From ac1e3c7c9941ded2b23c00afc5a9146a7587596f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Apr 2025 00:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rhpc-22qh-75f4.json | 15 +++-- .../GHSA-24rg-x9r9-x3f6.json | 37 +++++++++++ .../GHSA-28ch-w3c2-xg68.json | 41 ++++++++++++ .../GHSA-2c76-7cf4-w44v.json | 37 +++++++++++ .../GHSA-2f88-2r9h-hx4p.json | 37 +++++++++++ .../GHSA-2h82-w6j2-mfx6.json | 33 ++++++++++ .../GHSA-2qph-q8xw-gv7q.json | 31 +++++++++ .../GHSA-2w35-685f-3mpc.json | 37 +++++++++++ .../GHSA-2xcc-3vq7-mvjp.json | 29 +++++++++ .../GHSA-3286-4p8w-f9gp.json | 33 ++++++++++ .../GHSA-3324-7ggx-p2gq.json | 29 +++++++++ .../GHSA-34w4-3qr3-m637.json | 31 +++++++++ .../GHSA-36vv-q5jv-94cj.json | 31 +++++++++ .../GHSA-378r-2hmj-3r7x.json | 41 ++++++++++++ .../GHSA-387v-qw2x-rwg8.json | 37 +++++++++++ .../GHSA-38rr-jcx6-prmh.json | 45 +++++++++++++ .../GHSA-39g6-x4x8-5jcm.json | 31 +++++++++ .../GHSA-3cxf-3h44-8cxr.json | 37 +++++++++++ .../GHSA-3g2g-jmh9-pfcp.json | 37 +++++++++++ .../GHSA-3h6v-4pff-pgf4.json | 37 +++++++++++ .../GHSA-469w-q8hj-3hr3.json | 37 +++++++++++ .../GHSA-46jc-hp5h-cgrh.json | 29 +++++++++ .../GHSA-4f8q-mwgc-3mwc.json | 31 +++++++++ .../GHSA-4r7q-g5mr-63x8.json | 29 +++++++++ .../GHSA-4rpr-22rq-29fr.json | 29 +++++++++ .../GHSA-4rxj-2g88-h4fp.json | 33 ++++++++++ .../GHSA-4x4g-h2vr-367c.json | 33 ++++++++++ .../GHSA-52gw-v8vv-qrwr.json | 37 +++++++++++ .../GHSA-56rf-vwj9-f3p7.json | 37 +++++++++++ .../GHSA-56x3-c3f3-5345.json | 37 +++++++++++ .../GHSA-57p2-mgfw-2w94.json | 37 +++++++++++ .../GHSA-5945-5998-27h6.json | 56 ++++++++++++++++ .../GHSA-59wj-h89p-37x9.json | 37 +++++++++++ .../GHSA-5cgr-6hjx-88v5.json | 37 +++++++++++ .../GHSA-5j8h-9jcx-3px3.json | 29 +++++++++ .../GHSA-5jpr-cwj3-v74m.json | 45 +++++++++++++ .../GHSA-5qvg-xp2f-fp45.json | 45 +++++++++++++ .../GHSA-5r66-vgc7-2mm3.json | 31 +++++++++ .../GHSA-5wrm-m47r-jv84.json | 29 +++++++++ .../GHSA-62f2-58pp-q2wg.json | 49 ++++++++++++++ .../GHSA-6chf-hhqf-749c.json | 31 +++++++++ .../GHSA-6jg2-8qrr-fq2q.json | 56 ++++++++++++++++ .../GHSA-6p7v-mm3j-hhhh.json | 37 +++++++++++ .../GHSA-6p9f-6933-82rq.json | 64 +++++++++++++++++++ .../GHSA-6w5j-j56x-jmm3.json | 29 +++++++++ .../GHSA-6x3m-r98v-pgc4.json | 29 +++++++++ .../GHSA-7345-q82m-2h46.json | 45 +++++++++++++ .../GHSA-75p9-34jj-xrg5.json | 29 +++++++++ .../GHSA-75q7-hpjm-4cf5.json | 37 +++++++++++ .../GHSA-777h-hpfj-x7hv.json | 37 +++++++++++ .../GHSA-78fp-h4q6-qmjg.json | 29 +++++++++ .../GHSA-793h-885v-rxrh.json | 41 ++++++++++++ .../GHSA-7g9x-v864-75f3.json | 37 +++++++++++ .../GHSA-7hxq-4w6w-xgc9.json | 49 ++++++++++++++ .../GHSA-7mhw-3w3j-f4cw.json | 37 +++++++++++ .../GHSA-7mmq-w7cm-cxxj.json | 29 +++++++++ .../GHSA-7p4r-cj5f-3grm.json | 45 +++++++++++++ .../GHSA-7r6g-q2j3-vcf5.json | 36 +++++++++++ .../GHSA-7xff-8wqr-949p.json | 37 +++++++++++ .../GHSA-86h4-w859-3hhv.json | 31 +++++++++ .../GHSA-8852-5rrc-3m6q.json | 37 +++++++++++ .../GHSA-892g-82wc-7r8q.json | 29 +++++++++ .../GHSA-8h8h-4h46-6wx3.json | 49 ++++++++++++++ .../GHSA-8mq5-f87c-x4p2.json | 41 ++++++++++++ .../GHSA-8mq7-j2hp-g76j.json | 49 ++++++++++++++ .../GHSA-8q4c-gc84-4w63.json | 37 +++++++++++ .../GHSA-8r2q-865v-wm8j.json | 31 +++++++++ .../GHSA-8w29-wh58-hrm4.json | 37 +++++++++++ .../GHSA-94xq-8x25-gjrf.json | 56 ++++++++++++++++ .../GHSA-972j-fxc9-8wqp.json | 29 +++++++++ .../GHSA-9f34-hg9w-62vg.json | 49 ++++++++++++++ .../GHSA-9hjm-gm4c-vqqv.json | 53 +++++++++++++++ .../GHSA-9r28-p42w-83mg.json | 33 ++++++++++ .../GHSA-9w85-x5hg-fr66.json | 31 +++++++++ .../GHSA-c7pf-q3xj-34q3.json | 37 +++++++++++ .../GHSA-c8q6-wp7v-46r9.json | 31 +++++++++ .../GHSA-ccc9-jgj7-hxc7.json | 31 +++++++++ .../GHSA-cgpc-3qf8-7mx3.json | 37 +++++++++++ .../GHSA-cqxv-6v33-64xx.json | 37 +++++++++++ .../GHSA-cr5x-x94v-gf96.json | 41 ++++++++++++ .../GHSA-crwm-v9wf-m9pg.json | 29 +++++++++ .../GHSA-f2wv-6cwg-48rq.json | 49 ++++++++++++++ .../GHSA-f9vw-5v2f-5j5q.json | 29 +++++++++ .../GHSA-ff7g-r4f4-qg7v.json | 37 +++++++++++ .../GHSA-fhfh-9mcw-2g3q.json | 53 +++++++++++++++ .../GHSA-fpmq-p8gp-m5m2.json | 37 +++++++++++ .../GHSA-frrr-xgqj-649g.json | 53 +++++++++++++++ .../GHSA-g3r7-w9gq-5v84.json | 41 ++++++++++++ .../GHSA-g3v9-6xm2-qr9w.json | 37 +++++++++++ .../GHSA-g5m7-ph65-hj67.json | 45 +++++++++++++ .../GHSA-g632-x89p-c4m6.json | 37 +++++++++++ .../GHSA-g7xp-7fwj-m5hv.json | 37 +++++++++++ .../GHSA-g8gx-c35h-gv6w.json | 37 +++++++++++ .../GHSA-gf72-h4cp-wcm4.json | 31 +++++++++ .../GHSA-ghrr-554g-qqv5.json | 29 +++++++++ .../GHSA-gmw9-8h79-pvq5.json | 37 +++++++++++ .../GHSA-gvwv-9mwf-hg22.json | 37 +++++++++++ .../GHSA-gw73-hwr2-4qrm.json | 37 +++++++++++ .../GHSA-gwxc-74j8-c3pg.json | 37 +++++++++++ .../GHSA-h2wh-36m8-j3rp.json | 45 +++++++++++++ .../GHSA-h94m-mjfh-2g77.json | 37 +++++++++++ .../GHSA-h94q-fmqj-xgwh.json | 37 +++++++++++ .../GHSA-h9jw-2p4c-9c62.json | 56 ++++++++++++++++ .../GHSA-hc9m-f2mx-w9j7.json | 53 +++++++++++++++ .../GHSA-hf6c-fgp3-jfch.json | 31 +++++++++ .../GHSA-hvwm-h8x9-9rg5.json | 37 +++++++++++ .../GHSA-j34j-434j-r63c.json | 29 +++++++++ .../GHSA-j7j3-j385-mfpx.json | 37 +++++++++++ .../GHSA-j87v-9jp4-gw6c.json | 37 +++++++++++ .../GHSA-j8gc-8grp-vffr.json | 45 +++++++++++++ .../GHSA-jh66-rjx8-8qqc.json | 31 +++++++++ .../GHSA-jq4h-8p8p-vchg.json | 29 +++++++++ .../GHSA-jrgv-pmf9-6qg5.json | 37 +++++++++++ .../GHSA-jv6r-mj9p-9xff.json | 31 +++++++++ .../GHSA-jwpx-6c4p-q4jq.json | 31 +++++++++ .../GHSA-m47h-9h3r-rqw8.json | 41 ++++++++++++ .../GHSA-m4wj-hhwj-47qp.json | 31 +++++++++ .../GHSA-m773-p743-chvm.json | 41 ++++++++++++ .../GHSA-m8pg-77c8-3wj6.json | 33 ++++++++++ .../GHSA-m9w8-wxvp-c9gv.json | 31 +++++++++ .../GHSA-mgrm-96cw-6vxv.json | 37 +++++++++++ .../GHSA-mrh3-4hmr-qq29.json | 29 +++++++++ .../GHSA-p2wg-8h29-874v.json | 31 +++++++++ .../GHSA-p3gw-g89c-c3cq.json | 33 ++++++++++ .../GHSA-p4vm-6crq-4pg4.json | 33 ++++++++++ .../GHSA-p57m-j445-jv2j.json | 49 ++++++++++++++ .../GHSA-p7wf-qqfr-f6xp.json | 45 +++++++++++++ .../GHSA-pg82-qc3q-4772.json | 53 +++++++++++++++ .../GHSA-pph7-4r52-2m8q.json | 29 +++++++++ .../GHSA-pw3g-hp64-xmx9.json | 56 ++++++++++++++++ .../GHSA-pwjq-fx3v-8f9r.json | 31 +++++++++ .../GHSA-q3w8-9x53-fgrm.json | 53 +++++++++++++++ .../GHSA-q556-7cxr-pm34.json | 41 ++++++++++++ .../GHSA-q844-h75g-f78q.json | 41 ++++++++++++ .../GHSA-q953-x475-mh65.json | 52 +++++++++++++++ .../GHSA-qchr-8m24-7v66.json | 31 +++++++++ .../GHSA-qm2f-w2gq-vqp6.json | 53 +++++++++++++++ .../GHSA-qpj9-jpjq-jm8g.json | 37 +++++++++++ .../GHSA-qq45-cqhg-jwx5.json | 31 +++++++++ .../GHSA-qrx7-4fmv-56wc.json | 41 ++++++++++++ .../GHSA-qxhm-5vqv-9j5q.json | 33 ++++++++++ .../GHSA-r32r-4px4-7j36.json | 53 +++++++++++++++ .../GHSA-r6wp-29qw-vxr5.json | 49 ++++++++++++++ .../GHSA-rh3m-2p8j-6cf7.json | 41 ++++++++++++ .../GHSA-rhxm-r44m-4325.json | 31 +++++++++ .../GHSA-rqp3-mh44-cf98.json | 37 +++++++++++ .../GHSA-rwvj-3jx7-frmw.json | 49 ++++++++++++++ .../GHSA-rx8v-vhcf-rfq6.json | 29 +++++++++ .../GHSA-v3qr-7hm5-5r4j.json | 37 +++++++++++ .../GHSA-v7jj-vhq2-vgc8.json | 37 +++++++++++ .../GHSA-vc63-6wjr-qvp6.json | 37 +++++++++++ .../GHSA-vccw-jcwc-p44p.json | 29 +++++++++ .../GHSA-vhf9-v5pf-qmcg.json | 33 ++++++++++ .../GHSA-vhq9-x7cx-387j.json | 37 +++++++++++ .../GHSA-vjfx-mp69-qfw4.json | 29 +++++++++ .../GHSA-vjmg-6qjc-gxgh.json | 52 +++++++++++++++ .../GHSA-vm8m-rr8q-8rjw.json | 33 ++++++++++ .../GHSA-vmh7-68x6-gw3h.json | 37 +++++++++++ .../GHSA-vwcg-r7w2-v8qc.json | 33 ++++++++++ .../GHSA-vx9m-rfxq-gr74.json | 31 +++++++++ .../GHSA-whhr-6p94-vcj4.json | 53 +++++++++++++++ .../GHSA-wmw5-c4qx-m982.json | 49 ++++++++++++++ .../GHSA-wp33-fh49-7crr.json | 37 +++++++++++ .../GHSA-wpp8-fjgf-pwc7.json | 31 +++++++++ .../GHSA-wr75-hw2j-2jxm.json | 41 ++++++++++++ .../GHSA-wrwh-5f9j-74c6.json | 37 +++++++++++ .../GHSA-wvv7-vcrr-7vv5.json | 37 +++++++++++ .../GHSA-wxg9-m4pj-6hvr.json | 37 +++++++++++ .../GHSA-x5w2-ff4f-gg24.json | 29 +++++++++ .../GHSA-x84x-rvq8-4mx4.json | 53 +++++++++++++++ .../GHSA-x9p8-fww8-8frp.json | 29 +++++++++ .../GHSA-xcg2-pp7v-fm8f.json | 37 +++++++++++ .../GHSA-xg7p-78j8-hfrp.json | 37 +++++++++++ .../GHSA-xjr3-qv95-pmw4.json | 37 +++++++++++ .../GHSA-xmf4-8m9h-6vvh.json | 37 +++++++++++ .../GHSA-xxcr-5qmm-8wfp.json | 37 +++++++++++ 176 files changed, 6629 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-24rg-x9r9-x3f6/GHSA-24rg-x9r9-x3f6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2qph-q8xw-gv7q/GHSA-2qph-q8xw-gv7q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json create mode 100644 advisories/unreviewed/2025/04/GHSA-36vv-q5jv-94cj/GHSA-36vv-q5jv-94cj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-46jc-hp5h-cgrh/GHSA-46jc-hp5h-cgrh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4f8q-mwgc-3mwc/GHSA-4f8q-mwgc-3mwc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-52gw-v8vv-qrwr/GHSA-52gw-v8vv-qrwr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5945-5998-27h6/GHSA-5945-5998-27h6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json create mode 100644 advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6chf-hhqf-749c/GHSA-6chf-hhqf-749c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6jg2-8qrr-fq2q/GHSA-6jg2-8qrr-fq2q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6p9f-6933-82rq/GHSA-6p9f-6933-82rq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json create mode 100644 advisories/unreviewed/2025/04/GHSA-75p9-34jj-xrg5/GHSA-75p9-34jj-xrg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7p4r-cj5f-3grm/GHSA-7p4r-cj5f-3grm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7r6g-q2j3-vcf5/GHSA-7r6g-q2j3-vcf5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r2q-865v-wm8j/GHSA-8r2q-865v-wm8j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-94xq-8x25-gjrf/GHSA-94xq-8x25-gjrf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9w85-x5hg-fr66/GHSA-9w85-x5hg-fr66.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c7pf-q3xj-34q3/GHSA-c7pf-q3xj-34q3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c8q6-wp7v-46r9/GHSA-c8q6-wp7v-46r9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ccc9-jgj7-hxc7/GHSA-ccc9-jgj7-hxc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cgpc-3qf8-7mx3/GHSA-cgpc-3qf8-7mx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json create mode 100644 advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhfh-9mcw-2g3q/GHSA-fhfh-9mcw-2g3q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fpmq-p8gp-m5m2/GHSA-fpmq-p8gp-m5m2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g632-x89p-c4m6/GHSA-g632-x89p-c4m6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g8gx-c35h-gv6w/GHSA-g8gx-c35h-gv6w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gf72-h4cp-wcm4/GHSA-gf72-h4cp-wcm4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gwxc-74j8-c3pg/GHSA-gwxc-74j8-c3pg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h9jw-2p4c-9c62/GHSA-h9jw-2p4c-9c62.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hvwm-h8x9-9rg5/GHSA-hvwm-h8x9-9rg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jh66-rjx8-8qqc/GHSA-jh66-rjx8-8qqc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jv6r-mj9p-9xff/GHSA-jv6r-mj9p-9xff.