From abc63774b7f5d0c54648945a637c730a2da17806 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Feb 2025 21:33:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7wmh-gw77-55mp.json | 2 +- .../GHSA-f3pv-9fwh-mp3x.json | 26 +++++++++++- .../GHSA-4hp5-9mp9-5574.json | 2 +- .../GHSA-w45c-77r5-cpwj.json | 6 ++- .../GHSA-g3gr-pmrc-h9x8.json | 4 +- .../GHSA-w6wm-9q8x-p5h7.json | 4 +- .../GHSA-wwm6-cf6h-7h22.json | 4 +- .../GHSA-rh9q-p39g-xcv7.json | 4 +- .../GHSA-63vc-3rx9-frx5.json | 4 +- .../GHSA-8vjr-8rfp-6qqp.json | 4 +- .../GHSA-pvqh-8qgj-x6qm.json | 4 +- .../GHSA-3wf3-9vwr-cm6w.json | 6 ++- .../GHSA-77g7-q65f-rmxf.json | 6 ++- .../GHSA-7h92-85hj-27vv.json | 6 ++- .../GHSA-hj6w-5v7m-rj3p.json | 6 ++- .../GHSA-2g64-p9rr-cp7f.json | 2 +- .../GHSA-c9xj-qgpm-mj78.json | 3 +- .../GHSA-2r9h-x757-8j9q.json | 3 +- .../GHSA-5c3f-j7gj-gmxg.json | 3 +- .../GHSA-j2pc-4j53-q3ww.json | 1 + .../GHSA-m4rq-mf69-pwg7.json | 3 +- .../GHSA-w8w2-83mf-6cp5.json | 6 ++- .../GHSA-2mpx-hg3q-3wq8.json | 36 +++++++++++++++++ .../GHSA-2rq4-xq7w-xw4p.json | 36 +++++++++++++++++ .../GHSA-326h-2x69-48rv.json | 29 ++++++++++++++ .../GHSA-5297-gvvw-vmrc.json | 36 +++++++++++++++++ .../GHSA-58jq-9v9j-27q7.json | 29 ++++++++++++++ .../GHSA-68qp-rj3r-5wfp.json | 29 ++++++++++++++ .../GHSA-6r78-gm5f-2wgq.json | 36 +++++++++++++++++ .../GHSA-7gx7-rqf8-p84p.json | 29 ++++++++++++++ .../GHSA-8fxq-cfj5-2qpw.json | 40 +++++++++++++++++++ .../GHSA-8v99-v6mx-7wwr.json | 36 +++++++++++++++++ .../GHSA-8vh6-x54m-xp4c.json | 40 +++++++++++++++++++ .../GHSA-8x36-4hm5-x65x.json | 36 +++++++++++++++++ .../GHSA-99rw-q85c-42h7.json | 36 +++++++++++++++++ .../GHSA-9jmj-63mp-54pw.json | 36 +++++++++++++++++ .../GHSA-f477-2qwf-rv4g.json | 36 +++++++++++++++++ .../GHSA-f8qh-8jm6-2p94.json | 29 ++++++++++++++ .../GHSA-fq6v-7fwh-v7j7.json | 36 +++++++++++++++++ .../GHSA-fw98-qx57-q7pf.json | 36 +++++++++++++++++ .../GHSA-g496-2h33-mpvw.json | 36 +++++++++++++++++ .../GHSA-g6fx-m6jq-g8fj.json | 36 +++++++++++++++++ .../GHSA-gg96-8hgf-g3hr.json | 29 ++++++++++++++ .../GHSA-gxv5-f49x-7hp5.json | 36 +++++++++++++++++ .../GHSA-hf56-943j-3hp3.json | 29 ++++++++++++++ .../GHSA-j4w5-fp7w-rwm7.json | 36 +++++++++++++++++ .../GHSA-m2vr-44vr-52pj.json | 36 +++++++++++++++++ .../GHSA-m78v-p3pw-4h65.json | 36 +++++++++++++++++ .../GHSA-mgg2-v3h3-2m84.json | 36 +++++++++++++++++ .../GHSA-mjjg-jgrj-9453.json | 33 +++++++++++++++ .../GHSA-p3w4-g6w7-3v89.json | 36 +++++++++++++++++ .../GHSA-pjg6-r723-9cv2.json | 36 +++++++++++++++++ .../GHSA-qgr4-x6rm-5fpg.json | 36 +++++++++++++++++ .../GHSA-qvrw-24w7-q9x7.json | 36 +++++++++++++++++ .../GHSA-r2x7-3q95-cxfw.json | 36 +++++++++++++++++ .../GHSA-vcv3-98rx-3xxp.json | 29 ++++++++++++++ .../GHSA-vjv3-8wrv-hh93.json | 36 +++++++++++++++++ .../GHSA-x2hv-hf2m-v432.json | 29 ++++++++++++++ .../GHSA-x7cc-g69m-67hg.json | 36 +++++++++++++++++ 59 files changed, 1360 insertions(+), 23 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-2mpx-hg3q-3wq8/GHSA-2mpx-hg3q-3wq8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2rq4-xq7w-xw4p/GHSA-2rq4-xq7w-xw4p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-326h-2x69-48rv/GHSA-326h-2x69-48rv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5297-gvvw-vmrc/GHSA-5297-gvvw-vmrc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-58jq-9v9j-27q7/GHSA-58jq-9v9j-27q7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-68qp-rj3r-5wfp/GHSA-68qp-rj3r-5wfp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6r78-gm5f-2wgq/GHSA-6r78-gm5f-2wgq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7gx7-rqf8-p84p/GHSA-7gx7-rqf8-p84p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8fxq-cfj5-2qpw/GHSA-8fxq-cfj5-2qpw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8v99-v6mx-7wwr/GHSA-8v99-v6mx-7wwr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8vh6-x54m-xp4c/GHSA-8vh6-x54m-xp4c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8x36-4hm5-x65x/GHSA-8x36-4hm5-x65x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-99rw-q85c-42h7/GHSA-99rw-q85c-42h7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9jmj-63mp-54pw/GHSA-9jmj-63mp-54pw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f477-2qwf-rv4g/GHSA-f477-2qwf-rv4g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f8qh-8jm6-2p94/GHSA-f8qh-8jm6-2p94.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fw98-qx57-q7pf/GHSA-fw98-qx57-q7pf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g496-2h33-mpvw/GHSA-g496-2h33-mpvw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g6fx-m6jq-g8fj/GHSA-g6fx-m6jq-g8fj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gg96-8hgf-g3hr/GHSA-gg96-8hgf-g3hr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gxv5-f49x-7hp5/GHSA-gxv5-f49x-7hp5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hf56-943j-3hp3/GHSA-hf56-943j-3hp3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j4w5-fp7w-rwm7/GHSA-j4w5-fp7w-rwm7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m2vr-44vr-52pj/GHSA-m2vr-44vr-52pj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m78v-p3pw-4h65/GHSA-m78v-p3pw-4h65.