From b3a5834ac18a536127f1ee8bc37a78431d99bdc9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 May 2025 09:33:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9589-mpwg-8xq6.json | 10 ++++- .../GHSA-f4vp-qjpg-x8wq.json | 10 ++++- .../GHSA-fp4x-j6ch-w8q5.json | 10 ++++- .../GHSA-pr7v-prvv-52v8.json | 10 ++++- .../GHSA-pv37-78jj-hvqv.json | 10 ++++- .../GHSA-26p9-7f96-xrcg.json | 34 ++++++++++++++ .../GHSA-2mqx-xpw9-6crj.json | 36 +++++++++++++++ .../GHSA-2p7w-jv73-hf6h.json | 36 +++++++++++++++ .../GHSA-3827-2vw5-3pm3.json | 36 +++++++++++++++ .../GHSA-3jxj-2fmg-wg9x.json | 36 +++++++++++++++ .../GHSA-4f32-q83j-5vfj.json | 36 +++++++++++++++ .../GHSA-4v5h-q8j3-g849.json | 34 ++++++++++++++ .../GHSA-5fr6-q8mw-fx75.json | 34 ++++++++++++++ .../GHSA-5r56-v3jw-7756.json | 34 ++++++++++++++ .../GHSA-6688-xwmm-27mr.json | 34 ++++++++++++++ .../GHSA-6q4v-6637-v9c9.json | 34 ++++++++++++++ .../GHSA-6vqp-97x2-9w68.json | 34 ++++++++++++++ .../GHSA-72gp-564x-qvpp.json | 34 ++++++++++++++ .../GHSA-84m5-5vgj-8qr2.json | 34 ++++++++++++++ .../GHSA-8758-9gxm-jcpf.json | 34 ++++++++++++++ .../GHSA-8j9x-j56g-p6pf.json | 34 ++++++++++++++ .../GHSA-8qpj-mfhj-m8h3.json | 34 ++++++++++++++ .../GHSA-8qqq-69r5-mv6r.json | 34 ++++++++++++++ .../GHSA-8rvc-mwwg-mp37.json | 34 ++++++++++++++ .../GHSA-97ff-chjc-r365.json | 34 ++++++++++++++ .../GHSA-9q6r-mr8j-x88j.json | 36 +++++++++++++++ .../GHSA-c56p-5rjc-7858.json | 34 ++++++++++++++ .../GHSA-c68v-cf88-8w65.json | 36 +++++++++++++++ .../GHSA-cjqg-w438-4fr8.json | 34 ++++++++++++++ .../GHSA-crjp-8g5r-p85r.json | 34 ++++++++++++++ .../GHSA-f3f4-3g45-5gh4.json | 34 ++++++++++++++ .../GHSA-g2w4-f56h-2wj6.json | 34 ++++++++++++++ .../GHSA-gjrf-jj6g-9jfj.json | 34 ++++++++++++++ .../GHSA-grvj-cc9v-jh9r.json | 36 +++++++++++++++ .../GHSA-hr5v-cxwr-h392.json | 36 +++++++++++++++ .../GHSA-j33m-6826-95m2.json | 34 ++++++++++++++ .../GHSA-j6c5-42fq-c3hr.json | 36 +++++++++++++++ .../GHSA-jg34-99pf-2cmp.json | 34 ++++++++++++++ .../GHSA-jm7c-x6r9-pc54.json | 36 +++++++++++++++ .../GHSA-m4g3-g4fm-5v88.json | 34 ++++++++++++++ .../GHSA-mccx-692g-vmcf.json | 1 + .../GHSA-mwpv-wfv8-f2x8.json | 34 ++++++++++++++ .../GHSA-qpv3-3px8-gmhc.json | 44 +++++++++++++++++++ .../GHSA-qx88-qw7m-mgq7.json | 34 ++++++++++++++ .../GHSA-r9w7-5f7h-f659.json | 36 +++++++++++++++ .../GHSA-rh9j-3chv-xw4h.json | 36 +++++++++++++++ .../GHSA-v6w6-862c-c8mm.json | 36 +++++++++++++++ .../GHSA-vp6c-cpgr-622f.json | 36 +++++++++++++++ .../GHSA-w584-3vj6-7f7f.json | 34 ++++++++++++++ .../GHSA-w6xc-89xr-622v.json | 36 +++++++++++++++ .../GHSA-w9c2-jr2q-g6xq.json | 40 +++++++++++++++++ .../GHSA-whmx-vmqq-mjpv.json | 34 ++++++++++++++ .../GHSA-whrv-65gc-prq2.json | 34 ++++++++++++++ .../GHSA-whxr-3p84-rf3c.json | 40 +++++++++++++++++ .../GHSA-x8j6-f4cg-fvh2.json | 34 ++++++++++++++ .../GHSA-xfj9-6phw-wqfj.json | 36 +++++++++++++++ 56 files changed, 1802 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-26p9-7f96-xrcg/GHSA-26p9-7f96-xrcg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2mqx-xpw9-6crj/GHSA-2mqx-xpw9-6crj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2p7w-jv73-hf6h/GHSA-2p7w-jv73-hf6h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3827-2vw5-3pm3/GHSA-3827-2vw5-3pm3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4v5h-q8j3-g849/GHSA-4v5h-q8j3-g849.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5fr6-q8mw-fx75/GHSA-5fr6-q8mw-fx75.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5r56-v3jw-7756/GHSA-5r56-v3jw-7756.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6688-xwmm-27mr/GHSA-6688-xwmm-27mr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6q4v-6637-v9c9/GHSA-6q4v-6637-v9c9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6vqp-97x2-9w68/GHSA-6vqp-97x2-9w68.json create mode 100644 advisories/unreviewed/2025/05/GHSA-72gp-564x-qvpp/GHSA-72gp-564x-qvpp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-84m5-5vgj-8qr2/GHSA-84m5-5vgj-8qr2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8758-9gxm-jcpf/GHSA-8758-9gxm-jcpf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8j9x-j56g-p6pf/GHSA-8j9x-j56g-p6pf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8qpj-mfhj-m8h3/GHSA-8qpj-mfhj-m8h3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8qqq-69r5-mv6r/GHSA-8qqq-69r5-mv6r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json create mode 100644 advisories/unreviewed/2025/05/GHSA-97ff-chjc-r365/GHSA-97ff-chjc-r365.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c56p-5rjc-7858/GHSA-c56p-5rjc-7858.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c68v-cf88-8w65/GHSA-c68v-cf88-8w65.