diff --git a/advisories/github-reviewed/2020/12/GHSA-4cch-wxpw-8p28/GHSA-4cch-wxpw-8p28.json b/advisories/github-reviewed/2020/12/GHSA-4cch-wxpw-8p28/GHSA-4cch-wxpw-8p28.json index d3b620616f9..84a6eedddf1 100644 --- a/advisories/github-reviewed/2020/12/GHSA-4cch-wxpw-8p28/GHSA-4cch-wxpw-8p28.json +++ b/advisories/github-reviewed/2020/12/GHSA-4cch-wxpw-8p28/GHSA-4cch-wxpw-8p28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cch-wxpw-8p28", - "modified": "2025-01-15T20:17:50Z", + "modified": "2025-01-15T21:31:38Z", "published": "2020-12-21T16:28:42Z", "aliases": [ "CVE-2020-26258" @@ -48,6 +48,10 @@ "type": "PACKAGE", "url": "https://github.com/x-stream/xstream" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r97993e3d78e1f5389b7b172ba9f308440830ce5f051ee62714a0aa34%40%3Ccommits.struts.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r97993e3d78e1f5389b7b172ba9f308440830ce5f051ee62714a0aa34@%3Ccommits.struts.apache.org%3E" @@ -56,6 +60,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00042.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP" diff --git a/advisories/unreviewed/2022/05/GHSA-86rq-gv28-jjr6/GHSA-86rq-gv28-jjr6.json b/advisories/unreviewed/2022/05/GHSA-86rq-gv28-jjr6/GHSA-86rq-gv28-jjr6.json index d824f37f78e..888023275a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-86rq-gv28-jjr6/GHSA-86rq-gv28-jjr6.json +++ b/advisories/unreviewed/2022/05/GHSA-86rq-gv28-jjr6/GHSA-86rq-gv28-jjr6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86rq-gv28-jjr6", - "modified": "2022-05-13T01:28:44Z", + "modified": "2025-01-15T21:31:36Z", "published": "2022-05-13T01:28:44Z", "aliases": [ "CVE-2016-4303" diff --git a/advisories/unreviewed/2023/05/GHSA-wh53-jcxh-p452/GHSA-wh53-jcxh-p452.json b/advisories/unreviewed/2023/05/GHSA-wh53-jcxh-p452/GHSA-wh53-jcxh-p452.json index d5724299292..52da11b8ea9 100644 --- a/advisories/unreviewed/2023/05/GHSA-wh53-jcxh-p452/GHSA-wh53-jcxh-p452.json +++ b/advisories/unreviewed/2023/05/GHSA-wh53-jcxh-p452/GHSA-wh53-jcxh-p452.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2r3p-7g4x-2m8x/GHSA-2r3p-7g4x-2m8x.json b/advisories/unreviewed/2024/02/GHSA-2r3p-7g4x-2m8x/GHSA-2r3p-7g4x-2m8x.json index f59e9f3b800..3f1b16887f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-2r3p-7g4x-2m8x/GHSA-2r3p-7g4x-2m8x.json +++ b/advisories/unreviewed/2024/02/GHSA-2r3p-7g4x-2m8x/GHSA-2r3p-7g4x-2m8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r3p-7g4x-2m8x", - "modified": "2024-02-27T06:30:33Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-02-27T06:30:33Z", "aliases": [ "CVE-2024-1686" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-65vg-43vj-r32c/GHSA-65vg-43vj-r32c.json b/advisories/unreviewed/2024/02/GHSA-65vg-43vj-r32c/GHSA-65vg-43vj-r32c.json index 0ed47e51c6e..9dca7fbce91 100644 --- a/advisories/unreviewed/2024/02/GHSA-65vg-43vj-r32c/GHSA-65vg-43vj-r32c.json +++ b/advisories/unreviewed/2024/02/GHSA-65vg-43vj-r32c/GHSA-65vg-43vj-r32c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6cc6-q8x8-h7vm/GHSA-6cc6-q8x8-h7vm.json b/advisories/unreviewed/2024/02/GHSA-6cc6-q8x8-h7vm/GHSA-6cc6-q8x8-h7vm.json index b68224980f1..91461c89217 100644 --- a/advisories/unreviewed/2024/02/GHSA-6cc6-q8x8-h7vm/GHSA-6cc6-q8x8-h7vm.json +++ b/advisories/unreviewed/2024/02/GHSA-6cc6-q8x8-h7vm/GHSA-6cc6-q8x8-h7vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cc6-q8x8-h7vm", - "modified": "2024-02-27T06:30:33Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-02-27T06:30:33Z", "aliases": [ "CVE-2024-1687" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h67p-q5m6-859h/GHSA-h67p-q5m6-859h.json b/advisories/unreviewed/2024/02/GHSA-h67p-q5m6-859h/GHSA-h67p-q5m6-859h.json index 79ae07fce54..509555af72e 100644 --- a/advisories/unreviewed/2024/02/GHSA-h67p-q5m6-859h/GHSA-h67p-q5m6-859h.json +++ b/advisories/unreviewed/2024/02/GHSA-h67p-q5m6-859h/GHSA-h67p-q5m6-859h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j4rr-p24q-x2wv/GHSA-j4rr-p24q-x2wv.json b/advisories/unreviewed/2024/02/GHSA-j4rr-p24q-x2wv/GHSA-j4rr-p24q-x2wv.json index 6b9ca7e6949..d813aed66c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-j4rr-p24q-x2wv/GHSA-j4rr-p24q-x2wv.json +++ b/advisories/unreviewed/2024/02/GHSA-j4rr-p24q-x2wv/GHSA-j4rr-p24q-x2wv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json b/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json index 17a850682d8..0aa49aa6765 100644 --- a/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json +++ b/advisories/unreviewed/2024/03/GHSA-3p89-8hm7-44h4/GHSA-3p89-8hm7-44h4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3p89-8hm7-44h4", - "modified": "2024-03-21T03:36:46Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-21T03:36:46Z", "aliases": [ "CVE-2024-1502" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7j97-wg47-fmcm/GHSA-7j97-wg47-fmcm.json b/advisories/unreviewed/2024/03/GHSA-7j97-wg47-fmcm/GHSA-7j97-wg47-fmcm.json index cd10209ff13..55dc3ddbd83 100644 --- a/advisories/unreviewed/2024/03/GHSA-7j97-wg47-fmcm/GHSA-7j97-wg47-fmcm.json +++ b/advisories/unreviewed/2024/03/GHSA-7j97-wg47-fmcm/GHSA-7j97-wg47-fmcm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json b/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json index 6bc2714351b..7ebeaedf297 100644 --- a/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json +++ b/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhwv-mrvc-q6mv", - "modified": "2024-03-09T09:30:41Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-09T09:30:41Z", "aliases": [ "CVE-2024-1124" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json b/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json index fff16a64bb6..48593faff30 100644 --- a/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json +++ b/advisories/unreviewed/2024/03/GHSA-qxmq-f8x5-rfg3/GHSA-qxmq-f8x5-rfg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxmq-f8x5-rfg3", - "modified": "2024-03-21T03:36:46Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-21T03:36:46Z", "aliases": [ "CVE-2024-1503" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json b/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json index 4356e04031e..06fddc250a4 100644 --- a/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json +++ b/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r334-cg32-8chf", - "modified": "2024-03-09T09:30:42Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-09T09:30:42Z", "aliases": [ "CVE-2024-1320" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json b/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json index dd5fdb473f3..d022cb89c39 100644 --- a/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json +++ b/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r382-478w-qwfw", - "modified": "2024-03-09T09:30:41Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-09T09:30:41Z", "aliases": [ "CVE-2024-1123" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json b/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json index 8f14f687148..68556ec4b91 100644 --- a/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json +++ b/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5r4-7hp9-q2xp", - "modified": "2024-03-09T09:30:41Z", + "modified": "2025-01-15T21:31:38Z", "published": "2024-03-09T09:30:41Z", "aliases": [ "CVE-2024-1125" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rfr4-cc7m-p8vv/GHSA-rfr4-cc7m-p8vv.json b/advisories/unreviewed/2024/03/GHSA-rfr4-cc7m-p8vv/GHSA-rfr4-cc7m-p8vv.json index 5923ff87d57..c7cac0a0c86 100644 --- a/advisories/unreviewed/2024/03/GHSA-rfr4-cc7m-p8vv/GHSA-rfr4-cc7m-p8vv.json +++ b/advisories/unreviewed/2024/03/GHSA-rfr4-cc7m-p8vv/GHSA-rfr4-cc7m-p8vv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2xh5-h62m-35rc/GHSA-2xh5-h62m-35rc.json b/advisories/unreviewed/2024/04/GHSA-2xh5-h62m-35rc/GHSA-2xh5-h62m-35rc.json index 76416a00b86..1f13d6a74a8 100644 --- a/advisories/unreviewed/2024/04/GHSA-2xh5-h62m-35rc/GHSA-2xh5-h62m-35rc.json +++ b/advisories/unreviewed/2024/04/GHSA-2xh5-h62m-35rc/GHSA-2xh5-h62m-35rc.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-3r7v-265j-fg8v/GHSA-3r7v-265j-fg8v.json b/advisories/unreviewed/2024/04/GHSA-3r7v-265j-fg8v/GHSA-3r7v-265j-fg8v.json index 7525fabb623..4601c666f13 100644 --- a/advisories/unreviewed/2024/04/GHSA-3r7v-265j-fg8v/GHSA-3r7v-265j-fg8v.json +++ b/advisories/unreviewed/2024/04/GHSA-3r7v-265j-fg8v/GHSA-3r7v-265j-fg8v.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5mpc-fr5x-rq6g/GHSA-5mpc-fr5x-rq6g.json b/advisories/unreviewed/2024/04/GHSA-5mpc-fr5x-rq6g/GHSA-5mpc-fr5x-rq6g.json index 0d404badd51..aaf14364246 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mpc-fr5x-rq6g/GHSA-5mpc-fr5x-rq6g.json +++ b/advisories/unreviewed/2024/04/GHSA-5mpc-fr5x-rq6g/GHSA-5mpc-fr5x-rq6g.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json index 535aa9198fa..e0757f1ef86 100644 --- a/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json +++ b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c2jf-mjc7-c377/GHSA-c2jf-mjc7-c377.json b/advisories/unreviewed/2024/04/GHSA-c2jf-mjc7-c377/GHSA-c2jf-mjc7-c377.json index 448fb75b50c..c673a279a1d 100644 --- a/advisories/unreviewed/2024/04/GHSA-c2jf-mjc7-c377/GHSA-c2jf-mjc7-c377.json +++ b/advisories/unreviewed/2024/04/GHSA-c2jf-mjc7-c377/GHSA-c2jf-mjc7-c377.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-chvx-77g5-qh6v/GHSA-chvx-77g5-qh6v.json b/advisories/unreviewed/2024/04/GHSA-chvx-77g5-qh6v/GHSA-chvx-77g5-qh6v.json index b451e0d6dd9..81f1fcb8fef 100644 --- a/advisories/unreviewed/2024/04/GHSA-chvx-77g5-qh6v/GHSA-chvx-77g5-qh6v.json +++ b/advisories/unreviewed/2024/04/GHSA-chvx-77g5-qh6v/GHSA-chvx-77g5-qh6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chvx-77g5-qh6v", - "modified": "2024-04-25T12:30:49Z", + "modified": "2025-01-15T21:31:39Z", "published": "2024-04-25T12:30:49Z", "aliases": [ "CVE-2024-3994" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-cw57-3gg4-75xr/GHSA-cw57-3gg4-75xr.json b/advisories/unreviewed/2024/04/GHSA-cw57-3gg4-75xr/GHSA-cw57-3gg4-75xr.json index fd528322626..bff8a8d6aa2 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw57-3gg4-75xr/GHSA-cw57-3gg4-75xr.json +++ b/advisories/unreviewed/2024/04/GHSA-cw57-3gg4-75xr/GHSA-cw57-3gg4-75xr.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-g22h-xh6j-cgc7/GHSA-g22h-xh6j-cgc7.json b/advisories/unreviewed/2024/04/GHSA-g22h-xh6j-cgc7/GHSA-g22h-xh6j-cgc7.json index e09323db45b..945da71ca6d 100644 --- a/advisories/unreviewed/2024/04/GHSA-g22h-xh6j-cgc7/GHSA-g22h-xh6j-cgc7.json +++ b/advisories/unreviewed/2024/04/GHSA-g22h-xh6j-cgc7/GHSA-g22h-xh6j-cgc7.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-g2cq-r84h-65g2/GHSA-g2cq-r84h-65g2.json b/advisories/unreviewed/2024/04/GHSA-g2cq-r84h-65g2/GHSA-g2cq-r84h-65g2.json index 3fad8b4928a..d2c7790ff59 100644 --- a/advisories/unreviewed/2024/04/GHSA-g2cq-r84h-65g2/GHSA-g2cq-r84h-65g2.json +++ b/advisories/unreviewed/2024/04/GHSA-g2cq-r84h-65g2/GHSA-g2cq-r84h-65g2.