diff --git a/advisories/unreviewed/2022/11/GHSA-4v8v-pr95-rhx7/GHSA-4v8v-pr95-rhx7.json b/advisories/unreviewed/2022/11/GHSA-4v8v-pr95-rhx7/GHSA-4v8v-pr95-rhx7.json index e04586f7629..4dbc38b5f71 100644 --- a/advisories/unreviewed/2022/11/GHSA-4v8v-pr95-rhx7/GHSA-4v8v-pr95-rhx7.json +++ b/advisories/unreviewed/2022/11/GHSA-4v8v-pr95-rhx7/GHSA-4v8v-pr95-rhx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v8v-pr95-rhx7", - "modified": "2022-12-01T18:30:47Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-11-29T00:30:18Z", "aliases": [ "CVE-2022-4128" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/5c835bb142d4" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/netdev/20220708233610.410786-2-mathew.j.martineau%40linux.intel.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/netdev/20220708233610.410786-2-mathew.j.martineau@linux.intel.com" diff --git a/advisories/unreviewed/2022/11/GHSA-6hcp-52xr-v4mv/GHSA-6hcp-52xr-v4mv.json b/advisories/unreviewed/2022/11/GHSA-6hcp-52xr-v4mv/GHSA-6hcp-52xr-v4mv.json index ab11d615139..7e399b59be4 100644 --- a/advisories/unreviewed/2022/11/GHSA-6hcp-52xr-v4mv/GHSA-6hcp-52xr-v4mv.json +++ b/advisories/unreviewed/2022/11/GHSA-6hcp-52xr-v4mv/GHSA-6hcp-52xr-v4mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hcp-52xr-v4mv", - "modified": "2022-12-01T21:30:21Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-11-29T00:30:18Z", "aliases": [ "CVE-2022-4127" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/d785a773bed966a75ca1f11d108ae1897189975b" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/d5a19c1e-9968-e22e-5917-c3139c5e7e89%40kernel.dk" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/d5a19c1e-9968-e22e-5917-c3139c5e7e89@kernel.dk" diff --git a/advisories/unreviewed/2022/11/GHSA-6hvc-j4m8-jp74/GHSA-6hvc-j4m8-jp74.json b/advisories/unreviewed/2022/11/GHSA-6hvc-j4m8-jp74/GHSA-6hvc-j4m8-jp74.json index 31b6696da72..c6ae061595a 100644 --- a/advisories/unreviewed/2022/11/GHSA-6hvc-j4m8-jp74/GHSA-6hvc-j4m8-jp74.json +++ b/advisories/unreviewed/2022/11/GHSA-6hvc-j4m8-jp74/GHSA-6hvc-j4m8-jp74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hvc-j4m8-jp74", - "modified": "2022-12-01T18:30:47Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-11-29T00:30:17Z", "aliases": [ "CVE-2022-4129" diff --git a/advisories/unreviewed/2022/11/GHSA-7m5q-w7p8-x8h4/GHSA-7m5q-w7p8-x8h4.json b/advisories/unreviewed/2022/11/GHSA-7m5q-w7p8-x8h4/GHSA-7m5q-w7p8-x8h4.json index 3b797a2945b..847aeefad5c 100644 --- a/advisories/unreviewed/2022/11/GHSA-7m5q-w7p8-x8h4/GHSA-7m5q-w7p8-x8h4.json +++ b/advisories/unreviewed/2022/11/GHSA-7m5q-w7p8-x8h4/GHSA-7m5q-w7p8-x8h4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7m5q-w7p8-x8h4", - "modified": "2022-12-02T00:30:26Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-11-29T18:30:18Z", "aliases": [ "CVE-2022-4172" @@ -27,10 +27,18 @@ "type": "WEB", "url": "https://gitlab.com/qemu-project/qemu/-/issues/1268" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/qemu-devel/20221024154233.1043347-1-lk%40c--e.de" + }, { "type": "WEB", "url": "https://lore.kernel.org/qemu-devel/20221024154233.1043347-1-lk@c--e.de" @@ -42,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-190" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-rc5v-q774-439g/GHSA-rc5v-q774-439g.json b/advisories/unreviewed/2022/11/GHSA-rc5v-q774-439g/GHSA-rc5v-q774-439g.json index bf7fb43c737..4445ef040fa 100644 --- a/advisories/unreviewed/2022/11/GHSA-rc5v-q774-439g/GHSA-rc5v-q774-439g.json +++ b/advisories/unreviewed/2022/11/GHSA-rc5v-q774-439g/GHSA-rc5v-q774-439g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc5v-q774-439g", - "modified": "2022-12-02T00:30:26Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-11-29T18:30:18Z", "aliases": [ "CVE-2022-4144" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2148506" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTVPHLLXJ65BUMFBUUZ35F3J632SLFRK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7J5IRXJYLELW7D43A75LOWRUE5EU54O" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTVPHLLXJ65BUMFBUUZ35F3J632SLFRK" diff --git a/advisories/unreviewed/2022/12/GHSA-2w6v-mpj2-44p3/GHSA-2w6v-mpj2-44p3.json