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cjqg-w438-4fr8/GHSA-cjqg-w438-4fr8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f3f4-3g45-5gh4/GHSA-f3f4-3g45-5gh4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g2w4-f56h-2wj6/GHSA-g2w4-f56h-2wj6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gjrf-jj6g-9jfj/GHSA-gjrf-jj6g-9jfj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-grvj-cc9v-jh9r/GHSA-grvj-cc9v-jh9r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hr5v-cxwr-h392/GHSA-hr5v-cxwr-h392.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j33m-6826-95m2/GHSA-j33m-6826-95m2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j6c5-42fq-c3hr/GHSA-j6c5-42fq-c3hr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jg34-99pf-2cmp/GHSA-jg34-99pf-2cmp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jm7c-x6r9-pc54/GHSA-jm7c-x6r9-pc54.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m4g3-g4fm-5v88/GHSA-m4g3-g4fm-5v88.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mwpv-wfv8-f2x8/GHSA-mwpv-wfv8-f2x8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qpv3-3px8-gmhc/GHSA-qpv3-3px8-gmhc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r9w7-5f7h-f659/GHSA-r9w7-5f7h-f659.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rh9j-3chv-xw4h/GHSA-rh9j-3chv-xw4h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w584-3vj6-7f7f/GHSA-w584-3vj6-7f7f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w6xc-89xr-622v/GHSA-w6xc-89xr-622v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w9c2-jr2q-g6xq/GHSA-w9c2-jr2q-g6xq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-whmx-vmqq-mjpv/GHSA-whmx-vmqq-mjpv.json create mode 100644 advisories/unreviewed/2025/05/GHSA-whrv-65gc-prq2/GHSA-whrv-65gc-prq2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-whxr-3p84-rf3c/GHSA-whxr-3p84-rf3c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x8j6-f4cg-fvh2/GHSA-x8j6-f4cg-fvh2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xfj9-6phw-wqfj/GHSA-xfj9-6phw-wqfj.json diff --git a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json index d0ca0d7c737..5716e697099 100644 --- a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json +++ b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9589-mpwg-8xq6", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-07T09:31:17Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32913" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4609" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4624" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32913" diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json index 69a378c70c3..ef1a550a0f0 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json +++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-qjpg-x8wq", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-07T09:31:17Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32906" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4609" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4624" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32906" diff --git a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json index 6ded7552cb9..f97a3ca205a 100644 --- a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json +++ b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp4x-j6ch-w8q5", - "modified": "2025-05-06T21:30:47Z", + "modified": "2025-05-07T09:31:17Z", "published": "2025-04-15T18:31:45Z", "aliases": [ "CVE-2025-32911" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4609" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4624" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32911" diff --git a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json index 1b92764e42f..ad535c3d350 100644 --- a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json +++ b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr7v-prvv-52v8", - "modified": "2025-05-06T21:30:48Z", + "modified": "2025-05-07T09:31:17Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46421" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4609" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4624" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46421" diff --git a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json index d490cc436ed..59bcb51fb42 100644 --- a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json +++ b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv37-78jj-hvqv", - "modified": "2025-05-06T21:30:48Z", + "modified": "2025-05-07T09:31:17Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46420" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4568" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4609" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4624" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46420" diff --git a/advisories/unreviewed/2025/05/GHSA-26p9-7f96-xrcg/GHSA-26p9-7f96-xrcg.json b/advisories/unreviewed/2025/05/GHSA-26p9-7f96-xrcg/GHSA-26p9-7f96-xrcg.json new file mode 100644 index 00000000000..d26e24ce753 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-26p9-7f96-xrcg/GHSA-26p9-7f96-xrcg.