From b3ffac1d6e62439076b11a327c32a5e13825791f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Feb 2025 21:33:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-48cj-44rg-fxc7.json | 6 +++- .../GHSA-9xmf-4p3w-hc8w.json | 2 +- .../GHSA-m8h2-2q9c-f24g.json | 2 +- .../GHSA-qvx7-wjgx-j93g.json | 4 ++- .../GHSA-94c6-6qpc-j73m.json | 2 +- .../GHSA-vhvr-7ww4-7fgj.json | 15 +++++--- .../GHSA-8xj7-c2mm-v3r5.json | 6 +++- .../GHSA-535j-2gj4-m7x7.json | 3 +- .../GHSA-2377-g2h8-5f9c.json | 3 +- .../GHSA-34gm-qfww-6gwm.json | 1 + .../GHSA-8r2x-fcq9-f9rj.json | 3 +- .../GHSA-vc27-49rw-f322.json | 3 +- .../GHSA-vrgx-86cv-946f.json | 3 +- .../GHSA-wjv3-548m-qhxx.json | 3 +- .../GHSA-264g-h4m4-r2w6.json | 6 +++- .../GHSA-2hv6-9hx6-7j2g.json | 36 +++++++++++++++++++ .../GHSA-2pq9-46mh-w84j.json | 5 +-- .../GHSA-2w4f-h4cf-767r.json | 36 +++++++++++++++++++ .../GHSA-33xp-654m-3j2x.json | 36 +++++++++++++++++++ .../GHSA-3w3w-mjc4-w534.json | 2 +- .../GHSA-4776-6pq8-cq78.json | 36 +++++++++++++++++++ .../GHSA-4grm-xc99-7x47.json | 36 +++++++++++++++++++ .../GHSA-4jjw-p5j8-wcgh.json | 3 +- .../GHSA-52g7-964p-h422.json | 3 +- .../GHSA-6753-7pjg-96pv.json | 36 +++++++++++++++++++ .../GHSA-6ghc-h6hx-hq7x.json | 6 +++- .../GHSA-749j-r6jc-ghfj.json | 15 +++++--- .../GHSA-7wjm-v526-8p9w.json | 34 ++++++++++++++++++ .../GHSA-84p2-qp33-qgfg.json | 2 +- .../GHSA-8528-jjpw-q9wx.json | 3 +- .../GHSA-8wc2-54gh-pq44.json | 36 +++++++++++++++++++ .../GHSA-9733-vpvw-5rpc.json | 15 +++++--- .../GHSA-c499-vvj4-hwww.json | 36 +++++++++++++++++++ .../GHSA-c8j4-9hch-jp6v.json | 3 +- .../GHSA-cq9g-38fc-j53v.json | 2 +- .../GHSA-fvhg-h82j-jfjq.json | 36 +++++++++++++++++++ .../GHSA-fvx6-jx94-49qx.json | 11 ++++-- .../GHSA-gw2v-7p5h-4fwr.json | 6 +++- .../GHSA-hjmv-v6c5-x23j.json | 15 +++++--- .../GHSA-hp33-4xv5-445m.json | 36 +++++++++++++++++++ .../GHSA-j4gm-mr6g-474q.json | 3 +- .../GHSA-jv6c-2mw3-h322.json | 36 +++++++++++++++++++ .../GHSA-m95x-5www-9p45.json | 36 +++++++++++++++++++ .../GHSA-p2h9-63jc-gj67.json | 6 +++- .../GHSA-ppxx-pr9w-7ww8.json | 36 +++++++++++++++++++ .../GHSA-pvq4-rqfr-rc8r.json | 36 +++++++++++++++++++ .../GHSA-pvxx-h279-jv5h.json | 36 +++++++++++++++++++ .../GHSA-q7mr-3qgg-qjxx.json | 36 +++++++++++++++++++ .../GHSA-qfxj-99gm-r9jr.json | 15 +++++--- .../GHSA-qr8x-m34w-97pj.json | 2 +- .../GHSA-rg35-696m-j8xx.json | 15 +++++--- .../GHSA-vqx6-86fx-35gx.json | 15 +++++--- .../GHSA-w3pv-gx2c-27p2.json | 36 +++++++++++++++++++ .../GHSA-w56m-wcpr-36rf.json | 2 +- .../GHSA-wg6m-8vxm-79gv.json | 36 +++++++++++++++++++ .../GHSA-x3g3-3qwm-w95x.json | 36 +++++++++++++++++++ .../GHSA-xjc3-vjh6-m283.json | 36 +++++++++++++++++++ .../GHSA-xvm3-w96c-9whc.json | 15 +++++--- 58 files changed, 917 insertions(+), 63 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-2hv6-9hx6-7j2g/GHSA-2hv6-9hx6-7j2g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2w4f-h4cf-767r/GHSA-2w4f-h4cf-767r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-33xp-654m-3j2x/GHSA-33xp-654m-3j2x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4776-6pq8-cq78/GHSA-4776-6pq8-cq78.