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mgg2-v3h3-2m84/GHSA-mgg2-v3h3-2m84.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mjjg-jgrj-9453/GHSA-mjjg-jgrj-9453.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p3w4-g6w7-3v89/GHSA-p3w4-g6w7-3v89.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pjg6-r723-9cv2/GHSA-pjg6-r723-9cv2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qgr4-x6rm-5fpg/GHSA-qgr4-x6rm-5fpg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qvrw-24w7-q9x7/GHSA-qvrw-24w7-q9x7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r2x7-3q95-cxfw/GHSA-r2x7-3q95-cxfw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vcv3-98rx-3xxp/GHSA-vcv3-98rx-3xxp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vjv3-8wrv-hh93/GHSA-vjv3-8wrv-hh93.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x2hv-hf2m-v432/GHSA-x2hv-hf2m-v432.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x7cc-g69m-67hg/GHSA-x7cc-g69m-67hg.json diff --git a/advisories/unreviewed/2022/05/GHSA-7wmh-gw77-55mp/GHSA-7wmh-gw77-55mp.json b/advisories/unreviewed/2022/05/GHSA-7wmh-gw77-55mp/GHSA-7wmh-gw77-55mp.json index 62d1b61bc79..0d000c878c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wmh-gw77-55mp/GHSA-7wmh-gw77-55mp.json +++ b/advisories/unreviewed/2022/05/GHSA-7wmh-gw77-55mp/GHSA-7wmh-gw77-55mp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wmh-gw77-55mp", - "modified": "2022-05-13T01:16:05Z", + "modified": "2025-02-11T21:32:00Z", "published": "2022-05-13T01:16:05Z", "aliases": [ "CVE-2018-19873" diff --git a/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json b/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json index b1075d07f06..2772249a7fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json +++ b/advisories/unreviewed/2022/05/GHSA-f3pv-9fwh-mp3x/GHSA-f3pv-9fwh-mp3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3pv-9fwh-mp3x", - "modified": "2022-05-26T00:01:15Z", + "modified": "2025-02-11T21:32:00Z", "published": "2022-05-17T00:00:35Z", "aliases": [ "CVE-2022-1586" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1586" }, + { + "type": "WEB", + "url": "https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a%2C" + }, { "type": "WEB", "url": "https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a," @@ -27,6 +31,10 @@ "type": "WEB", "url": "https://github.com/PCRE2Project/pcre2/commit/d4fa336fbcc388f89095b184ba6d99422cfc676c" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2077976%2C" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2077976," @@ -35,6 +43,22 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00014.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXINO3KKI5DICQ45E2FKD6MKVMGJLEKJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KAX7767BCUFC7JMDGP7GOQ5GIZCAUGBB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2GLQQUEY5VFM57CFYXVIFOXN2HUZPDM" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DWNG2NS3GINO6LQYUVC4BZLUQPJ3DYHA" diff --git a/advisories/unreviewed/2023/04/GHSA-4hp5-9mp9-5574/GHSA-4hp5-9mp9-5574.json b/advisories/unreviewed/2023/04/GHSA-4hp5-9mp9-5574/GHSA-4hp5-9mp9-5574.json index a0b0bbd6e02..9ee95739e5b 100644 --- a/advisories/unreviewed/2023/04/GHSA-4hp5-9mp9-5574/GHSA-4hp5-9mp9-5574.json +++ b/advisories/unreviewed/2023/04/GHSA-4hp5-9mp9-5574/GHSA-4hp5-9mp9-5574.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hp5-9mp9-5574", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-11T21:32:00Z", "published": "2023-04-09T21:30:14Z", "aliases": [ "CVE-2023-27718" diff --git a/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json b/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json index 5aaf7e541ff..f7f7d8bb2b6 100644 --- a/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json +++ b/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w45c-77r5-cpwj", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-11T21:32:00Z", "published": "2023-04-07T15:30:39Z", "aliases": [ "CVE-2023-27804" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27804" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/DelvsList" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/DelvsList" diff --git a/advisories/unreviewed/2024/02/GHSA-g3gr-pmrc-h9x8/GHSA-g3gr-pmrc-h9x8.json b/advisories/unreviewed/2024/02/GHSA-g3gr-pmrc-h9x8/GHSA-g3gr-pmrc-h9x8.json index 7a2fc7a2219..3b4b274424f 100644 --- a/advisories/unreviewed/2024/02/GHSA-g3gr-pmrc-h9x8/GHSA-g3gr-pmrc-h9x8.json +++ b/advisories/unreviewed/2024/02/GHSA-g3gr-pmrc-h9x8/GHSA-g3gr-pmrc-h9x8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json b/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json index 88fb45b9cc5..78d9db5ee72 100644 --- a/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json +++ b/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-wwm6-cf6h-7h22/GHSA-wwm6-cf6h-7h22.json b/advisories/unreviewed/2024/02/GHSA-wwm6-cf6h-7h22/GHSA-wwm6-cf6h-7h22.json index 5396a086e74..67f82d924c9 100644 --- a/advisories/unreviewed/2024/02/GHSA-wwm6-cf6h-7h22/GHSA-wwm6-cf6h-7h22.json +++ b/advisories/unreviewed/2024/02/GHSA-wwm6-cf6h-7h22/GHSA-wwm6-cf6h-7h22.