b/advisories/unreviewed/2022/12/GHSA-2w6v-mpj2-44p3/GHSA-2w6v-mpj2-44p3.json index c769076d481..c05aec5a71b 100644 --- a/advisories/unreviewed/2022/12/GHSA-2w6v-mpj2-44p3/GHSA-2w6v-mpj2-44p3.json +++ b/advisories/unreviewed/2022/12/GHSA-2w6v-mpj2-44p3/GHSA-2w6v-mpj2-44p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2w6v-mpj2-44p3", - "modified": "2023-01-05T18:30:25Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T21:30:24Z", "aliases": [ "CVE-2019-13988" diff --git a/advisories/unreviewed/2022/12/GHSA-5ffr-q63g-qhpp/GHSA-5ffr-q63g-qhpp.json b/advisories/unreviewed/2022/12/GHSA-5ffr-q63g-qhpp/GHSA-5ffr-q63g-qhpp.json index 6a5347beb41..64f8fd354d9 100644 --- a/advisories/unreviewed/2022/12/GHSA-5ffr-q63g-qhpp/GHSA-5ffr-q63g-qhpp.json +++ b/advisories/unreviewed/2022/12/GHSA-5ffr-q63g-qhpp/GHSA-5ffr-q63g-qhpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5ffr-q63g-qhpp", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-25T06:30:20Z", "aliases": [ "CVE-2022-45893" diff --git a/advisories/unreviewed/2022/12/GHSA-6r4q-gfjj-jhwr/GHSA-6r4q-gfjj-jhwr.json b/advisories/unreviewed/2022/12/GHSA-6r4q-gfjj-jhwr/GHSA-6r4q-gfjj-jhwr.json index a1d62241e2a..19f85ab6338 100644 --- a/advisories/unreviewed/2022/12/GHSA-6r4q-gfjj-jhwr/GHSA-6r4q-gfjj-jhwr.json +++ b/advisories/unreviewed/2022/12/GHSA-6r4q-gfjj-jhwr/GHSA-6r4q-gfjj-jhwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r4q-gfjj-jhwr", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-25T06:30:20Z", "aliases": [ "CVE-2022-45894" diff --git a/advisories/unreviewed/2022/12/GHSA-6w9w-8g4v-j4m6/GHSA-6w9w-8g4v-j4m6.json b/advisories/unreviewed/2022/12/GHSA-6w9w-8g4v-j4m6/GHSA-6w9w-8g4v-j4m6.json index 35cc9a464c7..1adb74d9a89 100644 --- a/advisories/unreviewed/2022/12/GHSA-6w9w-8g4v-j4m6/GHSA-6w9w-8g4v-j4m6.json +++ b/advisories/unreviewed/2022/12/GHSA-6w9w-8g4v-j4m6/GHSA-6w9w-8g4v-j4m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w9w-8g4v-j4m6", - "modified": "2023-01-05T18:30:29Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T06:30:22Z", "aliases": [ "CVE-2021-43395" @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-79p4-hp34-c4rw/GHSA-79p4-hp34-c4rw.json b/advisories/unreviewed/2022/12/GHSA-79p4-hp34-c4rw/GHSA-79p4-hp34-c4rw.json index 3d26d29ec67..dc599edb00f 100644 --- a/advisories/unreviewed/2022/12/GHSA-79p4-hp34-c4rw/GHSA-79p4-hp34-c4rw.json +++ b/advisories/unreviewed/2022/12/GHSA-79p4-hp34-c4rw/GHSA-79p4-hp34-c4rw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7gq3-x8v2-qv98/GHSA-7gq3-x8v2-qv98.json b/advisories/unreviewed/2022/12/GHSA-7gq3-x8v2-qv98/GHSA-7gq3-x8v2-qv98.json index 9283a27bdc0..184fdb0d98d 100644 --- a/advisories/unreviewed/2022/12/GHSA-7gq3-x8v2-qv98/GHSA-7gq3-x8v2-qv98.json +++ b/advisories/unreviewed/2022/12/GHSA-7gq3-x8v2-qv98/GHSA-7gq3-x8v2-qv98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gq3-x8v2-qv98", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-45892" diff --git a/advisories/unreviewed/2022/12/GHSA-92hg-r7h2-589f/GHSA-92hg-r7h2-589f.json b/advisories/unreviewed/2022/12/GHSA-92hg-r7h2-589f/GHSA-92hg-r7h2-589f.json index cd34e66ae74..f572d946aad 100644 --- a/advisories/unreviewed/2022/12/GHSA-92hg-r7h2-589f/GHSA-92hg-r7h2-589f.json +++ b/advisories/unreviewed/2022/12/GHSA-92hg-r7h2-589f/GHSA-92hg-r7h2-589f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92hg-r7h2-589f", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-45890" diff --git a/advisories/unreviewed/2022/12/GHSA-9fhx-7rcp-9rfp/GHSA-9fhx-7rcp-9rfp.json b/advisories/unreviewed/2022/12/GHSA-9fhx-7rcp-9rfp/GHSA-9fhx-7rcp-9rfp.json index d5b34bc1c0b..7457bfcc72c 100644 --- a/advisories/unreviewed/2022/12/GHSA-9fhx-7rcp-9rfp/GHSA-9fhx-7rcp-9rfp.json +++ b/advisories/unreviewed/2022/12/GHSA-9fhx-7rcp-9rfp/GHSA-9fhx-7rcp-9rfp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fhx-7rcp-9rfp", - "modified": "2022-12-12T18:30:28Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-09T18:30:31Z", "aliases": [ "CVE-2022-4336" diff --git a/advisories/unreviewed/2022/12/GHSA-cmwh-95wf-h584/GHSA-cmwh-95wf-h584.json b/advisories/unreviewed/2022/12/GHSA-cmwh-95wf-h584/GHSA-cmwh-95wf-h584.json index 5b9680db921..33fc0fdc058 100644 --- a/advisories/unreviewed/2022/12/GHSA-cmwh-95wf-h584/GHSA-cmwh-95wf-h584.json +++ b/advisories/unreviewed/2022/12/GHSA-cmwh-95wf-h584/GHSA-cmwh-95wf-h584.