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jwpx-6c4p-q4jq/GHSA-jwpx-6c4p-q4jq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m47h-9h3r-rqw8/GHSA-m47h-9h3r-rqw8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m4wj-hhwj-47qp/GHSA-m4wj-hhwj-47qp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m9w8-wxvp-c9gv/GHSA-m9w8-wxvp-c9gv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pw3g-hp64-xmx9/GHSA-pw3g-hp64-xmx9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pwjq-fx3v-8f9r/GHSA-pwjq-fx3v-8f9r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q953-x475-mh65/GHSA-q953-x475-mh65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qchr-8m24-7v66/GHSA-qchr-8m24-7v66.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qq45-cqhg-jwx5/GHSA-qq45-cqhg-jwx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rhxm-r44m-4325/GHSA-rhxm-r44m-4325.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vc63-6wjr-qvp6/GHSA-vc63-6wjr-qvp6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vjmg-6qjc-gxgh/GHSA-vjmg-6qjc-gxgh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vx9m-rfxq-gr74/GHSA-vx9m-rfxq-gr74.json create mode 100644 advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wmw5-c4qx-m982/GHSA-wmw5-c4qx-m982.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wpp8-fjgf-pwc7/GHSA-wpp8-fjgf-pwc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wvv7-vcrr-7vv5/GHSA-wvv7-vcrr-7vv5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x5w2-ff4f-gg24/GHSA-x5w2-ff4f-gg24.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json diff --git a/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json b/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json index 7ed48c42766..e20cadb8bd7 100644 --- a/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json +++ b/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rhpc-22qh-75f4", - "modified": "2025-03-28T21:30:47Z", + "modified": "2025-04-01T00:30:32Z", "published": "2025-03-28T21:30:47Z", "aliases": [ "CVE-2025-28256" ], "details": "An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T21:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-24rg-x9r9-x3f6/GHSA-24rg-x9r9-x3f6.json b/advisories/unreviewed/2025/04/GHSA-24rg-x9r9-x3f6/GHSA-24rg-x9r9-x3f6.json new file mode 100644 index 00000000000..4d455730f76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24rg-x9r9-x3f6/GHSA-24rg-x9r9-x3f6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24rg-x9r9-x3f6", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30444" + ], + "details": "A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30444" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json b/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json new file mode 100644 index 00000000000..d3765b59063 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28ch-w3c2-xg68", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24097" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to read arbitrary file metadata.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24097" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json b/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json new file mode 100644 index 00000000000..196dfceba0e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c76-7cf4-w44v", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24250" + ], + "details": "This issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24250" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json b/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json new file mode 100644 index 00000000000..e3f79e78b8c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f88-2r9h-hx4p", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24235" + ], + "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote attacker may be able to cause unexpected app termination or heap corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24235" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json b/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json new file mode 100644 index 00000000000..5f9312b92d2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2h82-w6j2-mfx6/GHSA-2h82-w6j2-mfx6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h82-w6j2-mfx6", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24095" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24095" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2qph-q8xw-gv7q/GHSA-2qph-q8xw-gv7q.json b/advisories/unreviewed/2025/04/GHSA-2qph-q8xw-gv7q/GHSA-2qph-q8xw-gv7q.json new file mode 100644 index 00000000000..439931452c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qph-q8xw-gv7q/GHSA-2qph-q8xw-gv7q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qph-q8xw-gv7q", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31674" + ], + "details": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31674" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-core-2025-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-915" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json b/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json new file mode 100644 index 00000000000..b37066b141a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w35-685f-3mpc", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24279" + ], + "details": "This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24279" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json b/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json new file mode 100644 index 00000000000..4241534090a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xcc-3vq7-mvjp", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30434" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30434" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json b/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json new file mode 100644 index 00000000000..89cd8308ea7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3286-4p8w-f9gp", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2024-40864" + ], + "details": "The issue was addressed with improved handling of protocols. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An attacker in a privileged network position can track a user's activity.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40864" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json b/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json new file mode 100644 index 00000000000..b1d54ab1f56 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3324-7ggx-p2gq/GHSA-3324-7ggx-p2gq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3324-7ggx-p2gq", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3059" + ], + "details": "Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3059" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-002" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json b/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json new file mode 100644 index 00000000000..ef1ae0dab28 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-34w4-3qr3-m637/GHSA-34w4-3qr3-m637.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34w4-3qr3-m637", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31676" + ], + "details": "Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31676" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-36vv-q5jv-94cj/GHSA-36vv-q5jv-94cj.json b/advisories/unreviewed/2025/04/GHSA-36vv-q5jv-94cj/GHSA-36vv-q5jv-94cj.json new file mode 100644 index 00000000000..05dabe03f66 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-36vv-q5jv-94cj/GHSA-36vv-q5jv-94cj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36vv-q5jv-94cj", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31682" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31682" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json b/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json new file mode 100644 index 00000000000..7248c44053e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-378r-2hmj-3r7x", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24203" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24203" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json b/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json new file mode 100644 index 00000000000..b9f6735a180 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-387v-qw2x-rwg8", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24260" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24260" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json b/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json new file mode 100644 index 00000000000..fcbcb0b678f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38rr-jcx6-prmh", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24198" + ], + "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24198" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json b/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json new file mode 100644 index 00000000000..265a5025476 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39g6-x4x8-5jcm", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-3057" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3057" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-core-2025-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json b/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json new file mode 100644 index 00000000000..5133f090b27 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cxf-3h44-8cxr", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31187" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31187" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json b/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json new file mode 100644 index 00000000000..78d4ef651f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g2g-jmh9-pfcp", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24233" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24233" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json b/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json new file mode 100644 index 00000000000..6ae554c2ed3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h6v-4pff-pgf4", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24167" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24167" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json b/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json new file mode 100644 index 00000000000..603c032907d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-469w-q8hj-3hr3", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24231" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24231" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-46jc-hp5h-cgrh/GHSA-46jc-hp5h-cgrh.json b/advisories/unreviewed/2025/04/GHSA-46jc-hp5h-cgrh/GHSA-46jc-hp5h-cgrh.json new file mode 100644 index 00000000000..f8634909f3a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-46jc-hp5h-cgrh/GHSA-46jc-hp5h-cgrh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46jc-hp5h-cgrh", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30469" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30469" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4f8q-mwgc-3mwc/GHSA-4f8q-mwgc-3mwc.json b/advisories/unreviewed/2025/04/GHSA-4f8q-mwgc-3mwc/GHSA-4f8q-mwgc-3mwc.json new file mode 100644 index 00000000000..2f845e3335b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f8q-mwgc-3mwc/GHSA-4f8q-mwgc-3mwc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f8q-mwgc-3mwc", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31691" + ], + "details": "Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31691" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json