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rh9q-p39g-xcv7/GHSA-rh9q-p39g-xcv7.json b/advisories/unreviewed/2024/03/GHSA-rh9q-p39g-xcv7/GHSA-rh9q-p39g-xcv7.json index 877e4e78695..ae3d3d22d9e 100644 --- a/advisories/unreviewed/2024/03/GHSA-rh9q-p39g-xcv7/GHSA-rh9q-p39g-xcv7.json +++ b/advisories/unreviewed/2024/03/GHSA-rh9q-p39g-xcv7/GHSA-rh9q-p39g-xcv7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rh9q-p39g-xcv7", - "modified": "2024-03-15T15:30:44Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-03-15T15:30:44Z", "aliases": [ "CVE-2023-51369" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-63vc-3rx9-frx5/GHSA-63vc-3rx9-frx5.json b/advisories/unreviewed/2024/04/GHSA-63vc-3rx9-frx5/GHSA-63vc-3rx9-frx5.json index 9bd8d7eec15..b22980cd728 100644 --- a/advisories/unreviewed/2024/04/GHSA-63vc-3rx9-frx5/GHSA-63vc-3rx9-frx5.json +++ b/advisories/unreviewed/2024/04/GHSA-63vc-3rx9-frx5/GHSA-63vc-3rx9-frx5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-63vc-3rx9-frx5", - "modified": "2024-04-15T12:30:35Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-04-15T12:30:35Z", "aliases": [ "CVE-2024-31378" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-8vjr-8rfp-6qqp/GHSA-8vjr-8rfp-6qqp.json b/advisories/unreviewed/2024/04/GHSA-8vjr-8rfp-6qqp/GHSA-8vjr-8rfp-6qqp.json index 1256747aea9..ad62d33e3ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vjr-8rfp-6qqp/GHSA-8vjr-8rfp-6qqp.json +++ b/advisories/unreviewed/2024/04/GHSA-8vjr-8rfp-6qqp/GHSA-8vjr-8rfp-6qqp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pvqh-8qgj-x6qm/GHSA-pvqh-8qgj-x6qm.json b/advisories/unreviewed/2024/04/GHSA-pvqh-8qgj-x6qm/GHSA-pvqh-8qgj-x6qm.json index 35d61d0a40b..7b0bcbd9efe 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvqh-8qgj-x6qm/GHSA-pvqh-8qgj-x6qm.json +++ b/advisories/unreviewed/2024/04/GHSA-pvqh-8qgj-x6qm/GHSA-pvqh-8qgj-x6qm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3wf3-9vwr-cm6w/GHSA-3wf3-9vwr-cm6w.json b/advisories/unreviewed/2024/05/GHSA-3wf3-9vwr-cm6w/GHSA-3wf3-9vwr-cm6w.json index a0a7beadeae..629ed9bcefa 100644 --- a/advisories/unreviewed/2024/05/GHSA-3wf3-9vwr-cm6w/GHSA-3wf3-9vwr-cm6w.json +++ b/advisories/unreviewed/2024/05/GHSA-3wf3-9vwr-cm6w/GHSA-3wf3-9vwr-cm6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wf3-9vwr-cm6w", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4808" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json b/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json index 5623a4026a7..d34ba4e5236 100644 --- a/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json +++ b/advisories/unreviewed/2024/05/GHSA-77g7-q65f-rmxf/GHSA-77g7-q65f-rmxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77g7-q65f-rmxf", - "modified": "2024-05-15T18:30:36Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-05-15T18:30:36Z", "aliases": [ "CVE-2024-4905" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7h92-85hj-27vv/GHSA-7h92-85hj-27vv.json b/advisories/unreviewed/2024/05/GHSA-7h92-85hj-27vv/GHSA-7h92-85hj-27vv.json index 6d4792197de..aba23c1b50b 100644 --- a/advisories/unreviewed/2024/05/GHSA-7h92-85hj-27vv/GHSA-7h92-85hj-27vv.json +++ b/advisories/unreviewed/2024/05/GHSA-7h92-85hj-27vv/GHSA-7h92-85hj-27vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7h92-85hj-27vv", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4799" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-hj6w-5v7m-rj3p/GHSA-hj6w-5v7m-rj3p.json b/advisories/unreviewed/2024/05/GHSA-hj6w-5v7m-rj3p/GHSA-hj6w-5v7m-rj3p.json index 5e596c8c847..e2d892220e5 100644 --- a/advisories/unreviewed/2024/05/GHSA-hj6w-5v7m-rj3p/GHSA-hj6w-5v7m-rj3p.json +++ b/advisories/unreviewed/2024/05/GHSA-hj6w-5v7m-rj3p/GHSA-hj6w-5v7m-rj3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hj6w-5v7m-rj3p", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T21:32:01Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4807" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/08/GHSA-2g64-p9rr-cp7f/GHSA-2g64-p9rr-cp7f.json b/advisories/unreviewed/2024/08/GHSA-2g64-p9rr-cp7f/GHSA-2g64-p9rr-cp7f.json index 8717be31e6a..b92f12723cc 100644 --- a/advisories/unreviewed/2024/08/GHSA-2g64-p9rr-cp7f/GHSA-2g64-p9rr-cp7f.json +++ b/advisories/unreviewed/2024/08/GHSA-2g64-p9rr-cp7f/GHSA-2g64-p9rr-cp7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g64-p9rr-cp7f", - "modified": "2024-08-03T12:30:34Z", + "modified": "2025-02-11T21:32:02Z", "published": "2024-08-03T12:30:34Z", "aliases": [ "CVE-2024-7356" diff --git a/advisories/unreviewed/2024/08/GHSA-c9xj-qgpm-mj78/GHSA-c9xj-qgpm-mj78.json b/advisories/unreviewed/2024/08/GHSA-c9xj-qgpm-mj78/GHSA-c9xj-qgpm-mj78.json index 6f2b6a9bd65..02504d7bb83 100644 --- a/advisories/unreviewed/2024/08/GHSA-c9xj-qgpm-mj78/GHSA-c9xj-qgpm-mj78.json +++ b/advisories/unreviewed/2024/08/GHSA-c9xj-qgpm-mj78/GHSA-c9xj-qgpm-mj78.