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-m99h-pw7x-qh77/GHSA-m99h-pw7x-qh77.json b/advisories/unreviewed/2024/04/GHSA-m99h-pw7x-qh77/GHSA-m99h-pw7x-qh77.json index 7f7f93c3e5e..39441a250bd 100644 --- a/advisories/unreviewed/2024/04/GHSA-m99h-pw7x-qh77/GHSA-m99h-pw7x-qh77.json +++ b/advisories/unreviewed/2024/04/GHSA-m99h-pw7x-qh77/GHSA-m99h-pw7x-qh77.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-mwvg-g633-qqcv/GHSA-mwvg-g633-qqcv.json b/advisories/unreviewed/2024/04/GHSA-mwvg-g633-qqcv/GHSA-mwvg-g633-qqcv.json index c151ced7268..143d5bf7b39 100644 --- a/advisories/unreviewed/2024/04/GHSA-mwvg-g633-qqcv/GHSA-mwvg-g633-qqcv.json +++ b/advisories/unreviewed/2024/04/GHSA-mwvg-g633-qqcv/GHSA-mwvg-g633-qqcv.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-qxrm-rjv7-w3rx/GHSA-qxrm-rjv7-w3rx.json b/advisories/unreviewed/2024/04/GHSA-qxrm-rjv7-w3rx/GHSA-qxrm-rjv7-w3rx.json index 33dd18dc0ad..a530b4cfb60 100644 --- a/advisories/unreviewed/2024/04/GHSA-qxrm-rjv7-w3rx/GHSA-qxrm-rjv7-w3rx.json +++ b/advisories/unreviewed/2024/04/GHSA-qxrm-rjv7-w3rx/GHSA-qxrm-rjv7-w3rx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wgf6-mh23-5m7q/GHSA-wgf6-mh23-5m7q.json b/advisories/unreviewed/2024/04/GHSA-wgf6-mh23-5m7q/GHSA-wgf6-mh23-5m7q.json index 89763d4080e..3f713f710e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-wgf6-mh23-5m7q/GHSA-wgf6-mh23-5m7q.json +++ b/advisories/unreviewed/2024/04/GHSA-wgf6-mh23-5m7q/GHSA-wgf6-mh23-5m7q.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wm4x-ppr8-vvq4/GHSA-wm4x-ppr8-vvq4.json b/advisories/unreviewed/2024/04/GHSA-wm4x-ppr8-vvq4/GHSA-wm4x-ppr8-vvq4.json index d520457f20b..779c5c417e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm4x-ppr8-vvq4/GHSA-wm4x-ppr8-vvq4.json +++ b/advisories/unreviewed/2024/04/GHSA-wm4x-ppr8-vvq4/GHSA-wm4x-ppr8-vvq4.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-xwv9-fcr7-mxqx/GHSA-xwv9-fcr7-mxqx.json b/advisories/unreviewed/2024/04/GHSA-xwv9-fcr7-mxqx/GHSA-xwv9-fcr7-mxqx.json index 293931f15dd..d4b0cdc10ae 100644 --- a/advisories/unreviewed/2024/04/GHSA-xwv9-fcr7-mxqx/GHSA-xwv9-fcr7-mxqx.json +++ b/advisories/unreviewed/2024/04/GHSA-xwv9-fcr7-mxqx/GHSA-xwv9-fcr7-mxqx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4h95-2x33-pw42/GHSA-4h95-2x33-pw42.json b/advisories/unreviewed/2024/05/GHSA-4h95-2x33-pw42/GHSA-4h95-2x33-pw42.json index 74b452a2f2a..6fe00b64c7f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4h95-2x33-pw42/GHSA-4h95-2x33-pw42.json +++ b/advisories/unreviewed/2024/05/GHSA-4h95-2x33-pw42/GHSA-4h95-2x33-pw42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h95-2x33-pw42", - "modified": "2024-05-14T18:30:55Z", + "modified": "2025-01-15T21:31:39Z", "published": "2024-05-14T18:30:55Z", "aliases": [ "CVE-2024-4434" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-576v-pqr8-c2mq/GHSA-576v-pqr8-c2mq.json b/advisories/unreviewed/2024/05/GHSA-576v-pqr8-c2mq/GHSA-576v-pqr8-c2mq.json index 492e88696b3..a76536c0028 100644 --- a/advisories/unreviewed/2024/05/GHSA-576v-pqr8-c2mq/GHSA-576v-pqr8-c2mq.json +++ b/advisories/unreviewed/2024/05/GHSA-576v-pqr8-c2mq/GHSA-576v-pqr8-c2mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-576v-pqr8-c2mq", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-01-15T21:31:39Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3553" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8jjw-j8rj-43xm/GHSA-8jjw-j8rj-43xm.json b/advisories/unreviewed/2024/05/GHSA-8jjw-j8rj-43xm/GHSA-8jjw-j8rj-43xm.json index 26d19471267..090fe1bd982 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jjw-j8rj-43xm/GHSA-8jjw-j8rj-43xm.json +++ b/advisories/unreviewed/2024/05/GHSA-8jjw-j8rj-43xm/GHSA-8jjw-j8rj-43xm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jjw-j8rj-43xm", - "modified": "2024-05-14T18:30:54Z", + "modified": "2025-01-15T21:31:39Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4277" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v42x-qjv5-q9c2/GHSA-v42x-qjv5-q9c2.json b/advisories/unreviewed/2024/05/GHSA-v42x-qjv5-q9c2/GHSA-v42x-qjv5-q9c2.json index 121d58ef662..28ff45f538b 100644 --- a/advisories/unreviewed/2024/05/GHSA-v42x-qjv5-q9c2/GHSA-v42x-qjv5-q9c2.json +++ b/advisories/unreviewed/2024/05/GHSA-v42x-qjv5-q9c2/GHSA-v42x-qjv5-q9c2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v42x-qjv5-q9c2", - "modified": "2024-05-14T18:30:54Z", + "modified": "2025-01-15T21:31:39Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4397" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json b/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json index cd1fe6c174c..243ece9c0f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json +++ b/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjr2-g37g-hrjm", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-15T21:31:40Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47463" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/secretmem: fix NULL page->mapping dereference in page_is_secretmem()\n\nCheck for a NULL page->mapping before dereferencing the mapping in\npage_is_secretmem(), as the page's mapping can be nullified while gup()\nis running, e.g. by reclaim or truncation.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000068\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 6 PID: 4173897 Comm: CPU 3/KVM Tainted: G W\n RIP: 0010:internal_get_user_pages_fast+0x621/0x9d0\n Code: <48> 81 7a 68 80 08 04 bc 0f 85 21 ff ff 8 89 c7 be\n RSP: 0018:ffffaa90087679b0 EFLAGS: 00010046\n RAX: ffffe3f37905b900 RBX: 00007f2dd561e000 RCX: ffffe3f37905b934\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffe3f37905b900\n ...