367856148 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gj7c-8mv4-cp6p/GHSA-gj7c-8mv4-cp6p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj7c-8mv4-cp6p", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20082" + ], + "details": "Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20082" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp5v-jq85-98hg/GHSA-gp5v-jq85-98hg.json b/advisories/unreviewed/2025/05/GHSA-gp5v-jq85-98hg/GHSA-gp5v-jq85-98hg.json index 3d7fcc2edc2..80b61689e8f 100644 --- a/advisories/unreviewed/2025/05/GHSA-gp5v-jq85-98hg/GHSA-gp5v-jq85-98hg.json +++ b/advisories/unreviewed/2025/05/GHSA-gp5v-jq85-98hg/GHSA-gp5v-jq85-98hg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp5v-jq85-98hg", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:35Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40623" ], "details": "SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘Sender’ and “email” parameters of the ‘createNotificationAndroid’ endpoint.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-gx6w-379g-97r9/GHSA-gx6w-379g-97r9.json b/advisories/unreviewed/2025/05/GHSA-gx6w-379g-97r9/GHSA-gx6w-379g-97r9.json new file mode 100644 index 00000000000..e721d816afe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gx6w-379g-97r9/GHSA-gx6w-379g-97r9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx6w-379g-97r9", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20100" + ], + "details": "Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20100" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01278.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json b/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json index ecbd1ff7b31..85c4a3bd4a3 100644 --- a/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json +++ b/advisories/unreviewed/2025/05/GHSA-h5hr-h582-r8wp/GHSA-h5hr-h582-r8wp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h5hr-h582-r8wp", - "modified": "2025-05-13T00:31:14Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:14Z", "aliases": [ "CVE-2025-31228" ], "details": "The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:23Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h6pj-3jgp-mgr2/GHSA-h6pj-3jgp-mgr2.json b/advisories/unreviewed/2025/05/GHSA-h6pj-3jgp-mgr2/GHSA-h6pj-3jgp-mgr2.json new file mode 100644 index 00000000000..40d02523a94 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h6pj-3jgp-mgr2/GHSA-h6pj-3jgp-mgr2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6pj-3jgp-mgr2", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-47800" + ], + "details": "Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47800" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8ww-m8w3-8w9c/GHSA-h8ww-m8w3-8w9c.json b/advisories/unreviewed/2025/05/GHSA-h8ww-m8w3-8w9c/GHSA-h8ww-m8w3-8w9c.json new file mode 100644 index 00000000000..b4ed1831718 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8ww-m8w3-8w9c/GHSA-h8ww-m8w3-8w9c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8ww-m8w3-8w9c", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22892" + ], + "details": "Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22892" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01272.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hf4x-2pvm-qxvv/GHSA-hf4x-2pvm-qxvv.json b/advisories/unreviewed/2025/05/GHSA-hf4x-2pvm-qxvv/GHSA-hf4x-2pvm-qxvv.json new file mode 100644 index 00000000000..6b87419af04 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hf4x-2pvm-qxvv/GHSA-hf4x-2pvm-qxvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf4x-2pvm-qxvv", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43565" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43565" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hhw7-gww2-f8p5/GHSA-hhw7-gww2-f8p5.json b/advisories/unreviewed/2025/05/GHSA-hhw7-gww2-f8p5/GHSA-hhw7-gww2-f8p5.json new file mode 100644 index 00000000000..a9c012efde7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hhw7-gww2-f8p5/GHSA-hhw7-gww2-f8p5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhw7-gww2-f8p5", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-28954" + ], + "details": "Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28954" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hj5r-xh67-qwq9/GHSA-hj5r-xh67-qwq9.json b/advisories/unreviewed/2025/05/GHSA-hj5r-xh67-qwq9/GHSA-hj5r-xh67-qwq9.json index db2053e4d02..9d3d2ab8420 100644 --- a/advisories/unreviewed/2025/05/GHSA-hj5r-xh67-qwq9/GHSA-hj5r-xh67-qwq9.json +++ b/advisories/unreviewed/2025/05/GHSA-hj5r-xh67-qwq9/GHSA-hj5r-xh67-qwq9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hjg3-gh8v-mvc5/GHSA-hjg3-gh8v-mvc5.json b/advisories/unreviewed/2025/05/GHSA-hjg3-gh8v-mvc5/GHSA-hjg3-gh8v-mvc5.json new file mode 100644 index 00000000000..3733de5c098 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjg3-gh8v-mvc5/GHSA-hjg3-gh8v-mvc5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjg3-gh8v-mvc5", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20616" + ], + "details": "Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20616" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hmjm-5wqx-fp83/GHSA-hmjm-5wqx-fp83.json b/advisories/unreviewed/2025/05/GHSA-hmjm-5wqx-fp83/GHSA-hmjm-5wqx-fp83.json new file mode 100644 index 00000000000..7ad2b4796ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hmjm-5wqx-fp83/GHSA-hmjm-5wqx-fp83.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmjm-5wqx-fp83", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-21099" + ], + "details": "Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21099" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hq6h-wq38-v7h8/GHSA-hq6h-wq38-v7h8.json b/advisories/unreviewed/2025/05/GHSA-hq6h-wq38-v7h8/GHSA-hq6h-wq38-v7h8.json new file mode 100644 index 00000000000..5e6707bf812 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hq6h-wq38-v7h8/GHSA-hq6h-wq38-v7h8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq6h-wq38-v7h8", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20104" + ], + "details": "Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20104" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01293.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json b/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json new file mode 100644 index 00000000000..7cf1f309e9f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwrg-xmjh-93xc", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-28956" + ], + "details": "Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28956" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j67c-j5p2-79rx/GHSA-j67c-j5p2-79rx.json b/advisories/unreviewed/2025/05/GHSA-j67c-j5p2-79rx/GHSA-j67c-j5p2-79rx.json new file mode 100644 index 00000000000..3bd33f10ed3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j67c-j5p2-79rx/GHSA-j67c-j5p2-79rx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j67c-j5p2-79rx", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20022" + ], + "details": "Insufficient control flow management for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow a privileged user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20022" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-691" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgjg-2p7q-9r87/GHSA-jgjg-2p7q-9r87.json b/advisories/unreviewed/2025/05/GHSA-jgjg-2p7q-9r87/GHSA-jgjg-2p7q-9r87.json new file mode 100644 index 00000000000..aacbb9fe0c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgjg-2p7q-9r87/GHSA-jgjg-2p7q-9r87.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgjg-2p7q-9r87", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20030" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20030" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jpfr-pqqp-78jv/GHSA-jpfr-pqqp-78jv.json b/advisories/unreviewed/2025/05/GHSA-jpfr-pqqp-78jv/GHSA-jpfr-pqqp-78jv.json new file mode 100644 index 00000000000..850682c4e0b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jpfr-pqqp-78jv/GHSA-jpfr-pqqp-78jv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpfr-pqqp-78jv", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20611" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20611" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jphr-h5rc-4fcm/GHSA-jphr-h5rc-4fcm.json b/advisories/unreviewed/2025/05/GHSA-jphr-h5rc-4fcm/GHSA-jphr-h5rc-4fcm.json new file mode 100644 index 00000000000..75457ac17e8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jphr-h5rc-4fcm/GHSA-jphr-h5rc-4fcm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jphr-h5rc-4fcm", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-21100" + ], + "details": "Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21100" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqrv-q86j-89gq/GHSA-jqrv-q86j-89gq.json b/advisories/unreviewed/2025/05/GHSA-jqrv-q86j-89gq/GHSA-jqrv-q86j-89gq.json