b/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json new file mode 100644 index 00000000000..935a9c86c22 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r7q-g5mr-63x8", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30451" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30451" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json b/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json new file mode 100644 index 00000000000..98ce94beb18 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rpr-22rq-29fr", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30437" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30437" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json b/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json new file mode 100644 index 00000000000..254eeb2de07 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rxj-2g88-h4fp", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24280" + ], + "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24280" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json b/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json new file mode 100644 index 00000000000..75240892f65 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x4g-h2vr-367c", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24196" + ], + "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24196" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-52gw-v8vv-qrwr/GHSA-52gw-v8vv-qrwr.json b/advisories/unreviewed/2025/04/GHSA-52gw-v8vv-qrwr/GHSA-52gw-v8vv-qrwr.json new file mode 100644 index 00000000000..00a121d145a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-52gw-v8vv-qrwr/GHSA-52gw-v8vv-qrwr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52gw-v8vv-qrwr", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30464" + ], + "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30464" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json b/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json new file mode 100644 index 00000000000..3cec175a2ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56rf-vwj9-f3p7", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24283" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24283" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json b/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json new file mode 100644 index 00000000000..4a9c8bfac1c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56x3-c3f3-5345", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24234" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24234" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json b/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json new file mode 100644 index 00000000000..e1463975aa3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57p2-mgfw-2w94", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24148" + ], + "details": "This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24148" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5945-5998-27h6/GHSA-5945-5998-27h6.json b/advisories/unreviewed/2025/04/GHSA-5945-5998-27h6/GHSA-5945-5998-27h6.json new file mode 100644 index 00000000000..f07c4b81a50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5945-5998-27h6/GHSA-5945-5998-27h6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5945-5998-27h6", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3037" + ], + "details": "A vulnerability has been found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a0643f1dae908a4831206f2714b21820f991 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3037" + }, + { + "type": "WEB", + "url": "https://github.com/yzk2356911358/StudentServlet-JSP/issues/3" + }, + { + "type": "WEB", + "url": "https://github.com/yzk2356911358/StudentServlet-JSP/issues/3#issue-2937762896" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json b/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json new file mode 100644 index 00000000000..53df2a45fb9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59wj-h89p-37x9", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30457" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to create symlinks to protected regions of the disk.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30457" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json b/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json new file mode 100644 index 00000000000..d3f788269e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cgr-6hjx-88v5", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24259" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24259" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json b/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json new file mode 100644 index 00000000000..5db6e3f27ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8h-9jcx-3px3", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3061" + ], + "details": "Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3061" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-006" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json b/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json new file mode 100644 index 00000000000..a8b7ca8ab43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jpr-cwj3-v74m", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24205" + ], + "details": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24205" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json new file mode 100644 index 00000000000..06e65c2f510 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qvg-xp2f-fp45", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-30470" + ], + "details": "A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30470" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json b/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json new file mode 100644 index 00000000000..e039ef7fb55 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r66-vgc7-2mm3", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31697" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31697" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json b/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json new file mode 100644 index 00000000000..6cb9bd921b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wrm-m47r-jv84", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24269" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24269" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json new file mode 100644 index 00000000000..1c8e9b06daf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62f2-58pp-q2wg", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30427" + ], + "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30427" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6chf-hhqf-749c/GHSA-6chf-hhqf-749c.json b/advisories/unreviewed/2025/04/GHSA-6chf-hhqf-749c/GHSA-6chf-hhqf-749c.json new file mode 100644 index 00000000000..bf19a9ffe4d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6chf-hhqf-749c/GHSA-6chf-hhqf-749c.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6chf-hhqf-749c", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31684" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31684" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jg2-8qrr-fq2q/GHSA-6jg2-8qrr-fq2q.json b/advisories/unreviewed/2025/04/GHSA-6jg2-8qrr-fq2q/GHSA-6jg2-8qrr-fq2q.json new file mode 100644 index 00000000000..4c7cfe9cdaa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jg2-8qrr-fq2q/GHSA-6jg2-8qrr-fq2q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jg2-8qrr-fq2q", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3038" + ], + "details": "A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_account.php. The manipulation of the argument salary_rate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3038" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/nabiland/cve/blob/main/cve.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json b/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json new file mode 100644 index 00000000000..e0b0ceea186 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p7v-mm3j-hhhh", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24254" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24254" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6p9f-6933-82rq/GHSA-6p9f-6933-82rq.json b/advisories/unreviewed/2025/04/GHSA-6p9f-6933-82rq/GHSA-6p9f-6933-82rq.json new file mode 100644 index 00000000000..7dff26c20c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6p9f-6933-82rq/GHSA-6p9f-6933-82rq.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p9f-6933-82rq", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-3017" + ], + "details": "A vulnerability, which was classified as critical, has been found in TA-Lib up to 0.6.4. This issue affects the function setInputBuffer of the file src/tools/ta_regtest/ta_test_func/test_minmax.c of the component ta_regtest. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5879180e9070ec35d52948f2f57519713256a0f1. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3017" + }, + { + "type": "WEB", + "url": "https://github.com/TA-Lib/ta-lib/issues/61" + }, + { + "type": "WEB", + "url": "https://github.com/TA-Lib/ta-lib/issues/61#issue-2931609110" + }, + { + "type": "WEB", + "url": "https://github.com/TA-Lib/ta-lib/pull/62" + }, + { + "type": "WEB", + "url": "https://github.com/TA-Lib/ta-lib/commit/5879180e9070ec35d52948f2f57519713256a0f1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json b/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json new file mode 100644 index 00000000000..d17c1266d01 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w5j-j56x-jmm3", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3062" + ], + "details": "Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3062" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-010" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json b/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json new file mode 100644 index 00000000000..12d94dfcbf2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x3m-r98v-pgc4", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24281" + ], + "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24281" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json b/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json new file mode 100644 index 00000000000..1ced5e4394f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7345-q82m-2h46", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30426" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to enumerate a user's installed apps.