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmwh-95wf-h584", - "modified": "2023-01-05T21:30:15Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T06:30:22Z", "aliases": [ "CVE-2021-45466" diff --git a/advisories/unreviewed/2022/12/GHSA-gjgw-rx73-rvp5/GHSA-gjgw-rx73-rvp5.json b/advisories/unreviewed/2022/12/GHSA-gjgw-rx73-rvp5/GHSA-gjgw-rx73-rvp5.json index 27becc58ad1..d1165252d0d 100644 --- a/advisories/unreviewed/2022/12/GHSA-gjgw-rx73-rvp5/GHSA-gjgw-rx73-rvp5.json +++ b/advisories/unreviewed/2022/12/GHSA-gjgw-rx73-rvp5/GHSA-gjgw-rx73-rvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjgw-rx73-rvp5", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-25T06:30:20Z", "aliases": [ "CVE-2022-45895" diff --git a/advisories/unreviewed/2022/12/GHSA-h98c-hq83-wq3c/GHSA-h98c-hq83-wq3c.json b/advisories/unreviewed/2022/12/GHSA-h98c-hq83-wq3c/GHSA-h98c-hq83-wq3c.json index a7997fe5b7f..627e763390d 100644 --- a/advisories/unreviewed/2022/12/GHSA-h98c-hq83-wq3c/GHSA-h98c-hq83-wq3c.json +++ b/advisories/unreviewed/2022/12/GHSA-h98c-hq83-wq3c/GHSA-h98c-hq83-wq3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h98c-hq83-wq3c", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-45889" diff --git a/advisories/unreviewed/2022/12/GHSA-hqqr-2352-48q8/GHSA-hqqr-2352-48q8.json b/advisories/unreviewed/2022/12/GHSA-hqqr-2352-48q8/GHSA-hqqr-2352-48q8.json index dcbea8879ad..4706fd1fb7b 100644 --- a/advisories/unreviewed/2022/12/GHSA-hqqr-2352-48q8/GHSA-hqqr-2352-48q8.json +++ b/advisories/unreviewed/2022/12/GHSA-hqqr-2352-48q8/GHSA-hqqr-2352-48q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hqqr-2352-48q8", - "modified": "2023-01-06T03:30:29Z", + "modified": "2025-04-14T18:31:44Z", "published": "2022-12-27T00:30:27Z", "aliases": [ "CVE-2019-11851" diff --git a/advisories/unreviewed/2022/12/GHSA-j7vr-c84p-54jm/GHSA-j7vr-c84p-54jm.json b/advisories/unreviewed/2022/12/GHSA-j7vr-c84p-54jm/GHSA-j7vr-c84p-54jm.json index 1fd71f64ad4..947877a0440 100644 --- a/advisories/unreviewed/2022/12/GHSA-j7vr-c84p-54jm/GHSA-j7vr-c84p-54jm.json +++ b/advisories/unreviewed/2022/12/GHSA-j7vr-c84p-54jm/GHSA-j7vr-c84p-54jm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7vr-c84p-54jm", - "modified": "2022-12-19T15:30:29Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-09T21:30:47Z", "aliases": [ "CVE-2022-4390" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://www.synacktiv.com/en/publications/cool-vulns-dont-live-long-netgear-and-pwn2own.html" }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2022-36%2C" + }, { "type": "WEB", "url": "https://www.tenable.com/security/research/tra-2022-36," diff --git a/advisories/unreviewed/2022/12/GHSA-jj68-7h34-v267/GHSA-jj68-7h34-v267.json b/advisories/unreviewed/2022/12/GHSA-jj68-7h34-v267/GHSA-jj68-7h34-v267.json index a29d0e774f6..2e9748b9a3e 100644 --- a/advisories/unreviewed/2022/12/GHSA-jj68-7h34-v267/GHSA-jj68-7h34-v267.json +++ b/advisories/unreviewed/2022/12/GHSA-jj68-7h34-v267/GHSA-jj68-7h34-v267.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj68-7h34-v267", - "modified": "2023-01-05T18:30:30Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T21:30:24Z", "aliases": [ "CVE-2019-9011" diff --git a/advisories/unreviewed/2022/12/GHSA-m55w-4rm6-mmm8/GHSA-m55w-4rm6-mmm8.json b/advisories/unreviewed/2022/12/GHSA-m55w-4rm6-mmm8/GHSA-m55w-4rm6-mmm8.json index b8b102c04a4..75173e66c72 100644 --- a/advisories/unreviewed/2022/12/GHSA-m55w-4rm6-mmm8/GHSA-m55w-4rm6-mmm8.json +++ b/advisories/unreviewed/2022/12/GHSA-m55w-4rm6-mmm8/GHSA-m55w-4rm6-mmm8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m55w-4rm6-mmm8", - "modified": "2023-01-05T18:30:29Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T21:30:24Z", "aliases": [ "CVE-2020-11101" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json b/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json index 74655bbaacc..c48d9fafec8 100644 --- a/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json +++ b/advisories/unreviewed/2022/12/GHSA-w4mm-gfhc-2p52/GHSA-w4mm-gfhc-2p52.