new file mode 100644 index 00000000000..a24b22dbf05 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqrv-q86j-89gq/GHSA-jqrv-q86j-89gq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqrv-q86j-89gq", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-45333" + ], + "details": "Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45333" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwhg-mgwp-pxg5/GHSA-jwhg-mgwp-pxg5.json b/advisories/unreviewed/2025/05/GHSA-jwhg-mgwp-pxg5/GHSA-jwhg-mgwp-pxg5.json new file mode 100644 index 00000000000..14160378356 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jwhg-mgwp-pxg5/GHSA-jwhg-mgwp-pxg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwhg-mgwp-pxg5", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-30314" + ], + "details": "Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30314" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/connect/apsb25-36.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwpm-8696-jr8x/GHSA-jwpm-8696-jr8x.json b/advisories/unreviewed/2025/05/GHSA-jwpm-8696-jr8x/GHSA-jwpm-8696-jr8x.json index e71c65bbcec..caf91076afb 100644 --- a/advisories/unreviewed/2025/05/GHSA-jwpm-8696-jr8x/GHSA-jwpm-8696-jr8x.json +++ b/advisories/unreviewed/2025/05/GHSA-jwpm-8696-jr8x/GHSA-jwpm-8696-jr8x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jx33-373q-67x5/GHSA-jx33-373q-67x5.json b/advisories/unreviewed/2025/05/GHSA-jx33-373q-67x5/GHSA-jx33-373q-67x5.json index d28190898ef..8bf2229f94d 100644 --- a/advisories/unreviewed/2025/05/GHSA-jx33-373q-67x5/GHSA-jx33-373q-67x5.json +++ b/advisories/unreviewed/2025/05/GHSA-jx33-373q-67x5/GHSA-jx33-373q-67x5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json b/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json new file mode 100644 index 00000000000..09ae1e725af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m3hm-6gqp-pf9f/GHSA-m3hm-6gqp-pf9f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3hm-6gqp-pf9f", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-45332" + ], + "details": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45332" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json b/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json index 229e5453ce8..fa8fca90906 100644 --- a/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json +++ b/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mccx-692g-vmcf", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:35Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40625" ], "details": "Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-p4cq-3r8h-xhpx/GHSA-p4cq-3r8h-xhpx.json b/advisories/unreviewed/2025/05/GHSA-p4cq-3r8h-xhpx/GHSA-p4cq-3r8h-xhpx.json index ef3b607b3db..c3119f36c6e 100644 --- a/advisories/unreviewed/2025/05/GHSA-p4cq-3r8h-xhpx/GHSA-p4cq-3r8h-xhpx.json +++ b/advisories/unreviewed/2025/05/GHSA-p4cq-3r8h-xhpx/GHSA-p4cq-3r8h-xhpx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p54f-88c4-rhqc/GHSA-p54f-88c4-rhqc.json b/advisories/unreviewed/2025/05/GHSA-p54f-88c4-rhqc/GHSA-p54f-88c4-rhqc.json new file mode 100644 index 00000000000..1eba8b70fa2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p54f-88c4-rhqc/GHSA-p54f-88c4-rhqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p54f-88c4-rhqc", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43564" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43564" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p54g-r78w-vp49/GHSA-p54g-r78w-vp49.json b/advisories/unreviewed/2025/05/GHSA-p54g-r78w-vp49/GHSA-p54g-r78w-vp49.json new file mode 100644 index 00000000000..dbd8f860c7d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p54g-r78w-vp49/GHSA-p54g-r78w-vp49.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p54g-r78w-vp49", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-24308" + ], + "details": "Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24308" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01269.