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26p9-7f96-xrcg", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20977" + ], + "details": "Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20977" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2mqx-xpw9-6crj/GHSA-2mqx-xpw9-6crj.json b/advisories/unreviewed/2025/05/GHSA-2mqx-xpw9-6crj/GHSA-2mqx-xpw9-6crj.json new file mode 100644 index 00000000000..e9a9b33d569 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2mqx-xpw9-6crj/GHSA-2mqx-xpw9-6crj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mqx-xpw9-6crj", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-39361" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39361" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-7-1017-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2p7w-jv73-hf6h/GHSA-2p7w-jv73-hf6h.json b/advisories/unreviewed/2025/05/GHSA-2p7w-jv73-hf6h/GHSA-2p7w-jv73-hf6h.json new file mode 100644 index 00000000000..9c0b514e1c0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2p7w-jv73-hf6h/GHSA-2p7w-jv73-hf6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p7w-jv73-hf6h", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32402" + ], + "details": "An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32402" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32402" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3827-2vw5-3pm3/GHSA-3827-2vw5-3pm3.json b/advisories/unreviewed/2025/05/GHSA-3827-2vw5-3pm3/GHSA-3827-2vw5-3pm3.json new file mode 100644 index 00000000000..6822b8a6094 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3827-2vw5-3pm3/GHSA-3827-2vw5-3pm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3827-2vw5-3pm3", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32404" + ], + "details": "An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32404" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32404" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json b/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json new file mode 100644 index 00000000000..42965cacfeb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3jxj-2fmg-wg9x/GHSA-3jxj-2fmg-wg9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jxj-2fmg-wg9x", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32401" + ], + "details": "An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32401" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32401" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json b/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json new file mode 100644 index 00000000000..a9982077d7a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4f32-q83j-5vfj/GHSA-4f32-q83j-5vfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f32-q83j-5vfj", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32399" + ], + "details": "An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32399" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32399" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-606" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v5h-q8j3-g849/GHSA-4v5h-q8j3-g849.json b/advisories/unreviewed/2025/05/GHSA-4v5h-q8j3-g849/GHSA-4v5h-q8j3-g849.json new file mode 100644 index 00000000000..6033ac4c792 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4v5h-q8j3-g849/GHSA-4v5h-q8j3-g849.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v5h-q8j3-g849", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20973" + ], + "details": "Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20973" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fr6-q8mw-fx75/GHSA-5fr6-q8mw-fx75.json b/advisories/unreviewed/2025/05/GHSA-5fr6-q8mw-fx75/GHSA-5fr6-q8mw-fx75.json new file mode 100644 index 00000000000..f154980017d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fr6-q8mw-fx75/GHSA-5fr6-q8mw-fx75.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fr6-q8mw-fx75", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20958" + ], + "details": "Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20958" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5r56-v3jw-7756/GHSA-5r56-v3jw-7756.json b/advisories/unreviewed/2025/05/GHSA-5r56-v3jw-7756/GHSA-5r56-v3jw-7756.json new file mode 100644 index 00000000000..fdf1b04e632 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5r56-v3jw-7756/GHSA-5r56-v3jw-7756.