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-524", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-xmxc-2jc7-w66m/GHSA-xmxc-2jc7-w66m.json b/advisories/unreviewed/2022/12/GHSA-xmxc-2jc7-w66m/GHSA-xmxc-2jc7-w66m.json index 5166171564c..03e46ec165f 100644 --- a/advisories/unreviewed/2022/12/GHSA-xmxc-2jc7-w66m/GHSA-xmxc-2jc7-w66m.json +++ b/advisories/unreviewed/2022/12/GHSA-xmxc-2jc7-w66m/GHSA-xmxc-2jc7-w66m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmxc-2jc7-w66m", - "modified": "2023-01-05T18:30:30Z", + "modified": "2025-04-14T18:31:42Z", "published": "2022-12-26T21:30:24Z", "aliases": [ "CVE-2020-12067" diff --git a/advisories/unreviewed/2022/12/GHSA-xqr7-fvpx-w934/GHSA-xqr7-fvpx-w934.json b/advisories/unreviewed/2022/12/GHSA-xqr7-fvpx-w934/GHSA-xqr7-fvpx-w934.json index 04aec61a9d3..0d87a10cb41 100644 --- a/advisories/unreviewed/2022/12/GHSA-xqr7-fvpx-w934/GHSA-xqr7-fvpx-w934.json +++ b/advisories/unreviewed/2022/12/GHSA-xqr7-fvpx-w934/GHSA-xqr7-fvpx-w934.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-xv49-pvqx-8xr6/GHSA-xv49-pvqx-8xr6.json b/advisories/unreviewed/2022/12/GHSA-xv49-pvqx-8xr6/GHSA-xv49-pvqx-8xr6.json index a9ef9a67ac1..ab085ff2fb7 100644 --- a/advisories/unreviewed/2022/12/GHSA-xv49-pvqx-8xr6/GHSA-xv49-pvqx-8xr6.json +++ b/advisories/unreviewed/2022/12/GHSA-xv49-pvqx-8xr6/GHSA-xv49-pvqx-8xr6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv49-pvqx-8xr6", - "modified": "2022-12-07T15:30:29Z", + "modified": "2025-04-14T18:31:41Z", "published": "2022-12-05T18:30:41Z", "aliases": [ "CVE-2022-4269" diff --git a/advisories/unreviewed/2023/02/GHSA-f9v2-3453-rj68/GHSA-f9v2-3453-rj68.json b/advisories/unreviewed/2023/02/GHSA-f9v2-3453-rj68/GHSA-f9v2-3453-rj68.json index 2abd1fa36cb..a1209cd5c65 100644 --- a/advisories/unreviewed/2023/02/GHSA-f9v2-3453-rj68/GHSA-f9v2-3453-rj68.json +++ b/advisories/unreviewed/2023/02/GHSA-f9v2-3453-rj68/GHSA-f9v2-3453-rj68.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-23" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-v5cp-f652-48w9/GHSA-v5cp-f652-48w9.json b/advisories/unreviewed/2023/02/GHSA-v5cp-f652-48w9/GHSA-v5cp-f652-48w9.json index c7da443e534..81b1fb615ee 100644 --- a/advisories/unreviewed/2023/02/GHSA-v5cp-f652-48w9/GHSA-v5cp-f652-48w9.json +++ b/advisories/unreviewed/2023/02/GHSA-v5cp-f652-48w9/GHSA-v5cp-f652-48w9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-23" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json b/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json index 6caade46953..8c2b228f980 100644 --- a/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json +++ b/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6c2r-874p-4fv5", - "modified": "2024-12-06T21:30:38Z", + "modified": "2025-04-14T18:31:48Z", "published": "2024-12-05T18:31:03Z", "aliases": [ "CVE-2024-11155" diff --git a/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json b/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json index 34acc3c7117..34154fa428c 100644 --- a/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json +++ b/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json b/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json index 357cadc28e6..cce1bf8c65b 100644 --- a/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json +++ b/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fxx-w44v-7wmw", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-28395" ], "details": "D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T14:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3mp4-2w7h-6m56/GHSA-3mp4-2w7h-6m56.json b/advisories/unreviewed/2025/04/GHSA-3mp4-2w7h-6m56/GHSA-3mp4-2w7h-6m56.json new file mode 100644 index 00000000000..b09d7b5df76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3mp4-2w7h-6m56/GHSA-3mp4-2w7h-6m56.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mp4-2w7h-6m56", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-29720" + ], + "details": "Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29720" + }, + { + "type": "WEB", + "url": "https://github.com/langgenius/dify/issues/15185" + }, + { + "type": "WEB", + "url": "https://dify.ai" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json new file mode 100644 index 00000000000..1cc239ce444 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46h9-fw88-xg28", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-22371" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker to Bypass Authentication and execute arbitrary SQL commands. This issue at least affects BASEC for the date of 14 Dec 2021 onwards. It is very likely that this vulnerability has been present in the solution before that.