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json b/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json index 89f8f4941bd..9711c8ef745 100644 --- a/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json +++ b/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pc7f-fwqv-39wp/GHSA-pc7f-fwqv-39wp.json b/advisories/unreviewed/2025/05/GHSA-pc7f-fwqv-39wp/GHSA-pc7f-fwqv-39wp.json index 06ece2abb3a..69ddbbee161 100644 --- a/advisories/unreviewed/2025/05/GHSA-pc7f-fwqv-39wp/GHSA-pc7f-fwqv-39wp.json +++ b/advisories/unreviewed/2025/05/GHSA-pc7f-fwqv-39wp/GHSA-pc7f-fwqv-39wp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7f-fwqv-39wp", - "modified": "2025-05-06T12:30:24Z", + "modified": "2025-05-13T21:30:35Z", "published": "2025-05-06T12:30:24Z", "aliases": [ "CVE-2025-40624" ], "details": "SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/05/GHSA-pc7p-8jw5-r2vh/GHSA-pc7p-8jw5-r2vh.json b/advisories/unreviewed/2025/05/GHSA-pc7p-8jw5-r2vh/GHSA-pc7p-8jw5-r2vh.json index 1ffb3f3e0d3..90fe0a21199 100644 --- a/advisories/unreviewed/2025/05/GHSA-pc7p-8jw5-r2vh/GHSA-pc7p-8jw5-r2vh.json +++ b/advisories/unreviewed/2025/05/GHSA-pc7p-8jw5-r2vh/GHSA-pc7p-8jw5-r2vh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ph6m-xm86-g466/GHSA-ph6m-xm86-g466.json b/advisories/unreviewed/2025/05/GHSA-ph6m-xm86-g466/GHSA-ph6m-xm86-g466.json new file mode 100644 index 00000000000..9fa3bd7fe48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ph6m-xm86-g466/GHSA-ph6m-xm86-g466.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph6m-xm86-g466", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22843" + ], + "details": "Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22843" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-279" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pj2v-xcf9-fg6j/GHSA-pj2v-xcf9-fg6j.json b/advisories/unreviewed/2025/05/GHSA-pj2v-xcf9-fg6j/GHSA-pj2v-xcf9-fg6j.json new file mode 100644 index 00000000000..7d416b0f0cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pj2v-xcf9-fg6j/GHSA-pj2v-xcf9-fg6j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj2v-xcf9-fg6j", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-36292" + ], + "details": "Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36292" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pmfj-xxhm-76m4/GHSA-pmfj-xxhm-76m4.json b/advisories/unreviewed/2025/05/GHSA-pmfj-xxhm-76m4/GHSA-pmfj-xxhm-76m4.json index d27c79cff8b..11443711f57 100644 --- a/advisories/unreviewed/2025/05/GHSA-pmfj-xxhm-76m4/GHSA-pmfj-xxhm-76m4.json +++ b/advisories/unreviewed/2025/05/GHSA-pmfj-xxhm-76m4/GHSA-pmfj-xxhm-76m4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pqh7-vp7f-6f29/GHSA-pqh7-vp7f-6f29.json b/advisories/unreviewed/2025/05/GHSA-pqh7-vp7f-6f29/GHSA-pqh7-vp7f-6f29.json new file mode 100644 index 00000000000..a22c904df64 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pqh7-vp7f-6f29/GHSA-pqh7-vp7f-6f29.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqh7-vp7f-6f29", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20057" + ], + "details": "Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20057" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-prg4-vj3x-j89v/GHSA-prg4-vj3x-j89v.json b/advisories/unreviewed/2025/05/GHSA-prg4-vj3x-j89v/GHSA-prg4-vj3x-j89v.json new file mode 100644 index 00000000000..e641054b96c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prg4-vj3x-j89v/GHSA-prg4-vj3x-j89v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prg4-vj3x-j89v", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2024-46895" + ], + "details": "Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46895" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pw7w-9qc5-p77h/GHSA-pw7w-9qc5-p77h.json b/advisories/unreviewed/2025/05/GHSA-pw7w-9qc5-p77h/GHSA-pw7w-9qc5-p77h.json new file mode 100644 index 00000000000..c0b36c46c9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pw7w-9qc5-p77h/GHSA-pw7w-9qc5-p77h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw7w-9qc5-p77h", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22848" + ], + "details": "Improper conditions check for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22848" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q2g3-7222-f2p8/GHSA-q2g3-7222-f2p8.json b/advisories/unreviewed/2025/05/GHSA-q2g3-7222-f2p8/GHSA-q2g3-7222-f2p8.json new file mode 100644 index 00000000000..dd6404f681a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q2g3-7222-f2p8/GHSA-q2g3-7222-f2p8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2g3-7222-f2p8", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20006" + ], + "details": "Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20006" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json b/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json index d2abcee965a..eb736b107db 100644 --- a/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json +++ b/advisories/unreviewed/2025/05/GHSA-q67x-mx4c-h9qv/GHSA-q67x-mx4c-h9qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q67x-mx4c-h9qv", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-13T21:30:40Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24274" ], "details": "An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json b/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json index d2d18709b17..4257e3e438d 100644 --- a/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json +++ b/advisories/unreviewed/2025/05/GHSA-qvqh-wfm7-mh52/GHSA-qvqh-wfm7-mh52.