\n CR2: 0000000000000068 CR3: 00000004c5898003 CR4: 00000000001726e0\n Call Trace:\n get_user_pages_fast_only+0x13/0x20\n hva_to_pfn+0xa9/0x3e0\n try_async_pf+0xa1/0x270\n direct_page_fault+0x113/0xad0\n kvm_mmu_page_fault+0x69/0x680\n vmx_handle_exit+0xe1/0x5d0\n kvm_arch_vcpu_ioctl_run+0xd81/0x1c70\n kvm_vcpu_ioctl+0x267/0x670\n __x64_sys_ioctl+0x83/0xa0\n do_syscall_64+0x56/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fpcp-87j2-pf32/GHSA-fpcp-87j2-pf32.json b/advisories/unreviewed/2024/12/GHSA-fpcp-87j2-pf32/GHSA-fpcp-87j2-pf32.json index addaccf6246..51dfb9bfbee 100644 --- a/advisories/unreviewed/2024/12/GHSA-fpcp-87j2-pf32/GHSA-fpcp-87j2-pf32.json +++ b/advisories/unreviewed/2024/12/GHSA-fpcp-87j2-pf32/GHSA-fpcp-87j2-pf32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpcp-87j2-pf32", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-15T21:31:40Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53188" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix crash when unbinding\n\nIf there is an error during some initialization related to firmware,\nthe function ath12k_dp_cc_cleanup is called to release resources.\nHowever this is released again when the device is unbinded (ath12k_pci),\nand we get:\nBUG: kernel NULL pointer dereference, address: 0000000000000020\nat RIP: 0010:ath12k_dp_cc_cleanup.part.0+0xb6/0x500 [ath12k]\nCall Trace:\nath12k_dp_cc_cleanup\nath12k_dp_free\nath12k_core_deinit\nath12k_pci_remove\n...\n\nThe issue is always reproducible from a VM because the MSI addressing\ninitialization is failing.\n\nIn order to fix the issue, just set to NULL the released structure in\nath12k_dp_cc_cleanup at the end.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qvfp-2hw2-qffh/GHSA-qvfp-2hw2-qffh.json b/advisories/unreviewed/2024/12/GHSA-qvfp-2hw2-qffh/GHSA-qvfp-2hw2-qffh.json index e3dd34e5308..fc98cc54787 100644 --- a/advisories/unreviewed/2024/12/GHSA-qvfp-2hw2-qffh/GHSA-qvfp-2hw2-qffh.json +++ b/advisories/unreviewed/2024/12/GHSA-qvfp-2hw2-qffh/GHSA-qvfp-2hw2-qffh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvfp-2hw2-qffh", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-15T21:31:40Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56553" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix memleak of proc->delivered_freeze\n\nIf a freeze notification is cleared with BC_CLEAR_FREEZE_NOTIFICATION\nbefore calling binder_freeze_notification_done(), then it is detached\nfrom its reference (e.g. ref->freeze) but the work remains queued in\nproc->delivered_freeze. This leads to a memory leak when the process\nexits as any pending entries in proc->delivered_freeze are not freed:\n\n unreferenced object 0xffff38e8cfa36180 (size 64):\n comm \"binder-util\", pid 655, jiffies 4294936641\n hex dump (first 32 bytes):\n b8 e9 9e c8 e8 38 ff ff b8 e9 9e c8 e8 38 ff ff .....8.......8..\n 0b 00 00 00 00 00 00 00 3c 1f 4b 00 00 00 00 00 ........<.K.....\n backtrace (crc 95983b32):\n [<000000000d0582cf>] kmemleak_alloc+0x34/0x40\n [<000000009c99a513>] __kmalloc_cache_noprof+0x208/0x280\n [<00000000313b1704>] binder_thread_write+0xdec/0x439c\n [<000000000cbd33bb>] binder_ioctl+0x1b68/0x22cc\n [<000000002bbedeeb>] __arm64_sys_ioctl+0x124/0x190\n [<00000000b439adee>] invoke_syscall+0x6c/0x254\n [<00000000173558fc>] el0_svc_common.constprop.0+0xac/0x230\n [<0000000084f72311>] do_el0_svc+0x40/0x58\n [<000000008b872457>] el0_svc+0x38/0x78\n [<00000000ee778653>] el0t_64_sync_handler+0x120/0x12c\n [<00000000a8ec61bf>] el0t_64_sync+0x190/0x194\n\nThis patch fixes the leak by ensuring that any pending entries in\nproc->delivered_freeze are freed during binder_deferred_release().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vv3w-8397-5q9f/GHSA-vv3w-8397-5q9f.json b/advisories/unreviewed/2024/12/GHSA-vv3w-8397-5q9f/GHSA-vv3w-8397-5q9f.json index e810c6738f0..efec3a4f2ed 100644 --- a/advisories/unreviewed/2024/12/GHSA-vv3w-8397-5q9f/GHSA-vv3w-8397-5q9f.json +++ b/advisories/unreviewed/2024/12/GHSA-vv3w-8397-5q9f/GHSA-vv3w-8397-5q9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vv3w-8397-5q9f", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-15T21:31:40Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56629" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: fix when get product name maybe null pointer\n\nDue to incorrect dev->product reporting by certain devices, null\npointer dereferences occur when dev->product is empty, leading to\npotential system crashes.\n\nThis issue was found on EXCELSIOR DL37-D05 device with\nLoongson-LS3A6000-7A2000-DL37 motherboard.\n\nKernel logs:\n[ 56.470885] usb 4-3: new full-speed USB device number 4 using ohci-pci\n[ 56.671638] usb 4-3: string descriptor 0 read error: -22\n[ 56.671644] usb 4-3: New USB device found, idVendor=056a, idProduct=0374, bcdDevice= 1.07\n[ 56.671647] usb 4-3: New USB device strings: Mfr=1, Product=2, SerialNumber=3\n[ 56.678839] hid-generic 0003:056A:0374.0004: hiddev0,hidraw3: USB HID v1.10 Device [HID 056a:0374] on usb-0000:00:05.0-3/input0\n[ 56.697719] CPU 2 Unable to handle kernel paging request at virtual address 0000000000000000, era == 90000000066e35c8, ra == ffff800004f98a80\n[ 56.697732] Oops[#1]:\n[ 56.697734] CPU: 2 PID: 2742 Comm: (udev-worker) Tainted: G OE 6.6.0-loong64-desktop #25.00.2000.015\n[ 56.697737] Hardware name: Inspur CE520L2/C09901N000000000, BIOS 2.09.00 10/11/2024\n[ 56.697739] pc 90000000066e35c8 ra ffff800004f98a80 tp 9000000125478000 sp 900000012547b8a0\n[ 