\n\nAs of the date of this CVE record, there has been no patch", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22371" + }, + { + "type": "WEB", + "url": "https://basec.sicomm.net/login" + }, + { + "type": "WEB", + "url": "https://cisrt.divd.nl/CVE-2025-22371" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4r38-2fwm-9vj5/GHSA-4r38-2fwm-9vj5.json b/advisories/unreviewed/2025/04/GHSA-4r38-2fwm-9vj5/GHSA-4r38-2fwm-9vj5.json new file mode 100644 index 00000000000..79def8a776c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4r38-2fwm-9vj5/GHSA-4r38-2fwm-9vj5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r38-2fwm-9vj5", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-2572" + ], + "details": "In WhatsUp Gold versions released before 2024.0.3, a \n\ndatabase manipulation \n\nvulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2572" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json b/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json index 3203f601f26..049590b51bb 100644 --- a/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json +++ b/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xfw-qg2p-394c", - "modified": "2025-04-01T21:31:28Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T21:31:28Z", "aliases": [ "CVE-2025-26055" ], "details": "An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T19:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json b/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json index c0ed5b1f8c0..8dae85a3482 100644 --- a/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json +++ b/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8ff6-v3j2-x264", - "modified": "2025-04-01T18:30:55Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T18:30:55Z", "aliases": [ "CVE-2025-29208" ], "details": "CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T18:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json b/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json new file mode 100644 index 00000000000..1fc40ee9c08 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c7gj-f6xr-p7wp/GHSA-c7gj-f6xr-p7wp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7gj-f6xr-p7wp", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-3585" + ], + "details": "A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3585" + }, + { + "type": "WEB", + "url": "https://github.com/Bae-ke/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304641" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304641" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549981" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json b/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json index 39762c5ae66..0bda51ebe44 100644 --- a/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json +++ b/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg5p-ff4v-v3c7", - "modified": "2025-04-01T21:31:28Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T21:31:28Z", "aliases": [ "CVE-2025-26056" ], "details": "A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module \"MTR\" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T19:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g2ph-wvc2-ph4v/GHSA-g2ph-wvc2-ph4v.json b/advisories/unreviewed/2025/04/GHSA-g2ph-wvc2-ph4v/GHSA-g2ph-wvc2-ph4v.json new file mode 100644 index 00000000000..6eb8bcfd44e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2ph-wvc2-ph4v/GHSA-g2ph-wvc2-ph4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2ph-wvc2-ph4v", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-3277" + ], + "details": "An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3277" + }, + { + "type": "WEB", + "url": "https://sqlite.org/src/info/498e3f1cf57f164f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json b/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json index 98c625f9340..29e453ca66e 