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4grm-xc99-7x47/GHSA-4grm-xc99-7x47.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6753-7pjg-96pv/GHSA-6753-7pjg-96pv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7wjm-v526-8p9w/GHSA-7wjm-v526-8p9w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8wc2-54gh-pq44/GHSA-8wc2-54gh-pq44.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c499-vvj4-hwww/GHSA-c499-vvj4-hwww.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fvhg-h82j-jfjq/GHSA-fvhg-h82j-jfjq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hp33-4xv5-445m/GHSA-hp33-4xv5-445m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jv6c-2mw3-h322/GHSA-jv6c-2mw3-h322.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m95x-5www-9p45/GHSA-m95x-5www-9p45.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ppxx-pr9w-7ww8/GHSA-ppxx-pr9w-7ww8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pvq4-rqfr-rc8r/GHSA-pvq4-rqfr-rc8r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pvxx-h279-jv5h/GHSA-pvxx-h279-jv5h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q7mr-3qgg-qjxx/GHSA-q7mr-3qgg-qjxx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w3pv-gx2c-27p2/GHSA-w3pv-gx2c-27p2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wg6m-8vxm-79gv/GHSA-wg6m-8vxm-79gv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x3g3-3qwm-w95x/GHSA-x3g3-3qwm-w95x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json diff --git a/advisories/unreviewed/2023/03/GHSA-48cj-44rg-fxc7/GHSA-48cj-44rg-fxc7.json b/advisories/unreviewed/2023/03/GHSA-48cj-44rg-fxc7/GHSA-48cj-44rg-fxc7.json index 9737c08b13f..4181f0e1032 100644 --- a/advisories/unreviewed/2023/03/GHSA-48cj-44rg-fxc7/GHSA-48cj-44rg-fxc7.json +++ b/advisories/unreviewed/2023/03/GHSA-48cj-44rg-fxc7/GHSA-48cj-44rg-fxc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48cj-44rg-fxc7", - "modified": "2023-04-03T18:32:06Z", + "modified": "2025-02-25T21:31:20Z", "published": "2023-03-23T21:30:19Z", "aliases": [ "CVE-2023-1513" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/kvm/20230214103304.3689213-1-gregkh%40linuxfoundation.org" + }, { "type": "WEB", "url": "https://lore.kernel.org/kvm/20230214103304.3689213-1-gregkh@linuxfoundation.org" diff --git a/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json b/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json index d1df4d72c9c..116e1e6d224 100644 --- a/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json +++ b/advisories/unreviewed/2023/03/GHSA-9xmf-4p3w-hc8w/GHSA-9xmf-4p3w-hc8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xmf-4p3w-hc8w", - "modified": "2023-03-28T21:30:17Z", + "modified": "2025-02-25T21:31:22Z", "published": "2023-03-23T21:30:17Z", "aliases": [ "CVE-2023-28611" diff --git a/advisories/unreviewed/2023/03/GHSA-m8h2-2q9c-f24g/GHSA-m8h2-2q9c-f24g.json b/advisories/unreviewed/2023/03/GHSA-m8h2-2q9c-f24g/GHSA-m8h2-2q9c-f24g.json index 77daf754e53..a9f1447f104 100644 --- a/advisories/unreviewed/2023/03/GHSA-m8h2-2q9c-f24g/GHSA-m8h2-2q9c-f24g.json +++ b/advisories/unreviewed/2023/03/GHSA-m8h2-2q9c-f24g/GHSA-m8h2-2q9c-f24g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8h2-2q9c-f24g", - "modified": "2023-03-28T18:30:30Z", + "modified": "2025-02-25T21:31:16Z", "published": "2023-03-21T18:30:20Z", "aliases": [ "CVE-2023-1304" diff --git a/advisories/unreviewed/2023/03/GHSA-qvx7-wjgx-j93g/GHSA-qvx7-wjgx-j93g.json b/advisories/unreviewed/2023/03/GHSA-qvx7-wjgx-j93g/GHSA-qvx7-wjgx-j93g.json index 76e6f8988c0..47aa056beda 100644 --- a/advisories/unreviewed/2023/03/GHSA-qvx7-wjgx-j93g/GHSA-qvx7-wjgx-j93g.json +++ b/advisories/unreviewed/2023/03/GHSA-qvx7-wjgx-j93g/GHSA-qvx7-wjgx-j93g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json b/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json index 68abb8f5635..17df851d276 100644 --- a/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json +++ b/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94c6-6qpc-j73m", - "modified": "2024-04-04T05:34:55Z", + "modified": "2025-02-25T21:31:16Z", "published": "2023-07-06T19:24:12Z", "aliases": [ "CVE-2023-28663" diff --git a/advisories/unreviewed/2024/03/GHSA-vhvr-7ww4-7fgj/GHSA-vhvr-7ww4-7fgj.json b/advisories/unreviewed/2024/03/GHSA-vhvr-7ww4-7fgj/GHSA-vhvr-7ww4-7fgj.json index 482da54fa75..1916dc2ece5 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhvr-7ww4-7fgj/GHSA-vhvr-7ww4-7fgj.json +++ b/advisories/unreviewed/2024/03/GHSA-vhvr-7ww4-7fgj/GHSA-vhvr-7ww4-7fgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhvr-7ww4-7fgj", - "modified": "2024-03-13T15:31:05Z", + "modified": "2025-02-25T21:31:24Z", "published": "2024-03-13T15:31:05Z", "aliases": [ "CVE-2023-52608" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Check mailbox/SMT channel for consistency\n\nOn reception of a completion interrupt the shared memory area is accessed\nto retrieve the message header at first and then, if the message sequence\nnumber identifies a transaction which is still pending, the related\npayload is fetched too.\n\nWhen an SCMI command times out the channel ownership remains with the\nplatform until eventually a late reply is received and, as a consequence,\nany further transmission attempt remains pending, waiting for the channel\nto be relinquished by the platform.\n\nOnce that late reply is received the channel ownership is given back\nto the agent and any pending request is then allowed to proceed and\noverwrite the SMT area of the just delivered late reply; then the wait\nfor the reply to the new request starts.\n\nIt has been observed that the spurious IRQ related to the late reply can\nbe wrongly associated with the freshly enqueued request: when that happens\nthe SCMI stack in-flight lookup procedure is fooled by the fact that the\nmessage header now present in the SMT area is related to the new pending\ntransaction, even though the real reply has still to arrive.\n\nThis race-condition on the A2P channel can be detected by looking at the\nchannel status bits: a genuine reply from the platform will have set the\nchannel free bit before triggering the completion IRQ.