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json b/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json index 578f4b23187..105e7a3c487 100644 --- a/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json +++ b/advisories/unreviewed/2024/11/GHSA-2r9h-x757-8j9q/GHSA-2r9h-x757-8j9q.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-15" + "CWE-15", + "CWE-610" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5c3f-j7gj-gmxg/GHSA-5c3f-j7gj-gmxg.json b/advisories/unreviewed/2025/01/GHSA-5c3f-j7gj-gmxg/GHSA-5c3f-j7gj-gmxg.json index fa33112df8c..ec429d8a136 100644 --- a/advisories/unreviewed/2025/01/GHSA-5c3f-j7gj-gmxg/GHSA-5c3f-j7gj-gmxg.json +++ b/advisories/unreviewed/2025/01/GHSA-5c3f-j7gj-gmxg/GHSA-5c3f-j7gj-gmxg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json b/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json index be667a7d45e..ee03db84530 100644 --- a/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json +++ b/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-330", "CWE-340" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json b/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json index fef002b6b90..291ccd9b996 100644 --- a/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json +++ b/advisories/unreviewed/2025/01/GHSA-m4rq-mf69-pwg7/GHSA-m4rq-mf69-pwg7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-w8w2-83mf-6cp5/GHSA-w8w2-83mf-6cp5.json b/advisories/unreviewed/2025/01/GHSA-w8w2-83mf-6cp5/GHSA-w8w2-83mf-6cp5.json index 5e36a551a2f..7f27904e022 100644 --- a/advisories/unreviewed/2025/01/GHSA-w8w2-83mf-6cp5/GHSA-w8w2-83mf-6cp5.json +++ b/advisories/unreviewed/2025/01/GHSA-w8w2-83mf-6cp5/GHSA-w8w2-83mf-6cp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8w2-83mf-6cp5", - "modified": "2025-02-07T18:31:17Z", + "modified": "2025-02-11T21:32:05Z", "published": "2025-01-30T00:31:03Z", "aliases": [ "CVE-2024-11187" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2024-11187" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00011.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250207-0002" diff --git a/advisories/unreviewed/2025/02/GHSA-2mpx-hg3q-3wq8/GHSA-2mpx-hg3q-3wq8.json b/advisories/unreviewed/2025/02/GHSA-2mpx-hg3q-3wq8/GHSA-2mpx-hg3q-3wq8.json new file mode 100644 index 00000000000..2d32bef507a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2mpx-hg3q-3wq8/GHSA-2mpx-hg3q-3wq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mpx-hg3q-3wq8", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2023-31361" + ], + "details": "A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31361" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9012.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2rq4-xq7w-xw4p/GHSA-2rq4-xq7w-xw4p.json b/advisories/unreviewed/2025/02/GHSA-2rq4-xq7w-xw4p/GHSA-2rq4-xq7w-xw4p.json new file mode 100644 index 00000000000..749bb225270 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2rq4-xq7w-xw4p/GHSA-2rq4-xq7w-xw4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rq4-xq7w-xw4p", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-1052" + ], + "details": "Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1052" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-326h-2x69-48rv/GHSA-326h-2x69-48rv.json b/advisories/unreviewed/2025/02/GHSA-326h-2x69-48rv/GHSA-326h-2x69-48rv.json new file mode 100644 index 00000000000..5853c9759e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-326h-2x69-48rv/GHSA-326h-2x69-48rv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-326h-2x69-48rv", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-25526" + ], + "details": "Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25526" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/5e3770d5e78e0aa5f9d51ba3882c35cd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5297-gvvw-vmrc/GHSA-5297-gvvw-vmrc.json b/advisories/unreviewed/2025/02/GHSA-5297-gvvw-vmrc/GHSA-5297-gvvw-vmrc.json new file mode 100644 index 00000000000..9889129de96 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5297-gvvw-vmrc/GHSA-5297-gvvw-vmrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5297-gvvw-vmrc", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2024-12549" + ], + "details": "Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25565.