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30426" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75p9-34jj-xrg5/GHSA-75p9-34jj-xrg5.json b/advisories/unreviewed/2025/04/GHSA-75p9-34jj-xrg5/GHSA-75p9-34jj-xrg5.json new file mode 100644 index 00000000000..8247e441847 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75p9-34jj-xrg5/GHSA-75p9-34jj-xrg5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75p9-34jj-xrg5", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24191" + ], + "details": "The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24191" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json b/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json new file mode 100644 index 00000000000..ccb1f83ca81 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75q7-hpjm-4cf5", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24207" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24207" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json b/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json new file mode 100644 index 00000000000..b126f51fd77 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-777h-hpfj-x7hv/GHSA-777h-hpfj-x7hv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-777h-hpfj-x7hv", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31192" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31192" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json b/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json new file mode 100644 index 00000000000..da389a78e5e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78fp-h4q6-qmjg", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30458" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read files outside of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30458" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json b/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json new file mode 100644 index 00000000000..4ef1e61417f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-793h-885v-rxrh", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24180" + ], + "details": "The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24180" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json b/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json new file mode 100644 index 00000000000..16fde73c017 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g9x-v864-75f3", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24256" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24256" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json b/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json new file mode 100644 index 00000000000..b6b2759755e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hxq-4w6w-xgc9", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24264" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24264" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json b/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json new file mode 100644 index 00000000000..1af5909ef20 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mhw-3w3j-f4cw", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24276" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24276" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json b/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json new file mode 100644 index 00000000000..047ba65497d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mmq-w7cm-cxxj", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30435" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30435" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7p4r-cj5f-3grm/GHSA-7p4r-cj5f-3grm.json b/advisories/unreviewed/2025/04/GHSA-7p4r-cj5f-3grm/GHSA-7p4r-cj5f-3grm.json new file mode 100644 index 00000000000..aaa13849649 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7p4r-cj5f-3grm/GHSA-7p4r-cj5f-3grm.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p4r-cj5f-3grm", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30425" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to track users in Safari private browsing mode.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30425" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7r6g-q2j3-vcf5/GHSA-7r6g-q2j3-vcf5.json b/advisories/unreviewed/2025/04/GHSA-7r6g-q2j3-vcf5/GHSA-7r6g-q2j3-vcf5.json new file mode 100644 index 00000000000..d6cac02db7a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7r6g-q2j3-vcf5/GHSA-7r6g-q2j3-vcf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r6g-q2j3-vcf5", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-26683" + ], + "details": "Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26683" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26683" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json b/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json new file mode 100644 index 00000000000..8e160bff1f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xff-8wqr-949p", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24255" + ], + "details": "A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24255" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json b/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json new file mode 100644 index 00000000000..af8e1b5919a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86h4-w859-3hhv", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31696" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31696" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json b/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json new file mode 100644 index 00000000000..b7848623bf7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8852-5rrc-3m6q", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24249" + ], + "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to check the existence of an arbitrary path on the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24249" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json new file mode 100644 index 00000000000..b4264a19271 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-892g-82wc-7r8q", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24242" + ], + "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24242" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json b/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json new file mode 100644 index 00000000000..c8467c2dab4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h8h-4h46-6wx3", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24237" + ], + "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24237" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json b/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json new file mode 100644 index 00000000000..26c020ac6b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mq5-f87c-x4p2", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24194" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may result in the disclosure of process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24194" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json b/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json new file mode 100644 index 00000000000..513edada533 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8mq7-j2hp-g76j/GHSA-8mq7-j2hp-g76j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mq7-j2hp-g76j", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24216" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24216" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json b/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json new file mode 100644 index 00000000000..71268b903af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q4c-gc84-4w63", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24157" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24157" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r2q-865v-wm8j/GHSA-8r2q-865v-wm8j.json b/advisories/unreviewed/2025/04/GHSA-8r2q-865v-wm8j/GHSA-8r2q-865v-wm8j.json new file mode 100644 index 00000000000..4cd704c4438 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r2q-865v-wm8j/GHSA-8r2q-865v-wm8j.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r2q-865v-wm8j", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31687" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan filter allows Cross-Site Scripting (XSS).This issue affects SpamSpan filter: from 0.0.0 before 3.2.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31687" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json b/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json new file mode 100644 index 00000000000..22b8332a688 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w29-wh58-hrm4", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24199" + ], + "details": "An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24199" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94xq-8x25-gjrf/GHSA-94xq-8x25-gjrf.json b/advisories/unreviewed/2025/04/GHSA-94xq-8x25-gjrf/GHSA-94xq-8x25-gjrf.json new file mode 100644 index 00000000000..3d80f5c9e6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94xq-8x25-gjrf/GHSA-94xq-8x25-gjrf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94xq-8x25-gjrf", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-3036" + ], + "details": "A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a0643f1dae908a4831206f2714b21820f991. This affects an unknown part of the component Student Management Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3036" + }, + { + "type": "WEB", + "url": "https://github.com/yzk2356911358/StudentServlet-JSP/issues/2" + }, + { + "type": "WEB", + "url": "https://github.com/yzk2356911358/StudentServlet-JSP/issues/2#issue-2937740237" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json b/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json new file mode 100644 index 00000000000..ea7a09526db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-972j-fxc9-8wqp", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24193" + ], + "details": "This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24193" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json b/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json new file mode 100644 index 00000000000..aafeebb1d8d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f34-hg9w-62vg", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24178" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24178" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json b/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json new file mode 100644 index 00000000000..ee6c260d950 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hjm-gm4c-vqqv", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24190" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24190" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json b/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json new file mode 100644 index 00000000000..74053136fde --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r28-p42w-83mg", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24202" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24202" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9w85-x5hg-fr66/GHSA-9w85-x5hg-fr66.json b/advisories/unreviewed/2025/04/GHSA-9w85-x5hg-fr66/GHSA-9w85-x5hg-fr66.json new file mode 100644 index 00000000000..24127152941 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9w85-x5hg-fr66/GHSA-9w85-x5hg-fr66.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w85-x5hg-fr66", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31677" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31677" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c7pf-q3xj-34q3/GHSA-c7pf-q3xj-34q3.json b/advisories/unreviewed/2025/04/GHSA-c7pf-q3xj-34q3/GHSA-c7pf-q3xj-34q3.json new file mode 100644 index 00000000000..044c898ca67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c7pf-q3xj-34q3/GHSA-c7pf-q3xj-34q3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7pf-q3xj-34q3", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24277" + ], + "details": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24277" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8q6-wp7v-46r9/GHSA-c8q6-wp7v-46r9.json b/advisories/unreviewed/2025/04/GHSA-c8q6-wp7v-46r9/GHSA-c8q6-wp7v-46r9.json new file mode 100644 index 00000000000..9aa7eaf9509 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8q6-wp7v-46r9/GHSA-c8q6-wp7v-46r9.