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r56-v3jw-7756", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20979" + ], + "details": "Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20979" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6688-xwmm-27mr/GHSA-6688-xwmm-27mr.json b/advisories/unreviewed/2025/05/GHSA-6688-xwmm-27mr/GHSA-6688-xwmm-27mr.json new file mode 100644 index 00000000000..220e30842a4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6688-xwmm-27mr/GHSA-6688-xwmm-27mr.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6688-xwmm-27mr", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20953" + ], + "details": "Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20953" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6q4v-6637-v9c9/GHSA-6q4v-6637-v9c9.json b/advisories/unreviewed/2025/05/GHSA-6q4v-6637-v9c9/GHSA-6q4v-6637-v9c9.json new file mode 100644 index 00000000000..308b0557c52 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6q4v-6637-v9c9/GHSA-6q4v-6637-v9c9.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q4v-6637-v9c9", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20961" + ], + "details": "Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20961" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6vqp-97x2-9w68/GHSA-6vqp-97x2-9w68.json b/advisories/unreviewed/2025/05/GHSA-6vqp-97x2-9w68/GHSA-6vqp-97x2-9w68.json new file mode 100644 index 00000000000..480bb5fbebc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6vqp-97x2-9w68/GHSA-6vqp-97x2-9w68.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vqp-97x2-9w68", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20974" + ], + "details": "Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20974" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-72gp-564x-qvpp/GHSA-72gp-564x-qvpp.json b/advisories/unreviewed/2025/05/GHSA-72gp-564x-qvpp/GHSA-72gp-564x-qvpp.json new file mode 100644 index 00000000000..c2c7172d579 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-72gp-564x-qvpp/GHSA-72gp-564x-qvpp.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72gp-564x-qvpp", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20956" + ], + "details": "Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20956" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-84m5-5vgj-8qr2/GHSA-84m5-5vgj-8qr2.json b/advisories/unreviewed/2025/05/GHSA-84m5-5vgj-8qr2/GHSA-84m5-5vgj-8qr2.json new file mode 100644 index 00000000000..5a316849712 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-84m5-5vgj-8qr2/GHSA-84m5-5vgj-8qr2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84m5-5vgj-8qr2", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20960" + ], + "details": "Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20960" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8758-9gxm-jcpf/GHSA-8758-9gxm-jcpf.json b/advisories/unreviewed/2025/05/GHSA-8758-9gxm-jcpf/GHSA-8758-9gxm-jcpf.json new file mode 100644 index 00000000000..951c48c37db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8758-9gxm-jcpf/GHSA-8758-9gxm-jcpf.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8758-9gxm-jcpf", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20957" + ], + "details": "Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20957" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8j9x-j56g-p6pf/GHSA-8j9x-j56g-p6pf.json b/advisories/unreviewed/2025/05/GHSA-8j9x-j56g-p6pf/GHSA-8j9x-j56g-p6pf.json new file mode 100644 index 00000000000..41fcc6677f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8j9x-j56g-p6pf/GHSA-8j9x-j56g-p6pf.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j9x-j56g-p6pf", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20976" + ], + "details": "Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20976" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8qpj-mfhj-m8h3/GHSA-8qpj-mfhj-m8h3.json b/advisories/unreviewed/2025/05/GHSA-8qpj-mfhj-m8h3/GHSA-8qpj-mfhj-m8h3.json new file mode 100644 index 00000000000..41840fffc3e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8qpj-mfhj-m8h3/GHSA-8qpj-mfhj-m8h3.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qpj-mfhj-m8h3", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20959" + ], + "details": "Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20959" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8qqq-69r5-mv6r/GHSA-8qqq-69r5-mv6r.json b/advisories/unreviewed/2025/05/GHSA-8qqq-69r5-mv6r/GHSA-8qqq-69r5-mv6r.json new file mode 100644 index 00000000000..4370664ffc2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8qqq-69r5-mv6r/GHSA-8qqq-69r5-mv6r.