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12549" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1679" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-58jq-9v9j-27q7/GHSA-58jq-9v9j-27q7.json b/advisories/unreviewed/2025/02/GHSA-58jq-9v9j-27q7/GHSA-58jq-9v9j-27q7.json new file mode 100644 index 00000000000..20440f3ccb0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-58jq-9v9j-27q7/GHSA-58jq-9v9j-27q7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58jq-9v9j-27q7", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2025-25528" + ], + "details": "Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25528" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/87f3a4412c46fa9c27d2f723136920b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-68qp-rj3r-5wfp/GHSA-68qp-rj3r-5wfp.json b/advisories/unreviewed/2025/02/GHSA-68qp-rj3r-5wfp/GHSA-68qp-rj3r-5wfp.json new file mode 100644 index 00000000000..13db4c6abe4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-68qp-rj3r-5wfp/GHSA-68qp-rj3r-5wfp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68qp-rj3r-5wfp", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2025-25527" + ], + "details": "Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25527" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/354620285280aca98acba94a9c5fffb6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6r78-gm5f-2wgq/GHSA-6r78-gm5f-2wgq.json b/advisories/unreviewed/2025/02/GHSA-6r78-gm5f-2wgq/GHSA-6r78-gm5f-2wgq.json new file mode 100644 index 00000000000..c7c27a79f0e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6r78-gm5f-2wgq/GHSA-6r78-gm5f-2wgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r78-gm5f-2wgq", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0905" + ], + "details": "PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25433.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0905" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7gx7-rqf8-p84p/GHSA-7gx7-rqf8-p84p.json b/advisories/unreviewed/2025/02/GHSA-7gx7-rqf8-p84p/GHSA-7gx7-rqf8-p84p.json new file mode 100644 index 00000000000..688e0527e78 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7gx7-rqf8-p84p/GHSA-7gx7-rqf8-p84p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gx7-rqf8-p84p", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2025-25524" + ], + "details": "Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25524" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/ce1f80afd2d8be8ca543437f16eae96b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8fxq-cfj5-2qpw/GHSA-8fxq-cfj5-2qpw.json b/advisories/unreviewed/2025/02/GHSA-8fxq-cfj5-2qpw/GHSA-8fxq-cfj5-2qpw.json new file mode 100644 index 00000000000..1f03bceea7c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8fxq-cfj5-2qpw/GHSA-8fxq-cfj5-2qpw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxq-cfj5-2qpw", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2023-20507" + ], + "details": "An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20507" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4008.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8v99-v6mx-7wwr/GHSA-8v99-v6mx-7wwr.json b/advisories/unreviewed/2025/02/GHSA-8v99-v6mx-7wwr/GHSA-8v99-v6mx-7wwr.json new file mode 100644 index 00000000000..3b194a66989 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8v99-v6mx-7wwr/GHSA-8v99-v6mx-7wwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v99-v6mx-7wwr", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0909" + ], + "details": "PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25678.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0909" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8vh6-x54m-xp4c/GHSA-8vh6-x54m-xp4c.json b/advisories/unreviewed/2025/02/GHSA-8vh6-x54m-xp4c/GHSA-8vh6-x54m-xp4c.json new file mode 100644 index 00000000000..45e1dfeafe6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8vh6-x54m-xp4c/GHSA-8vh6-x54m-xp4c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vh6-x54m-xp4c", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-1044" + ], + "details": "Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1044" + }, + { + "type": "WEB", + "url": "https://support.logsign.net/hc/en-us/articles/22076844908946-18-10-2024-Version-6-4-32-Release-Notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8x36-4hm5-x65x/GHSA-8x36-4hm5-x65x.json b/advisories/unreviewed/2025/02/GHSA-8x36-4hm5-x65x/GHSA-8x36-4hm5-x65x.json new file mode 100644 index 00000000000..fdb1fb097ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8x36-4hm5-x65x/GHSA-8x36-4hm5-x65x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x36-4hm5-x65x", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0908" + ], + "details": "PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25557.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0908" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-99rw-q85c-42h7/GHSA-99rw-q85c-42h7.json b/advisories/unreviewed/2025/02/GHSA-99rw-q85c-42h7/GHSA-99rw-q85c-42h7.json new file mode 100644 index 00000000000..e3d3c22e3a6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-99rw-q85c-42h7/GHSA-99rw-q85c-42h7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rw-q85c-42h7", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0902" + ], + "details": "PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25405.