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8q6-wp7v-46r9", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31678" + ], + "details": "Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31678" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccc9-jgj7-hxc7/GHSA-ccc9-jgj7-hxc7.json b/advisories/unreviewed/2025/04/GHSA-ccc9-jgj7-hxc7/GHSA-ccc9-jgj7-hxc7.json new file mode 100644 index 00000000000..0256eee5dbc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccc9-jgj7-hxc7/GHSA-ccc9-jgj7-hxc7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccc9-jgj7-hxc7", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31690" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31690" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cgpc-3qf8-7mx3/GHSA-cgpc-3qf8-7mx3.json b/advisories/unreviewed/2025/04/GHSA-cgpc-3qf8-7mx3/GHSA-cgpc-3qf8-7mx3.json new file mode 100644 index 00000000000..bb0ac3f3cb8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cgpc-3qf8-7mx3/GHSA-cgpc-3qf8-7mx3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgpc-3qf8-7mx3", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24257" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to cause unexpected system termination or write kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24257" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json b/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json new file mode 100644 index 00000000000..4061b3d160f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqxv-6v33-64xx", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24265" + ], + "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24265" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json b/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json new file mode 100644 index 00000000000..25cb531e610 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr5x-x94v-gf96", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30456" + ], + "details": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30456" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json b/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json new file mode 100644 index 00000000000..4996b8ae10a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crwm-v9wf-m9pg", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24245" + ], + "details": "This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24245" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json b/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json new file mode 100644 index 00000000000..ed992774ce3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2wv-6cwg-48rq", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24244" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted font may result in the disclosure of process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24244" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json b/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json new file mode 100644 index 00000000000..b1d2b6a58a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9vw-5v2f-5j5q", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24263" + ], + "details": "A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24263" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json b/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json new file mode 100644 index 00000000000..598ae01eed1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff7g-r4f4-qg7v", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24217" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24217" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fhfh-9mcw-2g3q/GHSA-fhfh-9mcw-2g3q.json b/advisories/unreviewed/2025/04/GHSA-fhfh-9mcw-2g3q/GHSA-fhfh-9mcw-2g3q.json new file mode 100644 index 00000000000..981581f3d3f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhfh-9mcw-2g3q/GHSA-fhfh-9mcw-2g3q.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhfh-9mcw-2g3q", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24230" + ], + "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Playing a malicious audio file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24230" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fpmq-p8gp-m5m2/GHSA-fpmq-p8gp-m5m2.json b/advisories/unreviewed/2025/04/GHSA-fpmq-p8gp-m5m2/GHSA-fpmq-p8gp-m5m2.json new file mode 100644 index 00000000000..8842262867a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fpmq-p8gp-m5m2/GHSA-fpmq-p8gp-m5m2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpmq-p8gp-m5m2", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24172" + ], + "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. \"Block All Remote Content\" may not apply for all mail previews.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24172" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json b/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json new file mode 100644 index 00000000000..7d65efd6928 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frrr-xgqj-649g", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24210" + ], + "details": "A logic error was addressed with improved error handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Parsing an image may lead to disclosure of user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24210" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json b/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json new file mode 100644 index 00000000000..0c03cb29f2c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3r7-w9gq-5v84", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24215" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24215" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json b/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json new file mode 100644 index 00000000000..d77ddd96d4c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3v9-6xm2-qr9w", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24229" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A sandboxed app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24229" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json b/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json new file mode 100644 index 00000000000..fbbc99a6b4a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5m7-ph65-hj67", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24238" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain elevated privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24238" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g632-x89p-c4m6/GHSA-g632-x89p-c4m6.json b/advisories/unreviewed/2025/04/GHSA-g632-x89p-c4m6/GHSA-g632-x89p-c4m6.json new file mode 100644 index 00000000000..5a552c66b3c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g632-x89p-c4m6/GHSA-g632-x89p-c4m6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g632-x89p-c4m6", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24241" + ], + "details": "A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24241" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json b/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json new file mode 100644 index 00000000000..21f0c9a2db4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7xp-7fwj-m5hv", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24246" + ], + "details": "An injection issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24246" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g8gx-c35h-gv6w/GHSA-g8gx-c35h-gv6w.json b/advisories/unreviewed/2025/04/GHSA-g8gx-c35h-gv6w/GHSA-g8gx-c35h-gv6w.json new file mode 100644 index 00000000000..7dcebc340a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g8gx-c35h-gv6w/GHSA-g8gx-c35h-gv6w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8gx-c35h-gv6w", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24164" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24164" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gf72-h4cp-wcm4/GHSA-gf72-h4cp-wcm4.json b/advisories/unreviewed/2025/04/GHSA-gf72-h4cp-wcm4/GHSA-gf72-h4cp-wcm4.json new file mode 100644 index 00000000000..10046b55144 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gf72-h4cp-wcm4/GHSA-gf72-h4cp-wcm4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf72-h4cp-wcm4", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31685" + ], + "details": "Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31685" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json b/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json new file mode 100644 index 00000000000..03f21d30885 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghrr-554g-qqv5", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30461" + ], + "details": "An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30461" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json b/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json new file mode 100644 index 00000000000..f1495e28a46 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmw9-8h79-pvq5", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24240" + ], + "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24240" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json b/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json new file mode 100644 index 00000000000..7fec2c23450 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvwv-9mwf-hg22", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30439" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An attacker with physical access to a locked device may be able to view sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30439" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json b/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json new file mode 100644 index 00000000000..69adc71f88b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw73-hwr2-4qrm", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30443" + ], + "details": "A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30443" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gwxc-74j8-c3pg/GHSA-gwxc-74j8-c3pg.json b/advisories/unreviewed/2025/04/GHSA-gwxc-74j8-c3pg/GHSA-gwxc-74j8-c3pg.json new file mode 100644 index 00000000000..471c537b239 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwxc-74j8-c3pg/GHSA-gwxc-74j8-c3pg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwxc-74j8-c3pg", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30424" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Deleting a conversation in Messages may expose user contact information in system logging.