56.697741] a0 0000000000000000 a1 ffff800004818b28 a2 0000000000000000 a3 0000000000000000\n[ 56.697743] a4 900000012547b8f0 a5 0000000000000000 a6 0000000000000000 a7 0000000000000000\n[ 56.697745] t0 ffff800004818b2d t1 0000000000000000 t2 0000000000000003 t3 0000000000000005\n[ 56.697747] t4 0000000000000000 t5 0000000000000000 t6 0000000000000000 t7 0000000000000000\n[ 56.697748] t8 0000000000000000 u0 0000000000000000 s9 0000000000000000 s0 900000011aa48028\n[ 56.697750] s1 0000000000000000 s2 0000000000000000 s3 ffff800004818e80 s4 ffff800004810000\n[ 56.697751] s5 90000001000b98d0 s6 ffff800004811f88 s7 ffff800005470440 s8 0000000000000000\n[ 56.697753] ra: ffff800004f98a80 wacom_update_name+0xe0/0x300 [wacom]\n[ 56.697802] ERA: 90000000066e35c8 strstr+0x28/0x120\n[ 56.697806] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n[ 56.697816] PRMD: 0000000c (PPLV0 +PIE +PWE)\n[ 56.697821] EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n[ 56.697827] ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n[ 56.697831] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0)\n[ 56.697835] BADV: 0000000000000000\n[ 56.697836] PRID: 0014d000 (Loongson-64bit, Loongson-3A6000)\n[ 56.697838] Modules linked in: wacom(+) bnep bluetooth rfkill qrtr nls_iso8859_1 nls_cp437 snd_hda_codec_conexant snd_hda_codec_generic ledtrig_audio snd_hda_codec_hdmi snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core snd_hwdep snd_pcm snd_timer snd soundcore input_leds mousedev led_class joydev deepin_netmonitor(OE) fuse nfnetlink dmi_sysfs ip_tables x_tables overlay amdgpu amdxcp drm_exec gpu_sched drm_buddy radeon drm_suballoc_helper i2c_algo_bit drm_ttm_helper r8169 ttm drm_display_helper spi_loongson_pci xhci_pci cec xhci_pci_renesas spi_loongson_core hid_generic realtek gpio_loongson_64bit\n[ 56.697887] Process (udev-worker) (pid: 2742, threadinfo=00000000aee0d8b4, task=00000000a9eff1f3)\n[ 56.697890] Stack : 0000000000000000 ffff800004817e00 0000000000000000 0000251c00000000\n[ 56.697896] 0000000000000000 00000011fffffffd 0000000000000000 0000000000000000\n[ 56.697901] 0000000000000000 1b67a968695184b9 0000000000000000 90000001000b98d0\n[ 56.697906] 90000001000bb8d0 900000011aa48028 0000000000000000 ffff800004f9d74c\n[ 56.697911] 90000001000ba000 ffff800004f9ce58 0000000000000000 ffff800005470440\n[ 56.697916] ffff800004811f88 90000001000b98d0 9000000100da2aa8 90000001000bb8d0\n[ 56.697921] 0000000000000000 90000001000ba000 900000011aa48028 ffff800004f9d74c\n[ 56.697926] ffff8000054704e8 90000001000bb8b8 90000001000ba000 0000000000000000\n[ 56.697931] 90000001000bb8d0 \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:22Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4cxr-9fjv-2m3m/GHSA-4cxr-9fjv-2m3m.json b/advisories/unreviewed/2025/01/GHSA-4cxr-9fjv-2m3m/GHSA-4cxr-9fjv-2m3m.json new file mode 100644 index 00000000000..f9d87b18150 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cxr-9fjv-2m3m/GHSA-4cxr-9fjv-2m3m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cxr-9fjv-2m3m", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2024-48121" + ], + "details": "The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48121" + }, + { + "type": "WEB", + "url": "https://kth.diva-portal.org/smash/get/diva2:1876534/FULLTEXT01.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4gm2-58wx-3vqm/GHSA-4gm2-58wx-3vqm.json b/advisories/unreviewed/2025/01/GHSA-4gm2-58wx-3vqm/GHSA-4gm2-58wx-3vqm.json new file mode 100644 index 00000000000..8ef9fe813d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4gm2-58wx-3vqm/GHSA-4gm2-58wx-3vqm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gm2-58wx-3vqm", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2024-48126" + ], + "details": "HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48126" + }, + { + "type": "WEB", + "url": "https://kth.diva-portal.org/smash/get/diva2:1876534/FULLTEXT01.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json b/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json new file mode 100644 index 00000000000..024a765744c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-55ww-9933-hhf5/GHSA-55ww-9933-hhf5.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55ww-9933-hhf5", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2024-27856" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27856" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120896" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120898" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120901" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120902" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120903" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120905" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120906" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8v2j-g4fg-rvqc/GHSA-8v2j-g4fg-rvqc.json b/advisories/unreviewed/2025/01/GHSA-8v2j-g4fg-rvqc/GHSA-8v2j-g4fg-rvqc.json new file mode 100644 index 00000000000..8eac5fc673d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8v2j-g4fg-rvqc/GHSA-8v2j-g4fg-rvqc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v2j-g4fg-rvqc", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2025-0483" + ], + "details": "A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects unknown code of the file /fladmin/jump.php. The manipulation of the argument