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0902" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9jmj-63mp-54pw/GHSA-9jmj-63mp-54pw.json b/advisories/unreviewed/2025/02/GHSA-9jmj-63mp-54pw/GHSA-9jmj-63mp-54pw.json new file mode 100644 index 00000000000..edc290f3556 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9jmj-63mp-54pw/GHSA-9jmj-63mp-54pw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jmj-63mp-54pw", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2024-12548" + ], + "details": "Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JP2 files.The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25564.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12548" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1680" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f477-2qwf-rv4g/GHSA-f477-2qwf-rv4g.json b/advisories/unreviewed/2025/02/GHSA-f477-2qwf-rv4g/GHSA-f477-2qwf-rv4g.json new file mode 100644 index 00000000000..ec4334dd981 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f477-2qwf-rv4g/GHSA-f477-2qwf-rv4g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f477-2qwf-rv4g", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0904" + ], + "details": "PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25422.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0904" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f8qh-8jm6-2p94/GHSA-f8qh-8jm6-2p94.json b/advisories/unreviewed/2025/02/GHSA-f8qh-8jm6-2p94/GHSA-f8qh-8jm6-2p94.json new file mode 100644 index 00000000000..899bbb9d179 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f8qh-8jm6-2p94/GHSA-f8qh-8jm6-2p94.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8qh-8jm6-2p94", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2025-25530" + ], + "details": "Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25530" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/570a765f6812b8c53d35f623ee701b19" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json b/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json new file mode 100644 index 00000000000..b12a5f23a6c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq6v-7fwh-v7j7", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0903" + ], + "details": "PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25421.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0903" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fw98-qx57-q7pf/GHSA-fw98-qx57-q7pf.json b/advisories/unreviewed/2025/02/GHSA-fw98-qx57-q7pf/GHSA-fw98-qx57-q7pf.json new file mode 100644 index 00000000000..7ab008f6daf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fw98-qx57-q7pf/GHSA-fw98-qx57-q7pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw98-qx57-q7pf", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0907" + ], + "details": "PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25435.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0907" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g496-2h33-mpvw/GHSA-g496-2h33-mpvw.json b/advisories/unreviewed/2025/02/GHSA-g496-2h33-mpvw/GHSA-g496-2h33-mpvw.json new file mode 100644 index 00000000000..6171d0d4123 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g496-2h33-mpvw/GHSA-g496-2h33-mpvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g496-2h33-mpvw", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2024-21924" + ], + "details": "SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21924" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7028.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g6fx-m6jq-g8fj/GHSA-g6fx-m6jq-g8fj.json b/advisories/unreviewed/2025/02/GHSA-g6fx-m6jq-g8fj/GHSA-g6fx-m6jq-g8fj.json new file mode 100644 index 00000000000..6d4a874e2cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g6fx-m6jq-g8fj/GHSA-g6fx-m6jq-g8fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6fx-m6jq-g8fj", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2023-31360" + ], + "details": "Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31360" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9012.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gg96-8hgf-g3hr/GHSA-gg96-8hgf-g3hr.json b/advisories/unreviewed/2025/02/GHSA-gg96-8hgf-g3hr/GHSA-gg96-8hgf-g3hr.json new file mode 100644 index 00000000000..f50e9f0a52e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gg96-8hgf-g3hr/GHSA-gg96-8hgf-g3hr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg96-8hgf-g3hr", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2025-25523" + ], + "details": "Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25523" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/cb190038c9402c9f89681a0e116996f6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gxv5-f49x-7hp5/GHSA-gxv5-f49x-7hp5.json b/advisories/unreviewed/2025/02/GHSA-gxv5-f49x-7hp5/GHSA-gxv5-f49x-7hp5.json new file mode 100644 index 00000000000..a4329189457 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gxv5-f49x-7hp5/GHSA-gxv5-f49x-7hp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxv5-f49x-7hp5", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0899" + ], + "details": "PDF-XChange Editor AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25349.