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvqh-wfm7-mh52", - "modified": "2025-05-13T00:31:12Z", + "modified": "2025-05-13T21:30:40Z", "published": "2025-05-13T00:31:12Z", "aliases": [ "CVE-2025-24222" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r2g5-cc54-vchq/GHSA-r2g5-cc54-vchq.json b/advisories/unreviewed/2025/05/GHSA-r2g5-cc54-vchq/GHSA-r2g5-cc54-vchq.json new file mode 100644 index 00000000000..cc6a8698a3e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r2g5-cc54-vchq/GHSA-r2g5-cc54-vchq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2g5-cc54-vchq", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20004" + ], + "details": "Insufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20004" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01273.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-691" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r5w9-6rgg-43hq/GHSA-r5w9-6rgg-43hq.json b/advisories/unreviewed/2025/05/GHSA-r5w9-6rgg-43hq/GHSA-r5w9-6rgg-43hq.json new file mode 100644 index 00000000000..261a97056a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r5w9-6rgg-43hq/GHSA-r5w9-6rgg-43hq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5w9-6rgg-43hq", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20624" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20624" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json b/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json index a49b26f0fae..ef2dfc8d3bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json +++ b/advisories/unreviewed/2025/05/GHSA-r5x9-vf8c-hh3f/GHSA-r5x9-vf8c-hh3f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5x9-vf8c-hh3f", - "modified": "2025-05-13T00:31:16Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:16Z", "aliases": [ "CVE-2025-31260" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r75c-5vvp-mrg6/GHSA-r75c-5vvp-mrg6.json b/advisories/unreviewed/2025/05/GHSA-r75c-5vvp-mrg6/GHSA-r75c-5vvp-mrg6.json new file mode 100644 index 00000000000..a3b686c7b25 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r75c-5vvp-mrg6/GHSA-r75c-5vvp-mrg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r75c-5vvp-mrg6", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43561" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43561" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcc5-3vf5-vg86/GHSA-rcc5-3vf5-vg86.json b/advisories/unreviewed/2025/05/GHSA-rcc5-3vf5-vg86/GHSA-rcc5-3vf5-vg86.json new file mode 100644 index 00000000000..505ca34c190 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rcc5-3vf5-vg86/GHSA-rcc5-3vf5-vg86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcc5-3vf5-vg86", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43559" + ], + "details": "ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43559" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcr7-jhhc-q8xj/GHSA-rcr7-jhhc-q8xj.json b/advisories/unreviewed/2025/05/GHSA-rcr7-jhhc-q8xj/GHSA-rcr7-jhhc-q8xj.json index 48e527c8feb..95b4796daa0 100644 --- a/advisories/unreviewed/2025/05/GHSA-rcr7-jhhc-q8xj/GHSA-rcr7-jhhc-q8xj.json +++ b/advisories/unreviewed/2025/05/GHSA-rcr7-jhhc-q8xj/GHSA-rcr7-jhhc-q8xj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json new file mode 100644 index 00000000000..3131e21888f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rcw6-7x98-m9g9/GHSA-rcw6-7x98-m9g9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcw6-7x98-m9g9", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:53Z", + "aliases": [ + "CVE-2025-45746" + ], + "details": "In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45746" + }, + { + "type": "WEB", + "url": "https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2025-45746.md" + }, + { + "type": "WEB", + "url": "http://zkbio.