message/error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0483" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/5" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/5#issue-2769894596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291928" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291928" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475240" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8w9w-hrff-vhqw/GHSA-8w9w-hrff-vhqw.json b/advisories/unreviewed/2025/01/GHSA-8w9w-hrff-vhqw/GHSA-8w9w-hrff-vhqw.json new file mode 100644 index 00000000000..a2eeb6264e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8w9w-hrff-vhqw/GHSA-8w9w-hrff-vhqw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w9w-hrff-vhqw", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2024-54470" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1. An attacker with physical access may be able to access contacts from the lock screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54470" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121567" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8x8q-89w8-f24c/GHSA-8x8q-89w8-f24c.json b/advisories/unreviewed/2025/01/GHSA-8x8q-89w8-f24c/GHSA-8x8q-89w8-f24c.json new file mode 100644 index 00000000000..0ba7c2cc83c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8x8q-89w8-f24c/GHSA-8x8q-89w8-f24c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x8q-89w8-f24c", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2025-0501" + ], + "details": "An issue in the native clients for Amazon WorkSpaces Clients when running PCoIP protocol may allow an attacker to access remote sessions via man-in-the-middle.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0501" + }, + { + "type": "WEB", + "url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json b/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json index 91789c2ee92..ffccd689729 100644 --- a/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json +++ b/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92r5-r4ww-c543", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-15T21:31:40Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-57211" ], "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T17:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-99ph-c47h-7pf8/GHSA-99ph-c47h-7pf8.json b/advisories/unreviewed/2025/01/GHSA-99ph-c47h-7pf8/GHSA-99ph-c47h-7pf8.json new file mode 100644 index 00000000000..d7fb51e5446 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-99ph-c47h-7pf8/GHSA-99ph-c47h-7pf8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99ph-c47h-7pf8", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2025-0500" + ], + "details": "An issue in the native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0500" + }, + { + "type": "WEB", + "url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cp3h-93gm-48g5/GHSA-cp3h-93gm-48g5.json b/advisories/unreviewed/2025/01/GHSA-cp3h-93gm-48g5/GHSA-cp3h-93gm-48g5.json new file mode 100644 index 00000000000..8a1ebb24459 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cp3h-93gm-48g5/GHSA-cp3h-93gm-48g5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp3h-93gm-48g5", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2025-0487" + ], + "details": "A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /fladmin/cat_edit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0487" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/9" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/9#issue-2769962332" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291932" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291932" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json b/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json index 895fc6949e5..92b4209cfc1 100644 --- a/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json +++ b/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cp64-2mhv-pqv9", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-15T21:31:40Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-57226" ], "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T18:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f647-hv7f-cm73/GHSA-f647-hv7f-cm73.json b/advisories/unreviewed/2025/01/GHSA-f647-hv7f-cm73/GHSA-f647-hv7f-cm73.json new file mode 100644 index 00000000000..67733af2a12 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f647-hv7f-cm73/GHSA-f647-hv7f-cm73.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f647-hv7f-cm73", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2024-54535" + ], + "details": "A path handling issue was addressed with improved logic. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An attacker with access to calendar data could also read reminders.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54535" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121565" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121566" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json new file mode 100644 index 00000000000..573e2f2aff5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f69c-c87p-g4rh", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2024-44136" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44136" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120905" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f9hh-982g-8cwq/GHSA-f9hh-982g-8cwq.json b/advisories/unreviewed/2025/01/GHSA-f9hh-982g-8cwq/GHSA-f9hh-982g-8cwq.json new file mode 100644 index 00000000000..63cbaf374e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f9hh-982g-8cwq/GHSA-f9hh-982g-8cwq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9hh-982g-8cwq", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2025-0484" + ], + "details": "A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin/sysconfig_doedit.php of the component Backend. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0484" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/6" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/6#issue-2769903928" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291929" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291929" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmxc-p474-p2pp/GHSA-fmxc-p474-p2pp.json b/advisories/unreviewed/2025/01/GHSA-fmxc-p474-p2pp/GHSA-fmxc-p474-p2pp.json new file mode 100644 index 00000000000..fa23d6c461f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmxc-p474-p2pp/GHSA-fmxc-p474-p2pp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxc-p474-p2pp", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2024-48123" + ], + "details": "An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48123" + }, + { + "type": "WEB", + "url": "https://kth.diva-portal.org/smash/get/diva2:1876534/FULLTEXT01.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gf42-x7c4-vmr8/GHSA-gf42-x7c4-vmr8.json b/advisories/unreviewed/2025/01/GHSA-gf42-x7c4-vmr8/GHSA-gf42-x7c4-vmr8.json new file mode 100644 index 00000000000..da3bef15675 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gf42-x7c4-vmr8/GHSA-gf42-x7c4-vmr8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf42-x7c4-vmr8", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2024-40839" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120905" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-grr8-7xf6-xmc7/GHSA-grr8-7xf6-xmc7.json b/advisories/unreviewed/2025/01/GHSA-grr8-7xf6-xmc7/GHSA-grr8-7xf6-xmc7.json new file mode 100644 index 00000000000..88b67b9d003 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-grr8-7xf6-xmc7/GHSA-grr8-7xf6-xmc7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grr8-7xf6-xmc7", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2024-48122" + ], + "details": "Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to root-level privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48122" + }, + { + "type": "WEB", + "url": "https://kth.diva-portal.org/smash/get/diva2:1876534/FULLTEXT01.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hg4r-9c4x-96jw/GHSA-hg4r-9c4x-96jw.json b/advisories/unreviewed/2025/01/GHSA-hg4r-9c4x-96jw/GHSA-hg4r-9c4x-96jw.json index b57fc67520f..9321c2131e8 100644 --- a/advisories/unreviewed/2025/01/GHSA-hg4r-9c4x-96jw/GHSA-hg4r-9c4x-96jw.json +++ b/advisories/unreviewed/2025/01/GHSA-hg4r-9c4x-96jw/GHSA-hg4r-9c4x-96jw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hg4r-9c4x-96jw", - "modified": "2025-01-15T00:30:41Z", + "modified": "2025-01-15T21:31:41Z", "published": "2025-01-15T00:30:41Z", "aliases": [ "CVE-2024-50859" ], "details": "The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T22:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json b/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json new file mode 100644 index 00000000000..5ef93009259 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jw5g-j894-hv7p/GHSA-jw5g-j894-hv7p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw5g-j894-hv7p", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2024-54540" + ], + "details": "The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54540" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122043" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p8qr-ww3f-6mvm/GHSA-p8qr-ww3f-6mvm.json b/advisories/unreviewed/2025/01/GHSA-p8qr-ww3f-6mvm/GHSA-p8qr-ww3f-6mvm.json new file mode 100644 index 00000000000..9ef2f3de9b9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p8qr-ww3f-6mvm/GHSA-p8qr-ww3f-6mvm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8qr-ww3f-6mvm", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2025-0482" + ], + "details": "A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0482" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/4" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/4#issue-2769866348" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475237" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q2m7-hvgr-h9fm/GHSA-q2m7-hvgr-h9fm.json b/advisories/unreviewed/2025/01/GHSA-q2m7-hvgr-h9fm/GHSA-q2m7-hvgr-h9fm.json new file mode 100644 index 00000000000..82b855db298 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q2m7-hvgr-h9fm/GHSA-q2m7-hvgr-h9fm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2m7-hvgr-h9fm", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2025-0486" + ], + "details": "A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fladmin/login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0486" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/8" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/8#issue-2769942639" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291931" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291931" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json b/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json index ac25d7130c5..0d1113884c1 100644 --- a/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json +++ b/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qf55-97mm-vqcj", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-15T21:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-54887" ], "details": "TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json b/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json new file mode 100644 index 00000000000..048d7f439ab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhv7-wrpv-c54g", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2024-48125" + ], + "details": "An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol requests.