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qqq-69r5-mv6r", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20975" + ], + "details": "Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20975" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json b/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json new file mode 100644 index 00000000000..e1901af523f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rvc-mwwg-mp37/GHSA-8rvc-mwwg-mp37.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rvc-mwwg-mp37", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20937" + ], + "details": "Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20937" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-97ff-chjc-r365/GHSA-97ff-chjc-r365.json b/advisories/unreviewed/2025/05/GHSA-97ff-chjc-r365/GHSA-97ff-chjc-r365.json new file mode 100644 index 00000000000..05d1cc51a6c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-97ff-chjc-r365/GHSA-97ff-chjc-r365.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97ff-chjc-r365", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20978" + ], + "details": "Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20978" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json b/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json new file mode 100644 index 00000000000..e1d8ef80521 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9q6r-mr8j-x88j/GHSA-9q6r-mr8j-x88j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6r-mr8j-x88j", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32396" + ], + "details": "An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32396" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c56p-5rjc-7858/GHSA-c56p-5rjc-7858.json b/advisories/unreviewed/2025/05/GHSA-c56p-5rjc-7858/GHSA-c56p-5rjc-7858.json new file mode 100644 index 00000000000..ce93e39d310 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c56p-5rjc-7858/GHSA-c56p-5rjc-7858.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c56p-5rjc-7858", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20972" + ], + "details": "Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20972" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c68v-cf88-8w65/GHSA-c68v-cf88-8w65.json b/advisories/unreviewed/2025/05/GHSA-c68v-cf88-8w65/GHSA-c68v-cf88-8w65.json new file mode 100644 index 00000000000..db82e8e89f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c68v-cf88-8w65/GHSA-c68v-cf88-8w65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c68v-cf88-8w65", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-1399" + ], + "details": "Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1399" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1399" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cjqg-w438-4fr8/GHSA-cjqg-w438-4fr8.json b/advisories/unreviewed/2025/05/GHSA-cjqg-w438-4fr8/GHSA-cjqg-w438-4fr8.json new file mode 100644 index 00000000000..bfb390a62c7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cjqg-w438-4fr8/GHSA-cjqg-w438-4fr8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjqg-w438-4fr8", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20965" + ], + "details": "Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20965" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json b/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json new file mode 100644 index 00000000000..da64e6bb40e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crjp-8g5r-p85r/GHSA-crjp-8g5r-p85r.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crjp-8g5r-p85r", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20964" + ], + "details": "Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20964" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f3f4-3g45-5gh4/GHSA-f3f4-3g45-5gh4.json b/advisories/unreviewed/2025/05/GHSA-f3f4-3g45-5gh4/GHSA-f3f4-3g45-5gh4.json new file mode 100644 index 00000000000..c6a34b3bfd9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3f4-3g45-5gh4/GHSA-f3f4-3g45-5gh4.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3f4-3g45-5gh4", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20966" + ], + "details": "Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20966" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2w4-f56h-2wj6/GHSA-g2w4-f56h-2wj6.json b/advisories/unreviewed/2025/05/GHSA-g2w4-f56h-2wj6/GHSA-g2w4-f56h-2wj6.json new file mode 100644 index 00000000000..4fabe67ee12 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g2w4-f56h-2wj6/GHSA-g2w4-f56h-2wj6.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2w4-f56h-2wj6", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20969" + ], + "details": "Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20969" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gjrf-jj6g-9jfj/GHSA-gjrf-jj6g-9jfj.json b/advisories/unreviewed/2025/05/GHSA-gjrf-jj6g-9jfj/GHSA-gjrf-jj6g-9jfj.json new file mode 100644 index 00000000000..3f702db840b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gjrf-jj6g-9jfj/GHSA-gjrf-jj6g-9jfj.