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rh69-7g6g-53pr/GHSA-rh69-7g6g-53pr.json b/advisories/unreviewed/2025/05/GHSA-rh69-7g6g-53pr/GHSA-rh69-7g6g-53pr.json index 29f1e25c554..0c8ccc67f9e 100644 --- a/advisories/unreviewed/2025/05/GHSA-rh69-7g6g-53pr/GHSA-rh69-7g6g-53pr.json +++ b/advisories/unreviewed/2025/05/GHSA-rh69-7g6g-53pr/GHSA-rh69-7g6g-53pr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json b/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json index fb30e884fae..06c020e9865 100644 --- a/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json +++ b/advisories/unreviewed/2025/05/GHSA-rv3r-4pvf-f5pm/GHSA-rv3r-4pvf-f5pm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rv3r-4pvf-f5pm", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31249" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json index b0459ae3582..5abc78554e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json +++ b/advisories/unreviewed/2025/05/GHSA-rvh4-h7j5-46g3/GHSA-rvh4-h7j5-46g3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rvh4-h7j5-46g3", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31256" ], "details": "The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted notes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rw9f-r6rm-xmq7/GHSA-rw9f-r6rm-xmq7.json b/advisories/unreviewed/2025/05/GHSA-rw9f-r6rm-xmq7/GHSA-rw9f-r6rm-xmq7.json new file mode 100644 index 00000000000..5b1dbfdd07b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rw9f-r6rm-xmq7/GHSA-rw9f-r6rm-xmq7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw9f-r6rm-xmq7", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20032" + ], + "details": "Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20032" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json b/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json index 683864ba3bf..d64099a2b02 100644 --- a/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json +++ b/advisories/unreviewed/2025/05/GHSA-rwxj-39xx-47jr/GHSA-rwxj-39xx-47jr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwxj-39xx-47jr", - "modified": "2025-05-13T00:31:15Z", + "modified": "2025-05-13T21:30:43Z", "published": "2025-05-13T00:31:15Z", "aliases": [ "CVE-2025-31245" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:24Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rx8m-jv6m-48mj/GHSA-rx8m-jv6m-48mj.json b/advisories/unreviewed/2025/05/GHSA-rx8m-jv6m-48mj/GHSA-rx8m-jv6m-48mj.json new file mode 100644 index 00000000000..38a9c870e2b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rx8m-jv6m-48mj/GHSA-rx8m-jv6m-48mj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx8m-jv6m-48mj", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-23233" + ], + "details": "Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23233" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-279" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json b/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json index e87ff9aa5e4..d20e715c233 100644 --- a/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json +++ b/advisories/unreviewed/2025/05/GHSA-v248-84wv-hjm5/GHSA-v248-84wv-hjm5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v248-84wv-hjm5", - "modified": "2025-05-05T18:32:52Z", + "modified": "2025-05-13T21:30:33Z", "published": "2025-05-05T18:32:52Z", "aliases": [ "CVE-2025-28062" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T16:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json b/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json index 762fa739401..5b2f852dbf7 100644 --- a/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json +++ b/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v7hp-7j8c-xrp4/GHSA-v7hp-7j8c-xrp4.json b/advisories/unreviewed/2025/05/GHSA-v7hp-7j8c-xrp4/GHSA-v7hp-7j8c-xrp4.json new file mode 100644 index 00000000000..128be083d1b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7hp-7j8c-xrp4/GHSA-v7hp-7j8c-xrp4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7hp-7j8c-xrp4", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-22446" + ], + "details": "Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22446" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01239.