100644 --- a/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json +++ b/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7gr-m9c4-cg88", - "modified": "2025-04-01T18:30:55Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T18:30:55Z", "aliases": [ "CVE-2025-27829" ], "details": "An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T17:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json b/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json new file mode 100644 index 00000000000..80b9ad0bbc8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggp5-cmc4-x9q4", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-22373" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet BASEC on SaaS allows Reflected XSS, XSS Through HTTP Query Strings, Rendering of Arbitrary HTML and alternation of CSS Styles\nThis issue affects BASEC: from 14 Dec 2021.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22373" + }, + { + "type": "WEB", + "url": "https://basec.sicomm.net/login" + }, + { + "type": "WEB", + "url": "https://cisrt.divd.nl/CVE-2025-22373" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h236-32wj-mg7x/GHSA-h236-32wj-mg7x.json b/advisories/unreviewed/2025/04/GHSA-h236-32wj-mg7x/GHSA-h236-32wj-mg7x.json index a47912ee5d6..f4a0c4d2a58 100644 --- a/advisories/unreviewed/2025/04/GHSA-h236-32wj-mg7x/GHSA-h236-32wj-mg7x.json +++ b/advisories/unreviewed/2025/04/GHSA-h236-32wj-mg7x/GHSA-h236-32wj-mg7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h236-32wj-mg7x", - "modified": "2025-04-05T21:30:22Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-05T21:30:22Z", "aliases": [ "CVE-2024-56370" ], "details": "Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.\n\nSpecifically Net::Xero uses the Data::Random library which specifically states that it is \"Useful mostly for test programs\". Data::Random uses the rand() function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-05T19:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json b/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json index 1e33b74988f..9ee2a3a1333 100644 --- a/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json +++ b/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfhj-x3c5-7mgv", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-14T18:31:48Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-28398" ], "details": "D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T14:15:33Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jg9p-qrj8-5jw6/GHSA-jg9p-qrj8-5jw6.json b/advisories/unreviewed/2025/04/GHSA-jg9p-qrj8-5jw6/GHSA-jg9p-qrj8-5jw6.json new file mode 100644 index 00000000000..95605cb54f1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jg9p-qrj8-5jw6/GHSA-jg9p-qrj8-5jw6.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg9p-qrj8-5jw6", + "modified": "2025-04-14T18:31:48Z", + "published": "2025-04-14T18:31:48Z", + "aliases": [ + "CVE-2022-49276" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: fix memory leak in jffs2_scan_medium\n\nIf an error is returned in jffs2_scan_eraseblock() and some memory\nhas been added to the jffs2_summary *s, we can observe the following\nkmemleak report:\n\n--------------------------------------------\nunreferenced object 0xffff88812b889c40 (size 64):\n comm \"mount\", pid 692, jiffies 4294838325 (age 34.288s)\n hex dump (first 32 bytes):\n 40 48 b5 14 81 88 ff ff 01 e0 31 00 00 00 50 00 @H........1...P.\n 00 00 01 00 00 00 01 00 00 00 02 00 00 00 09 08 ................\n backtrace:\n [] __kmalloc+0x613/0x910\n [] jffs2_sum_add_dirent_mem+0x5c/0xa0\n [] jffs2_scan_medium.cold+0x36e5/0x4794\n [] jffs2_do_mount_fs.cold+0xa7/0x2267\n [] jffs2_do_fill_super+0x383/0xc30\n [] jffs2_fill_super+0x2ea/0x4c0\n [] mtd_get_sb+0x254/0x400\n [] mtd_get_sb_by_nr+0x4f/0xd0\n [] get_tree_mtd+0x498/0x840\n [] jffs2_get_tree+0x25/0x30\n [] vfs_get_tree+0x8d/0x2e0\n [] path_mount+0x50f/0x1e50\n [] do_mount+0x107/0x130\n [] __se_sys_mount+0x1c5/0x2f0\n [] __x64_sys_mount+0xc7/0x160\n [] do_syscall_64+0x45/0x70\nunreferenced object 0xffff888114b54840 (size 32):\n comm \"mount\", pid 692, jiffies 4294838325 (age 34.288s)\n hex dump (first 32 bytes):\n c0 75 b5 14 81 88 ff ff 02 e0 02 00 00 00 02 00 .u..............