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjrf-jj6g-9jfj", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20980" + ], + "details": "Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20980" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-grvj-cc9v-jh9r/GHSA-grvj-cc9v-jh9r.json b/advisories/unreviewed/2025/05/GHSA-grvj-cc9v-jh9r/GHSA-grvj-cc9v-jh9r.json new file mode 100644 index 00000000000..9f1d6a300c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-grvj-cc9v-jh9r/GHSA-grvj-cc9v-jh9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grvj-cc9v-jh9r", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-1400" + ], + "details": "Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1400" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hr5v-cxwr-h392/GHSA-hr5v-cxwr-h392.json b/advisories/unreviewed/2025/05/GHSA-hr5v-cxwr-h392/GHSA-hr5v-cxwr-h392.json new file mode 100644 index 00000000000..a1e43184f17 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hr5v-cxwr-h392/GHSA-hr5v-cxwr-h392.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr5v-cxwr-h392", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32398" + ], + "details": "A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32398" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32398" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j33m-6826-95m2/GHSA-j33m-6826-95m2.json b/advisories/unreviewed/2025/05/GHSA-j33m-6826-95m2/GHSA-j33m-6826-95m2.json new file mode 100644 index 00000000000..15957339803 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j33m-6826-95m2/GHSA-j33m-6826-95m2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j33m-6826-95m2", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20967" + ], + "details": "Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20967" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j6c5-42fq-c3hr/GHSA-j6c5-42fq-c3hr.json b/advisories/unreviewed/2025/05/GHSA-j6c5-42fq-c3hr/GHSA-j6c5-42fq-c3hr.json new file mode 100644 index 00000000000..bb5a1f6e172 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j6c5-42fq-c3hr/GHSA-j6c5-42fq-c3hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6c5-42fq-c3hr", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-0668" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0668" + }, + { + "type": "WEB", + "url": "https://www.compass-security.com/fileadmin/Research/Advisories/2025_03_CSNC-2025-004_BOINC_multiple_SQLi.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jg34-99pf-2cmp/GHSA-jg34-99pf-2cmp.json b/advisories/unreviewed/2025/05/GHSA-jg34-99pf-2cmp/GHSA-jg34-99pf-2cmp.json new file mode 100644 index 00000000000..13f98d06972 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jg34-99pf-2cmp/GHSA-jg34-99pf-2cmp.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg34-99pf-2cmp", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20970" + ], + "details": "Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20970" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jm7c-x6r9-pc54/GHSA-jm7c-x6r9-pc54.json b/advisories/unreviewed/2025/05/GHSA-jm7c-x6r9-pc54/GHSA-jm7c-x6r9-pc54.json new file mode 100644 index 00000000000..62983f728f8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jm7c-x6r9-pc54/GHSA-jm7c-x6r9-pc54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm7c-x6r9-pc54", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-0666" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0666" + }, + { + "type": "WEB", + "url": "https://www.compass-security.com/fileadmin/Research/Advisories/2025_01_CSNC-2025-002_BOINC_multiple_XSS.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m4g3-g4fm-5v88/GHSA-m4g3-g4fm-5v88.json b/advisories/unreviewed/2025/05/GHSA-m4g3-g4fm-5v88/GHSA-m4g3-g4fm-5v88.json new file mode 100644 index 00000000000..fd0a763c635 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m4g3-g4fm-5v88/GHSA-m4g3-g4fm-5v88.