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json b/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json new file mode 100644 index 00000000000..7ce08f90ef8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7m3-xggw-4h6v/GHSA-v7m3-xggw-4h6v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7m3-xggw-4h6v", + "modified": "2025-05-13T21:30:53Z", + "published": "2025-05-13T21:30:53Z", + "aliases": [ + "CVE-2025-45865" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45865" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/6/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vmj9-38jh-86gf/GHSA-vmj9-38jh-86gf.json b/advisories/unreviewed/2025/05/GHSA-vmj9-38jh-86gf/GHSA-vmj9-38jh-86gf.json new file mode 100644 index 00000000000..527bf3f8e9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vmj9-38jh-86gf/GHSA-vmj9-38jh-86gf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmj9-38jh-86gf", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20052" + ], + "details": "Improper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20052" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json b/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json index 399ba0f81ea..0b988e023ab 100644 --- a/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json +++ b/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vv97-g4jh-67w7/GHSA-vv97-g4jh-67w7.json b/advisories/unreviewed/2025/05/GHSA-vv97-g4jh-67w7/GHSA-vv97-g4jh-67w7.json index 6d3abc89bd3..67a65c05ee6 100644 --- a/advisories/unreviewed/2025/05/GHSA-vv97-g4jh-67w7/GHSA-vv97-g4jh-67w7.json +++ b/advisories/unreviewed/2025/05/GHSA-vv97-g4jh-67w7/GHSA-vv97-g4jh-67w7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vw6r-jvq2-p27g/GHSA-vw6r-jvq2-p27g.json b/advisories/unreviewed/2025/05/GHSA-vw6r-jvq2-p27g/GHSA-vw6r-jvq2-p27g.json new file mode 100644 index 00000000000..e7a6bcdf505 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vw6r-jvq2-p27g/GHSA-vw6r-jvq2-p27g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw6r-jvq2-p27g", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-47550" + ], + "details": "Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47550" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01254.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w2f7-j56m-cq8j/GHSA-w2f7-j56m-cq8j.json b/advisories/unreviewed/2025/05/GHSA-w2f7-j56m-cq8j/GHSA-w2f7-j56m-cq8j.json index d45e24729aa..e732dc4f035 100644 --- a/advisories/unreviewed/2025/05/GHSA-w2f7-j56m-cq8j/GHSA-w2f7-j56m-cq8j.json +++ b/advisories/unreviewed/2025/05/GHSA-w2f7-j56m-cq8j/GHSA-w2f7-j56m-cq8j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-w37v-gw38-5cpf/GHSA-w37v-gw38-5cpf.json b/advisories/unreviewed/2025/05/GHSA-w37v-gw38-5cpf/GHSA-w37v-gw38-5cpf.json new file mode 100644 index 00000000000..f82f597f900 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w37v-gw38-5cpf/GHSA-w37v-gw38-5cpf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w37v-gw38-5cpf", + "modified": "2025-05-13T21:30:56Z", + "published": "2025-05-13T21:30:56Z", + "aliases": [ + "CVE-2025-20618" + ], + "details": "Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20618" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4qq-8jwj-h7hp/GHSA-w4qq-8jwj-h7hp.json b/advisories/unreviewed/2025/05/GHSA-w4qq-8jwj-h7hp/GHSA-w4qq-8jwj-h7hp.json new file mode 100644 index 00000000000..c622789d171 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4qq-8jwj-h7hp/GHSA-w4qq-8jwj-h7hp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4qq-8jwj-h7hp", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20046" + ], + "details": "Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20046" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w8jf-vp47-grfv/GHSA-w8jf-vp47-grfv.json b/advisories/unreviewed/2025/05/GHSA-w8jf-vp47-grfv/GHSA-w8jf-vp47-grfv.json new file mode 100644 index 00000000000..00291bb392d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w8jf-vp47-grfv/GHSA-w8jf-vp47-grfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8jf-vp47-grfv", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43548" + ], + "details": "Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43548" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/dimension/apsb25-45.