\n 00 00 84 00 00 00 44 00 00 00 6b 6b 6b 6b 6b a5 ......D...kkkkk.\n backtrace:\n [] kmem_cache_alloc_trace+0x584/0x880\n [] jffs2_sum_add_inode_mem+0x54/0x90\n [] jffs2_scan_medium.cold+0x4481/0x4794\n [...]\nunreferenced object 0xffff888114b57280 (size 32):\n comm \"mount\", pid 692, jiffies 4294838393 (age 34.357s)\n hex dump (first 32 bytes):\n 10 d5 6c 11 81 88 ff ff 08 e0 05 00 00 00 01 00 ..l.............\n 00 00 38 02 00 00 28 00 00 00 6b 6b 6b 6b 6b a5 ..8...(...kkkkk.\n backtrace:\n [] kmem_cache_alloc_trace+0x584/0x880\n [] jffs2_sum_add_xattr_mem+0x54/0x90\n [] jffs2_scan_medium.cold+0x298c/0x4794\n [...]\nunreferenced object 0xffff8881116cd510 (size 16):\n comm \"mount\", pid 692, jiffies 4294838395 (age 34.355s)\n hex dump (first 16 bytes):\n 00 00 00 00 00 00 00 00 09 e0 60 02 00 00 6b a5 ..........`...k.\n backtrace:\n [] kmem_cache_alloc_trace+0x584/0x880\n [] jffs2_sum_add_xref_mem+0x54/0x90\n [] jffs2_scan_medium.cold+0x3a20/0x4794\n [...]\n--------------------------------------------\n\nTherefore, we should call jffs2_sum_reset_collected(s) on exit to\nrelease the memory added in s. In addition, a new tag \"out_buf\" is\nadded to prevent the NULL pointer reference caused by s being NULL.\n(thanks to Zhang Yi for this analysis)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49276" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/455f4a23490bfcbedc8e5c245c463a59b19e5ddd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51dbb5e36d59f62e34d462b801c1068248149cfe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52ba0ab4f0a606f02a6163493378989faa1ec10a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82462324bf35b6b553400af1c1aa265069cee28f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b0c69182f09b70779817af4dcf89780955d5c4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cdd3128874f5fe759e2c4e1360ab7fb96a8d1df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b26bbc0c122cad038831f226a4cb4de702225e16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b36bccb04e14cc0c1e2d0e92d477fe220314fad6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e711913463af916d777a4873068f415f1fe2ad33" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json b/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json new file mode 100644 index 00000000000..56a56f938d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8mv-f94r-2px4", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-22372" + ], + "details": "Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery.\nPasswords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily.\n\nThis issue affects BASEC: from 14 Dec 2021.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22372" + }, + { + "type": "WEB", + "url": "https://basec.sicomm.net/login" + }, + { + "type": "WEB", + "url": "https://cisrt.divd.nl/CVE-2025-22372" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qq2h-m2hj-hrff/GHSA-qq2h-m2hj-hrff.json b/advisories/unreviewed/2025/04/GHSA-qq2h-m2hj-hrff/GHSA-qq2h-m2hj-hrff.json new file mode 100644 index 00000000000..2ba061b1eeb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qq2h-m2hj-hrff/GHSA-qq2h-m2hj-hrff.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq2h-m2hj-hrff", + "modified": "2025-04-14T18:31:49Z", + "published": "2025-04-14T18:31:49Z", + "aliases": [ + "CVE-2025-32931" + ], + "details": "DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32931" + }, + { + "type": "WEB", + "url": "https://github.com/lishihihi/voyager-issue-report" + }, + { + "type": "WEB", + "url": "https://github.com/thedevdojo/voyager/blob/1.8/docs/core-concepts/compass.md" + }, + { + "type": "WEB", + "url": "https://github.com/thedevdojo/voyager/blob/7e7e0f4f0e115d2d9e0481a86153a1ceff194c00/resources/views/compass/includes/commands.blade.php#L11-L16" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-14T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfv9-hghg-chfq/GHSA-rfv9-hghg-chfq.json b/advisories/unreviewed/2025/04/GHSA-rfv9-hghg-chfq/GHSA-rfv9-hghg-chfq.json new file mode 100644 index 00000000000..a68bc432427 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfv9-hghg-chfq/GHSA-rfv9-hghg-chfq.