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4g3-g4fm-5v88", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20971" + ], + "details": "Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20971" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json b/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json index 5aa7da02e29..229e5453ce8 100644 --- a/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json +++ b/advisories/unreviewed/2025/05/GHSA-mccx-692g-vmcf/GHSA-mccx-692g-vmcf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-89" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-mwpv-wfv8-f2x8/GHSA-mwpv-wfv8-f2x8.json b/advisories/unreviewed/2025/05/GHSA-mwpv-wfv8-f2x8/GHSA-mwpv-wfv8-f2x8.json new file mode 100644 index 00000000000..28006609062 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mwpv-wfv8-f2x8/GHSA-mwpv-wfv8-f2x8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwpv-wfv8-f2x8", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20955" + ], + "details": "Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20955" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpv3-3px8-gmhc/GHSA-qpv3-3px8-gmhc.json b/advisories/unreviewed/2025/05/GHSA-qpv3-3px8-gmhc/GHSA-qpv3-3px8-gmhc.json new file mode 100644 index 00000000000..33c25446891 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qpv3-3px8-gmhc/GHSA-qpv3-3px8-gmhc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpv3-3px8-gmhc", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2024-12120" + ], + "details": "The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12120" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3236381/royal-elementor-addons/tags/1.7.1008/modules/countdown/widgets/wpr-countdown.php?old=3220755&old_path=royal-elementor-addons%2Ftags%2F1.7.1007%2Fmodules%2Fcountdown%2Fwidgets%2Fwpr-countdown.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3285549/royal-elementor-addons/tags/1.7.1018/assets/js/frontend.js?old=3277554&old_path=royal-elementor-addons%2Ftags%2F1.7.1017%2Fassets%2Fjs%2Ffrontend.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ee7b4d8-c397-41f6-981f-9a010e4ab2f1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json b/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json new file mode 100644 index 00000000000..393fda16c07 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qx88-qw7m-mgq7/GHSA-qx88-qw7m-mgq7.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx88-qw7m-mgq7", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20963" + ], + "details": "Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20963" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9w7-5f7h-f659/GHSA-r9w7-5f7h-f659.json b/advisories/unreviewed/2025/05/GHSA-r9w7-5f7h-f659/GHSA-r9w7-5f7h-f659.json new file mode 100644 index 00000000000..5e408cdc24f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9w7-5f7h-f659/GHSA-r9w7-5f7h-f659.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9w7-5f7h-f659", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-0667" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0667" + }, + { + "type": "WEB", + "url": "https://www.compass-security.com/fileadmin/Research/Advisories/2025_02_CSNC-2025-003_BOINC_stored_XSS.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rh9j-3chv-xw4h/GHSA-rh9j-3chv-xw4h.json b/advisories/unreviewed/2025/05/GHSA-rh9j-3chv-xw4h/GHSA-rh9j-3chv-xw4h.json new file mode 100644 index 00000000000..84b9d19c413 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rh9j-3chv-xw4h/GHSA-rh9j-3chv-xw4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh9j-3chv-xw4h", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-0669" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0669" + }, + { + "type": "WEB", + "url": "https://www.compass-security.com/fileadmin/Research/Advisories/2025_04_CSNC-2025-005_BOINC_CSRF.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json b/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json new file mode 100644 index 00000000000..762fa739401 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v6w6-862c-c8mm/GHSA-v6w6-862c-c8mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6w6-862c-c8mm", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32397" + ], + "details": "An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32397" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json b/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json new file mode 100644 index 00000000000..399ba0f81ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vp6c-cpgr-622f/GHSA-vp6c-cpgr-622f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp6c-cpgr-622f", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32400" + ], + "details": "An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32400" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w584-3vj6-7f7f/GHSA-w584-3vj6-7f7f.json b/advisories/unreviewed/2025/05/GHSA-w584-3vj6-7f7f/GHSA-w584-3vj6-7f7f.json new file mode 100644 index 00000000000..1f0325ed719 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w584-3vj6-7f7f/GHSA-w584-3vj6-7f7f.