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30424" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json b/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json new file mode 100644 index 00000000000..0038cd06a82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2wh-36m8-j3rp", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31191" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31191" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json b/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json new file mode 100644 index 00000000000..29adf7479f4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h94m-mjfh-2g77", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24247" + ], + "details": "A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker may be able to cause unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24247" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json b/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json new file mode 100644 index 00000000000..252d7afbd5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h94q-fmqj-xgwh", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30450" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30450" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h9jw-2p4c-9c62/GHSA-h9jw-2p4c-9c62.json b/advisories/unreviewed/2025/04/GHSA-h9jw-2p4c-9c62/GHSA-h9jw-2p4c-9c62.json new file mode 100644 index 00000000000..858db15d207 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9jw-2p4c-9c62/GHSA-h9jw-2p4c-9c62.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9jw-2p4c-9c62", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3039" + ], + "details": "A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_employee.php. The manipulation of the argument lname/fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3039" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/xuzhuojia22/cve/blob/main/cvexuzhoujia.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524676" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json b/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json new file mode 100644 index 00000000000..c55f81157ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc9m-f2mx-w9j7", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24173" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24173" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json b/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json new file mode 100644 index 00000000000..98f9ed00d44 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf6c-fgp3-jfch", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31694" + ], + "details": "Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31694" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hvwm-h8x9-9rg5/GHSA-hvwm-h8x9-9rg5.json b/advisories/unreviewed/2025/04/GHSA-hvwm-h8x9-9rg5/GHSA-hvwm-h8x9-9rg5.json new file mode 100644 index 00000000000..be86026e16c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hvwm-h8x9-9rg5/GHSA-hvwm-h8x9-9rg5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvwm-h8x9-9rg5", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24267" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24267" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json b/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json new file mode 100644 index 00000000000..62036f1c1c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j34j-434j-r63c", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24204" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24204" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json b/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json new file mode 100644 index 00000000000..775a9f606b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7j3-j385-mfpx", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24253" + ], + "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24253" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json b/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json new file mode 100644 index 00000000000..f39f7ea5e1a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j87v-9jp4-gw6c/GHSA-j87v-9jp4-gw6c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j87v-9jp4-gw6c", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31188" + ], + "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to bypass Privacy preferences.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31188" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json b/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json new file mode 100644 index 00000000000..b51977e6d37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8gc-8grp-vffr", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24209" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24209" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jh66-rjx8-8qqc/GHSA-jh66-rjx8-8qqc.json b/advisories/unreviewed/2025/04/GHSA-jh66-rjx8-8qqc/GHSA-jh66-rjx8-8qqc.json new file mode 100644 index 00000000000..8ed0d95ebfd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jh66-rjx8-8qqc/GHSA-jh66-rjx8-8qqc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh66-rjx8-8qqc", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31680" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31680" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json b/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json new file mode 100644 index 00000000000..b1d5a92b7f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq4h-8p8p-vchg", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24226" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24226" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122380" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json new file mode 100644 index 00000000000..706a724703e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrgv-pmf9-6qg5", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24278" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24278" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jv6r-mj9p-9xff/GHSA-jv6r-mj9p-9xff.json b/advisories/unreviewed/2025/04/GHSA-jv6r-mj9p-9xff/GHSA-jv6r-mj9p-9xff.json new file mode 100644 index 00000000000..aa25b70480b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jv6r-mj9p-9xff/GHSA-jv6r-mj9p-9xff.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv6r-mj9p-9xff", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31689" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31689" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jwpx-6c4p-q4jq/GHSA-jwpx-6c4p-q4jq.json b/advisories/unreviewed/2025/04/GHSA-jwpx-6c4p-q4jq/GHSA-jwpx-6c4p-q4jq.json new file mode 100644 index 00000000000..a0d21c1b5b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jwpx-6c4p-q4jq/GHSA-jwpx-6c4p-q4jq.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwpx-6c4p-q4jq", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31681" + ], + "details": "Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31681" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m47h-9h3r-rqw8/GHSA-m47h-9h3r-rqw8.json b/advisories/unreviewed/2025/04/GHSA-m47h-9h3r-rqw8/GHSA-m47h-9h3r-rqw8.json new file mode 100644 index 00000000000..f32219b82a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m47h-9h3r-rqw8/GHSA-m47h-9h3r-rqw8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m47h-9h3r-rqw8", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30465" + ], + "details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30465" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m4wj-hhwj-47qp/GHSA-m4wj-hhwj-47qp.json b/advisories/unreviewed/2025/04/GHSA-m4wj-hhwj-47qp/GHSA-m4wj-hhwj-47qp.json new file mode 100644 index 00000000000..f5a276eb7a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m4wj-hhwj-47qp/GHSA-m4wj-hhwj-47qp.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4wj-hhwj-47qp", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31675" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31675" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-core-2025-004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json b/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json new file mode 100644 index 00000000000..eb455b111f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m773-p743-chvm", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24214" + ], + "details": "A privacy issue was addressed by not logging contents of text fields. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24214" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json b/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json new file mode 100644 index 00000000000..629b8b655d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8pg-77c8-3wj6", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2024-54533" + ], + "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54533" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m9w8-wxvp-c9gv/GHSA-m9w8-wxvp-c9gv.json b/advisories/unreviewed/2025/04/GHSA-m9w8-wxvp-c9gv/GHSA-m9w8-wxvp-c9gv.json new file mode 100644 index 00000000000..a81b1efbaf7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m9w8-wxvp-c9gv/GHSA-m9w8-wxvp-c9gv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9w8-wxvp-c9gv", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31686" + ], + "details": "Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31686" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json b/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json new file mode 100644 index 00000000000..f1241825f92 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgrm-96cw-6vxv", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30449" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30449" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json b/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json new file mode 100644 index 00000000000..18f0593f94e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrh3-4hmr-qq29", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3060" + ], + "details": "Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3060" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-005" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json b/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json new file mode 100644 index 00000000000..82efc3d80f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2wg-8h29-874v", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31695" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31695" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json b/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json new file mode 100644 index 00000000000..fc3ee552b37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3gw-g89c-c3cq", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24236" + ], + "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24236" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json b/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json new file mode 100644 index 00000000000..0266408c2dd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vm-6crq-4pg4", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-24170" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24170" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json b/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json new file mode 100644 index 00000000000..0e831e5ef50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p57m-j445-jv2j", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30438" + ], + "details": "This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30438" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json new file mode 100644 index 00000000000..03283661ad0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7wf-qqfr-f6xp", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24213" + ], + "details": "This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A type confusion issue could lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24213" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json b/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json new file mode 100644 index 00000000000..516378e1cc8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg82-qc3q-4772", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-30471" + ], + "details": "A validation issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote user may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30471" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json b/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json new file mode 100644 index 00000000000..a6ccc924f3a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pph7-4r52-2m8q", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24218" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24218" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pw3g-hp64-xmx9/GHSA-pw3g-hp64-xmx9.json b/advisories/unreviewed/2025/04/GHSA-pw3g-hp64-xmx9/GHSA-pw3g-hp64-xmx9.json new file mode 100644 index 00000000000..6c779c491b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pw3g-hp64-xmx9/GHSA-pw3g-hp64-xmx9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw3g-hp64-xmx9", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-3018" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3018" + }, + { + "type": "WEB", + "url": "https://github.com/csemfl/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524623" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pwjq-fx3v-8f9r/GHSA-pwjq-fx3v-8f9r.json b/advisories/unreviewed/2025/04/GHSA-pwjq-fx3v-8f9r/GHSA-pwjq-fx3v-8f9r.json new file mode 100644 index 00000000000..96f5b9a897b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pwjq-fx3v-8f9r/GHSA-pwjq-fx3v-8f9r.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwjq-fx3v-8f9r", + "modified": "2025-04-01T00:30:35Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31692" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31692" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json b/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json new file mode 100644 index 00000000000..67202a6d3c6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3w8-9x53-fgrm", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24211" + ], + "details": "This issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24211" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json b/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json new file mode 100644 index 00000000000..de62447f05e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q556-7cxr-pm34", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24182" + ], + "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing a maliciously crafted font may result in the disclosure of process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24182" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json b/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json new file mode 100644 index 00000000000..45aaf6b8569 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q844-h75g-f78q/GHSA-q844-h75g-f78q.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q844-h75g-f78q", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31184" + ], + "details": "This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may gain unauthorized access to Local Network.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31184" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q953-x475-mh65/GHSA-q953-x475-mh65.json b/advisories/unreviewed/2025/04/GHSA-q953-x475-mh65/GHSA-q953-x475-mh65.json new file mode 100644 index 00000000000..29515e4d8c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q953-x475-mh65/GHSA-q953-x475-mh65.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q953-x475-mh65", + "modified": "2025-04-01T00:30:45Z", + "published": "2025-04-01T00:30:45Z", + "aliases": [ + "CVE-2025-3040" + ], + "details": "A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_student.php. The manipulation of the argument pic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3040" + }, + { + "type": "WEB", + "url": "https://github.com/ydnd/cve/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524934" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qchr-8m24-7v66/GHSA-qchr-8m24-7v66.json b/advisories/unreviewed/2025/04/GHSA-qchr-8m24-7v66/GHSA-qchr-8m24-7v66.json new file mode 100644 index 00000000000..ad1aecb9934 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qchr-8m24-7v66/GHSA-qchr-8m24-7v66.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qchr-8m24-7v66", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31683" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31683" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json b/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json new file mode 100644 index 00000000000..7213fb04910 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm2f-w2gq-vqp6", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24243" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted file may lead to arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24243" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json b/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json new file mode 100644 index 00000000000..f57272a08d1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpj9-jpjq-jm8g", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24261" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24261" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qq45-cqhg-jwx5/GHSA-qq45-cqhg-jwx5.json b/advisories/unreviewed/2025/04/GHSA-qq45-cqhg-jwx5/GHSA-qq45-cqhg-jwx5.json new file mode 100644 index 00000000000..c9241876af2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qq45-cqhg-jwx5/GHSA-qq45-cqhg-jwx5.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq45-cqhg-jwx5", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31688" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31688" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json b/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json new file mode 100644 index 00000000000..f065710ca7a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrx7-4fmv-56wc", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24192" + ], + "details": "A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a website may leak sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24192" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json b/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json new file mode 100644 index 00000000000..b46d87cff47 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxhm-5vqv-9j5q", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30463" + ], + "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30463" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json b/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json new file mode 100644 index 00000000000..c4299f3e6ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r32r-4px4-7j36", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30447" + ], + "details": "The issue was resolved by sanitizing logging This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30447" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json b/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json new file mode 100644 index 00000000000..f53318e4968 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r6wp-29qw-vxr5/GHSA-r6wp-29qw-vxr5.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6wp-29qw-vxr5", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30432" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sonoma 14.7.5. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30432" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json b/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json new file mode 100644 index 00000000000..03fdd0c18b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh3m-2p8j-6cf7", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31183" + ], + "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31183" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rhxm-r44m-4325/GHSA-rhxm-r44m-4325.json b/advisories/unreviewed/2025/04/GHSA-rhxm-r44m-4325/GHSA-rhxm-r44m-4325.json new file mode 100644 index 00000000000..2cc69547f56 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rhxm-r44m-4325/GHSA-rhxm-r44m-4325.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhxm-r44m-4325", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31679" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Error Pages allows Cross-Site Scripting (XSS).This issue affects Ignition Error Pages: from 0.0.0 before 1.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31679" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json b/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json new file mode 100644 index 00000000000..021e6675f9f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqp3-mh44-cf98", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30462" + ], + "details": "A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30462" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json b/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json new file mode 100644 index 00000000000..67f8c68f8dd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwvj-3jx7-frmw", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31182" + ], + "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to delete files for which it does not have permission.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31182" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json b/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json new file mode 100644 index 00000000000..b06b780ac5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx8v-vhcf-rfq6", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30441" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30441" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122380" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json b/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json new file mode 100644 index 00000000000..144b1d6d3e1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3qr-7hm5-5r4j", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24228" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24228" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json b/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json new file mode 100644 index 00000000000..2e093fffa6f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7jj-vhq2-vgc8", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24266" + ], + "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24266" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vc63-6wjr-qvp6/GHSA-vc63-6wjr-qvp6.json b/advisories/unreviewed/2025/04/GHSA-vc63-6wjr-qvp6/GHSA-vc63-6wjr-qvp6.json new file mode 100644 index 00000000000..b811c639e4b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vc63-6wjr-qvp6/GHSA-vc63-6wjr-qvp6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc63-6wjr-qvp6", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24221" + ], + "details": "This issue was addressed with improved data access restriction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Sensitive keychain data may be accessible from an iOS backup.