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfv9-hghg-chfq", + "modified": "2025-04-14T18:31:48Z", + "published": "2025-04-14T18:31:48Z", + "aliases": [ + "CVE-2022-49277" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: fix memory leak in jffs2_do_mount_fs\n\nIf jffs2_build_filesystem() in jffs2_do_mount_fs() returns an error,\nwe can observe the following kmemleak report:\n\n--------------------------------------------\nunreferenced object 0xffff88811b25a640 (size 64):\n comm \"mount\", pid 691, jiffies 4294957728 (age 71.952s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] kmem_cache_alloc_trace+0x584/0x880\n [] jffs2_sum_init+0x86/0x130\n [] jffs2_do_mount_fs+0x798/0xac0\n [] jffs2_do_fill_super+0x383/0xc30\n [] jffs2_fill_super+0x2ea/0x4c0\n [...]\nunreferenced object 0xffff88812c760000 (size 65536):\n comm \"mount\", pid 691, jiffies 4294957728 (age 71.952s)\n hex dump (first 32 bytes):\n bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................\n bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb ................\n backtrace:\n [] __kmalloc+0x6b9/0x910\n [] jffs2_sum_init+0xd7/0x130\n [] jffs2_do_mount_fs+0x798/0xac0\n [] jffs2_do_fill_super+0x383/0xc30\n [] jffs2_fill_super+0x2ea/0x4c0\n [...]\n--------------------------------------------\n\nThis is because the resources allocated in jffs2_sum_init() are not\nreleased. Call jffs2_sum_exit() to release these resources to solve\nthe problem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49277" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0978e9af4559a171ac7a74a1b3ef21804b0a0fa9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a9d8184458562e6bf2f40d0e677fc85e2dd3834" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4392e8aeebc5a4f8073620bccba7de1b1f6d7c88" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f34310d1376ca5b2ed798258def2c2ab3cc6699" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/607d3aab7349f18e0d9dba4100d09d16fe27caca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a0f6610c7daedd2eace430beeb08a8b7ac80699" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c94128470e6fe53d9bd9d16d2d3271813f9d37af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d051cef784de4d54835f6b6836d98a8f6935772c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbe0d0521eaa6a3d235517319266c539bb5c5112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rq3p-6qpw-48cx/GHSA-rq3p-6qpw-48cx.json b/advisories/unreviewed/2025/04/GHSA-rq3p-6qpw-48cx/GHSA-rq3p-6qpw-48cx.json new file mode 100644 index 00000000000..f82fb71dd3d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rq3p-6qpw-48cx/GHSA-rq3p-6qpw-48cx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq3p-6qpw-48cx", + "modified": "2025-04-14T18:31:48Z", + "published": "2025-04-14T18:31:48Z", + "aliases": [ + "CVE-2022-49273" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: pl031: fix rtc features null pointer dereference\n\nWhen there is no interrupt line, rtc alarm feature is disabled.\n\nThe clearing of the alarm feature bit was being done prior to allocations\nof ldata->rtc device, resulting in a null pointer dereference.\n\nClear RTC_FEATURE_ALARM after the rtc device is allocated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49273" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b915703964f7e636961df04c540261dc55c6c70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd2722e411e8ab7e5ae41102f6925fa13dffdac5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d274ce4a3dfd0b9a292667535578359b865765cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea6af39f3da50c86367a71eb3cc674ade3ed244c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqx9-j8xg-xg6x/GHSA-rqx9-j8xg-xg6x.json b/advisories/unreviewed/2025/04/GHSA-rqx9-j8xg-xg6x/GHSA-rqx9-j8xg-xg6x.json new file mode 100644 index 00000000000..bdf4b0a07c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rqx9-j8xg-xg6x/GHSA-rqx9-j8xg-xg6x.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqx9-j8xg-xg6x", + "modified": "2025-04-14T18:31:47Z", + "published": "2025-04-14T18:31:47Z", + "aliases": [ + "CVE-2023-0449" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0449" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:18:08Z" + } +} \ No newline at end of file