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0899" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hf56-943j-3hp3/GHSA-hf56-943j-3hp3.json b/advisories/unreviewed/2025/02/GHSA-hf56-943j-3hp3/GHSA-hf56-943j-3hp3.json new file mode 100644 index 00000000000..d564eb52258 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hf56-943j-3hp3/GHSA-hf56-943j-3hp3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf56-943j-3hp3", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-25522" + ], + "details": "Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25522" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/f2365f4f6d18b2b4518ee20d5c091e1b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j4w5-fp7w-rwm7/GHSA-j4w5-fp7w-rwm7.json b/advisories/unreviewed/2025/02/GHSA-j4w5-fp7w-rwm7/GHSA-j4w5-fp7w-rwm7.json new file mode 100644 index 00000000000..3392c27826d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j4w5-fp7w-rwm7/GHSA-j4w5-fp7w-rwm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4w5-fp7w-rwm7", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2024-12833" + ], + "details": "Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability.\n\nThe specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12833" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1736" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m2vr-44vr-52pj/GHSA-m2vr-44vr-52pj.json b/advisories/unreviewed/2025/02/GHSA-m2vr-44vr-52pj/GHSA-m2vr-44vr-52pj.json new file mode 100644 index 00000000000..e8547a1ee33 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m2vr-44vr-52pj/GHSA-m2vr-44vr-52pj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2vr-44vr-52pj", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2024-12550" + ], + "details": "Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25566.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12550" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m78v-p3pw-4h65/GHSA-m78v-p3pw-4h65.json b/advisories/unreviewed/2025/02/GHSA-m78v-p3pw-4h65/GHSA-m78v-p3pw-4h65.json new file mode 100644 index 00000000000..361f116db32 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m78v-p3pw-4h65/GHSA-m78v-p3pw-4h65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m78v-p3pw-4h65", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2024-21925" + ], + "details": "Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21925" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7027.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mgg2-v3h3-2m84/GHSA-mgg2-v3h3-2m84.json b/advisories/unreviewed/2025/02/GHSA-mgg2-v3h3-2m84/GHSA-mgg2-v3h3-2m84.json new file mode 100644 index 00000000000..0211e050461 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mgg2-v3h3-2m84/GHSA-mgg2-v3h3-2m84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgg2-v3h3-2m84", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2024-12551" + ], + "details": "Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25567.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12551" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1677" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mjjg-jgrj-9453/GHSA-mjjg-jgrj-9453.json b/advisories/unreviewed/2025/02/GHSA-mjjg-jgrj-9453/GHSA-mjjg-jgrj-9453.json new file mode 100644 index 00000000000..af3d7d4d4a4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mjjg-jgrj-9453/GHSA-mjjg-jgrj-9453.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjjg-jgrj-9453", + "modified": "2025-02-11T21:32:06Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2022-35202" + ], + "details": "A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystore is protected with a low-complexity, auto-generated password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35202" + }, + { + "type": "WEB", + "url": "https://developer.sitevision.se/archives/release-notes/release-notes/2022-05-06-release-notes-sitevision-10.3" + }, + { + "type": "WEB", + "url": "https://www.shelltrail.com/research/how-auto-generated-passwords-in-sitevision-leads-to-signing-key-leakage-cve-2022-35202" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p3w4-g6w7-3v89/GHSA-p3w4-g6w7-3v89.json b/advisories/unreviewed/2025/02/GHSA-p3w4-g6w7-3v89/GHSA-p3w4-g6w7-3v89.json new file mode 100644 index 00000000000..996f114ef38 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p3w4-g6w7-3v89/GHSA-p3w4-g6w7-3v89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3w4-g6w7-3v89", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:06Z", + "aliases": [ + "CVE-2024-12547" + ], + "details": "Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JPF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25560.