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48125" + }, + { + "type": "WEB", + "url": "https://kth.diva-portal.org/smash/get/diva2:1876534/FULLTEXT01.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r2fr-78p9-w3pq/GHSA-r2fr-78p9-w3pq.json b/advisories/unreviewed/2025/01/GHSA-r2fr-78p9-w3pq/GHSA-r2fr-78p9-w3pq.json new file mode 100644 index 00000000000..f6f8d2a546c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r2fr-78p9-w3pq/GHSA-r2fr-78p9-w3pq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2fr-78p9-w3pq", + "modified": "2025-01-15T21:31:43Z", + "published": "2025-01-15T21:31:43Z", + "aliases": [ + "CVE-2025-0488" + ], + "details": "A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0488" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/10" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/10#issue-2769983658" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rwv9-c467-fc89/GHSA-rwv9-c467-fc89.json b/advisories/unreviewed/2025/01/GHSA-rwv9-c467-fc89/GHSA-rwv9-c467-fc89.json new file mode 100644 index 00000000000..54f83acbb9a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rwv9-c467-fc89/GHSA-rwv9-c467-fc89.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwv9-c467-fc89", + "modified": "2025-01-15T21:31:42Z", + "published": "2025-01-15T21:31:42Z", + "aliases": [ + "CVE-2025-0485" + ], + "details": "A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown function of the file /fladmin/sysconfig_doedit.php. The manipulation of the argument info leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0485" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/7" + }, + { + "type": "WEB", + "url": "https://github.com/Fanli2012/native-php-cms/issues/7#issue-2769919832" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291930" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291930" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475247" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfh4-5f9p-v75j/GHSA-vfh4-5f9p-v75j.json b/advisories/unreviewed/2025/01/GHSA-vfh4-5f9p-v75j/GHSA-vfh4-5f9p-v75j.json new file mode 100644 index 00000000000..b8bdfefb479 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfh4-5f9p-v75j/GHSA-vfh4-5f9p-v75j.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfh4-5f9p-v75j", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2024-40771" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, watchOS 10.5, tvOS 17.5, macOS Ventura 13.6.7, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40771" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120898" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120899" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120900" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120901" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120902" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120903" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120905" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120906" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w896-hq9g-5qc9/GHSA-w896-hq9g-5qc9.json b/advisories/unreviewed/2025/01/GHSA-w896-hq9g-5qc9/GHSA-w896-hq9g-5qc9.json new file mode 100644 index 00000000000..fe3226f8a82 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w896-hq9g-5qc9/GHSA-w896-hq9g-5qc9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w896-hq9g-5qc9", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2025-0481" + ], + "details": "A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0481" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-878/dllog.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475011" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wrxp-6gw7-g9fx/GHSA-wrxp-6gw7-g9fx.json b/advisories/unreviewed/2025/01/GHSA-wrxp-6gw7-g9fx/GHSA-wrxp-6gw7-g9fx.json new file mode 100644 index 00000000000..f3a6883924f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wrxp-6gw7-g9fx/GHSA-wrxp-6gw7-g9fx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrxp-6gw7-g9fx", + "modified": "2025-01-15T21:31:41Z", + "published": "2025-01-15T21:31:41Z", + "aliases": [ + "CVE-2024-40854" + ], + "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpected system termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40854" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121563" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121567" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121568" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121570" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7fx-57rj-7whh/GHSA-x7fx-57rj-7whh.json b/advisories/unreviewed/2025/01/GHSA-x7fx-57rj-7whh/GHSA-x7fx-57rj-7whh.json index d2cc24ee8a6..9ddff5c0636 100644 --- a/advisories/unreviewed/2025/01/GHSA-x7fx-57rj-7whh/GHSA-x7fx-57rj-7whh.json +++ b/advisories/unreviewed/2025/01/GHSA-x7fx-57rj-7whh/GHSA-x7fx-57rj-7whh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7fx-57rj-7whh", - "modified": "2025-01-15T00:30:41Z", + "modified": "2025-01-15T21:31:41Z", "published": "2025-01-15T00:30:41Z", "aliases": [ "CVE-2024-50857" ], "details": "The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T22:15:27Z"