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w8jh-376c-cw53/GHSA-w8jh-376c-cw53.json b/advisories/unreviewed/2025/05/GHSA-w8jh-376c-cw53/GHSA-w8jh-376c-cw53.json new file mode 100644 index 00000000000..f823813cdef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w8jh-376c-cw53/GHSA-w8jh-376c-cw53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8jh-376c-cw53", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-43549" + ], + "details": "Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43549" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wcm9-xh5q-36wf/GHSA-wcm9-xh5q-36wf.json b/advisories/unreviewed/2025/05/GHSA-wcm9-xh5q-36wf/GHSA-wcm9-xh5q-36wf.json new file mode 100644 index 00000000000..dc7cbb926cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wcm9-xh5q-36wf/GHSA-wcm9-xh5q-36wf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcm9-xh5q-36wf", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20015" + ], + "details": "Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20015" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01294.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wq2q-cqq5-59c8/GHSA-wq2q-cqq5-59c8.json b/advisories/unreviewed/2025/05/GHSA-wq2q-cqq5-59c8/GHSA-wq2q-cqq5-59c8.json new file mode 100644 index 00000000000..e521fbed28c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wq2q-cqq5-59c8/GHSA-wq2q-cqq5-59c8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq2q-cqq5-59c8", + "modified": "2025-05-13T21:30:57Z", + "published": "2025-05-13T21:30:57Z", + "aliases": [ + "CVE-2025-22448" + ], + "details": "Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22448" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01297.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json b/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json index a9daae0e189..816ffec29c5 100644 --- a/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json +++ b/advisories/unreviewed/2025/05/GHSA-wv7w-fgmw-6vg2/GHSA-wv7w-fgmw-6vg2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wv7w-fgmw-6vg2", - "modified": "2025-05-13T00:31:13Z", + "modified": "2025-05-13T21:30:41Z", "published": "2025-05-13T00:31:13Z", "aliases": [ "CVE-2025-31206" ], "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-12T22:15:21Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wx26-mq6r-mrxc/GHSA-wx26-mq6r-mrxc.json b/advisories/unreviewed/2025/05/GHSA-wx26-mq6r-mrxc/GHSA-wx26-mq6r-mrxc.json new file mode 100644 index 00000000000..29263d255ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wx26-mq6r-mrxc/GHSA-wx26-mq6r-mrxc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx26-mq6r-mrxc", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2024-45371" + ], + "details": "Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45371" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6gq-x5vj-75fr/GHSA-x6gq-x5vj-75fr.json b/advisories/unreviewed/2025/05/GHSA-x6gq-x5vj-75fr/GHSA-x6gq-x5vj-75fr.json new file mode 100644 index 00000000000..01b2d335069 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6gq-x5vj-75fr/GHSA-x6gq-x5vj-75fr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6gq-x5vj-75fr", + "modified": "2025-05-13T21:30:54Z", + "published": "2025-05-13T21:30:54Z", + "aliases": [ + "CVE-2024-43101" + ], + "details": "Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43101" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01253.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgw4-9mp9-75mc/GHSA-xgw4-9mp9-75mc.json b/advisories/unreviewed/2025/05/GHSA-xgw4-9mp9-75mc/GHSA-xgw4-9mp9-75mc.json index 7daef5862dd..6625d2866b6 100644 --- a/advisories/unreviewed/2025/05/GHSA-xgw4-9mp9-75mc/GHSA-xgw4-9mp9-75mc.json +++ b/advisories/unreviewed/2025/05/GHSA-xgw4-9mp9-75mc/GHSA-xgw4-9mp9-75mc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xh33-q298-mqqf/GHSA-xh33-q298-mqqf.json b/advisories/unreviewed/2025/05/GHSA-xh33-q298-mqqf/GHSA-xh33-q298-mqqf.json index e00af244860..2c65340c1d3 100644 --- a/advisories/unreviewed/2025/05/GHSA-xh33-q298-mqqf/GHSA-xh33-q298-mqqf.json +++ b/advisories/unreviewed/2025/05/GHSA-xh33-q298-mqqf/GHSA-xh33-q298-mqqf.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xvw9-48jx-4p2f/GHSA-xvw9-48jx-4p2f.json b/advisories/unreviewed/2025/05/GHSA-xvw9-48jx-4p2f/GHSA-xvw9-48jx-4p2f.json new file mode 100644 index 00000000000..7598fff5e3c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xvw9-48jx-4p2f/GHSA-xvw9-48jx-4p2f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvw9-48jx-4p2f", + "modified": "2025-05-13T21:30:55Z", + "published": "2025-05-13T21:30:55Z", + "aliases": [ + "CVE-2025-20018" + ], + "details": "Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20018" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01259.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T21:16:03Z" + } +} \ No newline at end of file