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12547" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1681" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pjg6-r723-9cv2/GHSA-pjg6-r723-9cv2.json b/advisories/unreviewed/2025/02/GHSA-pjg6-r723-9cv2/GHSA-pjg6-r723-9cv2.json new file mode 100644 index 00000000000..81220e95c4d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pjg6-r723-9cv2/GHSA-pjg6-r723-9cv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjg6-r723-9cv2", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2024-0179" + ], + "details": "SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0179" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7027.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qgr4-x6rm-5fpg/GHSA-qgr4-x6rm-5fpg.json b/advisories/unreviewed/2025/02/GHSA-qgr4-x6rm-5fpg/GHSA-qgr4-x6rm-5fpg.json new file mode 100644 index 00000000000..3cfdbe2374a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qgr4-x6rm-5fpg/GHSA-qgr4-x6rm-5fpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgr4-x6rm-5fpg", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2024-21966" + ], + "details": "A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21966" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9010.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qvrw-24w7-q9x7/GHSA-qvrw-24w7-q9x7.json b/advisories/unreviewed/2025/02/GHSA-qvrw-24w7-q9x7/GHSA-qvrw-24w7-q9x7.json new file mode 100644 index 00000000000..737dbf879ce --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qvrw-24w7-q9x7/GHSA-qvrw-24w7-q9x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvrw-24w7-q9x7", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0906" + ], + "details": "PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25434.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0906" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r2x7-3q95-cxfw/GHSA-r2x7-3q95-cxfw.json b/advisories/unreviewed/2025/02/GHSA-r2x7-3q95-cxfw/GHSA-r2x7-3q95-cxfw.json new file mode 100644 index 00000000000..8edc14efde6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r2x7-3q95-cxfw/GHSA-r2x7-3q95-cxfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2x7-3q95-cxfw", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0901" + ], + "details": "PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25372.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0901" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vcv3-98rx-3xxp/GHSA-vcv3-98rx-3xxp.json b/advisories/unreviewed/2025/02/GHSA-vcv3-98rx-3xxp/GHSA-vcv3-98rx-3xxp.json new file mode 100644 index 00000000000..e434f3abe5e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vcv3-98rx-3xxp/GHSA-vcv3-98rx-3xxp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcv3-98rx-3xxp", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2025-25529" + ], + "details": "Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25529" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/121e150c1cc100eab2cbd8ba3b55626b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vjv3-8wrv-hh93/GHSA-vjv3-8wrv-hh93.json b/advisories/unreviewed/2025/02/GHSA-vjv3-8wrv-hh93/GHSA-vjv3-8wrv-hh93.json new file mode 100644 index 00000000000..6889f77f969 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vjv3-8wrv-hh93/GHSA-vjv3-8wrv-hh93.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjv3-8wrv-hh93", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0911" + ], + "details": "PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25957.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0911" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x2hv-hf2m-v432/GHSA-x2hv-hf2m-v432.json b/advisories/unreviewed/2025/02/GHSA-x2hv-hf2m-v432/GHSA-x2hv-hf2m-v432.json new file mode 100644 index 00000000000..0113f5d4655 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x2hv-hf2m-v432/GHSA-x2hv-hf2m-v432.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2hv-hf2m-v432", + "modified": "2025-02-11T21:32:08Z", + "published": "2025-02-11T21:32:08Z", + "aliases": [ + "CVE-2025-25525" + ], + "details": "Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25525" + }, + { + "type": "WEB", + "url": "https://gist.github.com/XiaoCurry/d797c3cce41678028ff2d20c4e12137e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x7cc-g69m-67hg/GHSA-x7cc-g69m-67hg.json b/advisories/unreviewed/2025/02/GHSA-x7cc-g69m-67hg/GHSA-x7cc-g69m-67hg.json new file mode 100644 index 00000000000..e6168d5f602 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x7cc-g69m-67hg/GHSA-x7cc-g69m-67hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7cc-g69m-67hg", + "modified": "2025-02-11T21:32:07Z", + "published": "2025-02-11T21:32:07Z", + "aliases": [ + "CVE-2025-0910" + ], + "details": "PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25748.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0910" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T20:15:35Z" + } +} \ No newline at end of file