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24221" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json b/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json new file mode 100644 index 00000000000..6db1237b4d2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vccw-jcwc-p44p", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24262" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24262" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json b/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json new file mode 100644 index 00000000000..d1e860bfdc8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhf9-v5pf-qmcg/GHSA-vhf9-v5pf-qmcg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhf9-v5pf-qmcg", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30428" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30428" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json b/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json new file mode 100644 index 00000000000..d162a5af3b1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhq9-x7cx-387j", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24195" + ], + "details": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24195" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json b/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json new file mode 100644 index 00000000000..3421b11936b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjfx-mp69-qfw4", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24248" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24248" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjmg-6qjc-gxgh/GHSA-vjmg-6qjc-gxgh.json b/advisories/unreviewed/2025/04/GHSA-vjmg-6qjc-gxgh/GHSA-vjmg-6qjc-gxgh.json new file mode 100644 index 00000000000..d0cc47b05e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vjmg-6qjc-gxgh/GHSA-vjmg-6qjc-gxgh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjmg-6qjc-gxgh", + "modified": "2025-04-01T00:30:46Z", + "published": "2025-04-01T00:30:46Z", + "aliases": [ + "CVE-2025-3041" + ], + "details": "A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /admin/updatestudent.php. The manipulation of the argument pic leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3041" + }, + { + "type": "WEB", + "url": "https://github.com/ydnd/cve/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524935" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json b/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json new file mode 100644 index 00000000000..8e86eeee00a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm8m-rr8q-8rjw", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30455" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30455" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json b/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json new file mode 100644 index 00000000000..dca62459188 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmh7-68x6-gw3h", + "modified": "2025-04-01T00:30:36Z", + "published": "2025-04-01T00:30:36Z", + "aliases": [ + "CVE-2025-24181" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24181" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json b/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json new file mode 100644 index 00000000000..880ea7dbfd0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwcg-r7w2-v8qc", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24208" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24208" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vx9m-rfxq-gr74/GHSA-vx9m-rfxq-gr74.json b/advisories/unreviewed/2025/04/GHSA-vx9m-rfxq-gr74/GHSA-vx9m-rfxq-gr74.json new file mode 100644 index 00000000000..e454e3da68b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vx9m-rfxq-gr74/GHSA-vx9m-rfxq-gr74.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx9m-rfxq-gr74", + "modified": "2025-04-01T00:30:34Z", + "published": "2025-04-01T00:30:34Z", + "aliases": [ + "CVE-2025-31693" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31693" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json b/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json new file mode 100644 index 00000000000..84a0bafcb83 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhr-6p94-vcj4", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30429" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30429" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wmw5-c4qx-m982/GHSA-wmw5-c4qx-m982.json b/advisories/unreviewed/2025/04/GHSA-wmw5-c4qx-m982/GHSA-wmw5-c4qx-m982.json new file mode 100644 index 00000000000..9a883073d4d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wmw5-c4qx-m982/GHSA-wmw5-c4qx-m982.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmw5-c4qx-m982", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30433" + ], + "details": "This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30433" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json b/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json new file mode 100644 index 00000000000..6561ce4f455 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp33-fh49-7crr", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30467" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30467" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wpp8-fjgf-pwc7/GHSA-wpp8-fjgf-pwc7.json b/advisories/unreviewed/2025/04/GHSA-wpp8-fjgf-pwc7/GHSA-wpp8-fjgf-pwc7.json new file mode 100644 index 00000000000..ee101e3be15 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wpp8-fjgf-pwc7/GHSA-wpp8-fjgf-pwc7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpp8-fjgf-pwc7", + "modified": "2025-04-01T00:30:33Z", + "published": "2025-04-01T00:30:33Z", + "aliases": [ + "CVE-2025-31673" + ], + "details": "Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31673" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-core-2025-002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json b/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json new file mode 100644 index 00000000000..200bb4226af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr75-hw2j-2jxm", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30454" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. A malicious app may be able to access private information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30454" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json b/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json new file mode 100644 index 00000000000..f82e3c060e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrwh-5f9j-74c6", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:43Z", + "aliases": [ + "CVE-2025-30460" + ], + "details": "A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30460" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wvv7-vcrr-7vv5/GHSA-wvv7-vcrr-7vv5.json b/advisories/unreviewed/2025/04/GHSA-wvv7-vcrr-7vv5/GHSA-wvv7-vcrr-7vv5.json new file mode 100644 index 00000000000..a4b4564f858 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wvv7-vcrr-7vv5/GHSA-wvv7-vcrr-7vv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvv7-vcrr-7vv5", + "modified": "2025-04-01T00:30:43Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30452" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An input validation issue was addressed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30452" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json b/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json new file mode 100644 index 00000000000..3eb00e28983 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxg9-m4pj-6hvr", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24272" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24272" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x5w2-ff4f-gg24/GHSA-x5w2-ff4f-gg24.json b/advisories/unreviewed/2025/04/GHSA-x5w2-ff4f-gg24/GHSA-x5w2-ff4f-gg24.json new file mode 100644 index 00000000000..97eb1f24f32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x5w2-ff4f-gg24/GHSA-x5w2-ff4f-gg24.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5w2-ff4f-gg24", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-24282" + ], + "details": "A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24282" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json b/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json new file mode 100644 index 00000000000..e9d4d9eb7d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x84x-rvq8-4mx4", + "modified": "2025-04-01T00:30:37Z", + "published": "2025-04-01T00:30:37Z", + "aliases": [ + "CVE-2025-24212" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24212" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json b/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json new file mode 100644 index 00000000000..ed38582f7f1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9p8-fww8-8frp", + "modified": "2025-04-01T00:30:39Z", + "published": "2025-04-01T00:30:39Z", + "aliases": [ + "CVE-2025-24239" + ], + "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24239" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json b/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json new file mode 100644 index 00000000000..472bf34d3bf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcg2-pp7v-fm8f", + "modified": "2025-04-01T00:30:42Z", + "published": "2025-04-01T00:30:42Z", + "aliases": [ + "CVE-2025-30446" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app with root privileges may be able to modify the contents of system files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30446" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json b/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json new file mode 100644 index 00000000000..313f3d5b9a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg7p-78j8-hfrp", + "modified": "2025-04-01T00:30:41Z", + "published": "2025-04-01T00:30:41Z", + "aliases": [ + "CVE-2025-30430" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Password autofill may fill in passwords after failing authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30430" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json b/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json new file mode 100644 index 00000000000..53f87300502 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjr3-qv95-pmw4", + "modified": "2025-04-01T00:30:40Z", + "published": "2025-04-01T00:30:40Z", + "aliases": [ + "CVE-2025-24273" + ], + "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24273" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json b/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json new file mode 100644 index 00000000000..66219dd4c14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmf4-8m9h-6vvh", + "modified": "2025-04-01T00:30:44Z", + "published": "2025-04-01T00:30:44Z", + "aliases": [ + "CVE-2025-31194" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A Shortcut may run with admin privileges without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31194" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json b/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json new file mode 100644 index 00000000000..dab631f9e67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxcr-5qmm-8wfp", + "modified": "2025-04-01T00:30:38Z", + "published": "2025-04-01T00:30:38Z", + "aliases": [ + "CVE-2025-24232" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24232" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T23:15:20Z" + } +} \ No newline at end of file