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w584-3vj6-7f7f", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-20968" + ], + "details": "Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20968" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w6xc-89xr-622v/GHSA-w6xc-89xr-622v.json b/advisories/unreviewed/2025/05/GHSA-w6xc-89xr-622v/GHSA-w6xc-89xr-622v.json new file mode 100644 index 00000000000..4c6653cbc43 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w6xc-89xr-622v/GHSA-w6xc-89xr-622v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xc-89xr-622v", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-32405" + ], + "details": "An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32405" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w9c2-jr2q-g6xq/GHSA-w9c2-jr2q-g6xq.json b/advisories/unreviewed/2025/05/GHSA-w9c2-jr2q-g6xq/GHSA-w9c2-jr2q-g6xq.json new file mode 100644 index 00000000000..f603e14d3b8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w9c2-jr2q-g6xq/GHSA-w9c2-jr2q-g6xq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9c2-jr2q-g6xq", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-4171" + ], + "details": "The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wfp' shortcode in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4171" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3287192%40where-did-they-go-from-here&new=3287192%40where-did-they-go-from-here&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2b27a7b1-6fee-433f-8102-4a3745a8dfed?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whmx-vmqq-mjpv/GHSA-whmx-vmqq-mjpv.json b/advisories/unreviewed/2025/05/GHSA-whmx-vmqq-mjpv/GHSA-whmx-vmqq-mjpv.json new file mode 100644 index 00000000000..67ce22e8553 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whmx-vmqq-mjpv/GHSA-whmx-vmqq-mjpv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whmx-vmqq-mjpv", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20949" + ], + "details": "Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20949" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whrv-65gc-prq2/GHSA-whrv-65gc-prq2.json b/advisories/unreviewed/2025/05/GHSA-whrv-65gc-prq2/GHSA-whrv-65gc-prq2.json new file mode 100644 index 00000000000..75089eb3c99 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whrv-65gc-prq2/GHSA-whrv-65gc-prq2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whrv-65gc-prq2", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20962" + ], + "details": "Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20962" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whxr-3p84-rf3c/GHSA-whxr-3p84-rf3c.json b/advisories/unreviewed/2025/05/GHSA-whxr-3p84-rf3c/GHSA-whxr-3p84-rf3c.json new file mode 100644 index 00000000000..549f363ccef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whxr-3p84-rf3c/GHSA-whxr-3p84-rf3c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whxr-3p84-rf3c", + "modified": "2025-05-07T09:31:19Z", + "published": "2025-05-07T09:31:19Z", + "aliases": [ + "CVE-2025-27533" + ], + "details": "Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.\n\nDuring unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections.\nThis issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.\n\nUsers are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.\n\nExisting users may implement mutual TLS to mitigate the risk on affected brokers.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:M/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27533" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8hcm25vf7mchg4zbbhnlx2lc5bs705hg" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/06/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x8j6-f4cg-fvh2/GHSA-x8j6-f4cg-fvh2.json b/advisories/unreviewed/2025/05/GHSA-x8j6-f4cg-fvh2/GHSA-x8j6-f4cg-fvh2.json new file mode 100644 index 00000000000..6e4cfb2470f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x8j6-f4cg-fvh2/GHSA-x8j6-f4cg-fvh2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8j6-f4cg-fvh2", + "modified": "2025-05-07T09:31:18Z", + "published": "2025-05-07T09:31:18Z", + "aliases": [ + "CVE-2025-20954" + ], + "details": "Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20954" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xfj9-6phw-wqfj/GHSA-xfj9-6phw-wqfj.json b/advisories/unreviewed/2025/05/GHSA-xfj9-6phw-wqfj/GHSA-xfj9-6phw-wqfj.json new file mode 100644 index 00000000000..3a6220cc24f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xfj9-6phw-wqfj/GHSA-xfj9-6phw-wqfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfj9-6phw-wqfj", + "modified": "2025-05-07T09:31:17Z", + "published": "2025-05-07T09:31:17Z", + "aliases": [ + "CVE-2025-32403" + ], + "details": "An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32403" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-07T07:15:51Z" + } +} \ No newline at end of file