\n\nAdd a consistency check to validate such condition in the A2P ISR.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T14:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8xj7-c2mm-v3r5/GHSA-8xj7-c2mm-v3r5.json b/advisories/unreviewed/2024/10/GHSA-8xj7-c2mm-v3r5/GHSA-8xj7-c2mm-v3r5.json index 4d7560f10d6..899e3174d9c 100644 --- a/advisories/unreviewed/2024/10/GHSA-8xj7-c2mm-v3r5/GHSA-8xj7-c2mm-v3r5.json +++ b/advisories/unreviewed/2024/10/GHSA-8xj7-c2mm-v3r5/GHSA-8xj7-c2mm-v3r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xj7-c2mm-v3r5", - "modified": "2024-10-08T18:33:17Z", + "modified": "2025-02-25T21:31:27Z", "published": "2024-10-08T18:33:17Z", "aliases": [ "CVE-2024-43583" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43583" }, + { + "type": "WEB", + "url": "https://github.com/Kvngtheta/CVE-2024-43583-PoC/blob/main/poc-43583.py" + }, { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43583" diff --git a/advisories/unreviewed/2024/12/GHSA-535j-2gj4-m7x7/GHSA-535j-2gj4-m7x7.json b/advisories/unreviewed/2024/12/GHSA-535j-2gj4-m7x7/GHSA-535j-2gj4-m7x7.json index 46f9c1d6f01..348131d880e 100644 --- a/advisories/unreviewed/2024/12/GHSA-535j-2gj4-m7x7/GHSA-535j-2gj4-m7x7.json +++ b/advisories/unreviewed/2024/12/GHSA-535j-2gj4-m7x7/GHSA-535j-2gj4-m7x7.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-2377-g2h8-5f9c/GHSA-2377-g2h8-5f9c.json b/advisories/unreviewed/2025/01/GHSA-2377-g2h8-5f9c/GHSA-2377-g2h8-5f9c.json index 3fe03562262..08d808938ce 100644 --- a/advisories/unreviewed/2025/01/GHSA-2377-g2h8-5f9c/GHSA-2377-g2h8-5f9c.json +++ b/advisories/unreviewed/2025/01/GHSA-2377-g2h8-5f9c/GHSA-2377-g2h8-5f9c.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-34gm-qfww-6gwm/GHSA-34gm-qfww-6gwm.json b/advisories/unreviewed/2025/01/GHSA-34gm-qfww-6gwm/GHSA-34gm-qfww-6gwm.json index e854b0fcf2f..1b04a885e0d 100644 --- a/advisories/unreviewed/2025/01/GHSA-34gm-qfww-6gwm/GHSA-34gm-qfww-6gwm.json +++ b/advisories/unreviewed/2025/01/GHSA-34gm-qfww-6gwm/GHSA-34gm-qfww-6gwm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-8r2x-fcq9-f9rj/GHSA-8r2x-fcq9-f9rj.json b/advisories/unreviewed/2025/01/GHSA-8r2x-fcq9-f9rj/GHSA-8r2x-fcq9-f9rj.json index 0cdd716d994..c8f5792c16b 100644 --- a/advisories/unreviewed/2025/01/GHSA-8r2x-fcq9-f9rj/GHSA-8r2x-fcq9-f9rj.json +++ b/advisories/unreviewed/2025/01/GHSA-8r2x-fcq9-f9rj/GHSA-8r2x-fcq9-f9rj.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-vc27-49rw-f322/GHSA-vc27-49rw-f322.json b/advisories/unreviewed/2025/01/GHSA-vc27-49rw-f322/GHSA-vc27-49rw-f322.json index 5e264dbf1d3..0aa873f1f82 100644 --- a/advisories/unreviewed/2025/01/GHSA-vc27-49rw-f322/GHSA-vc27-49rw-f322.json +++ b/advisories/unreviewed/2025/01/GHSA-vc27-49rw-f322/GHSA-vc27-49rw-f322.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-vrgx-86cv-946f/GHSA-vrgx-86cv-946f.json b/advisories/unreviewed/2025/01/GHSA-vrgx-86cv-946f/GHSA-vrgx-86cv-946f.json index e2eaf1480e6..2b52fc99d09 100644 --- a/advisories/unreviewed/2025/01/GHSA-vrgx-86cv-946f/GHSA-vrgx-86cv-946f.json +++ b/advisories/unreviewed/2025/01/GHSA-vrgx-86cv-946f/GHSA-vrgx-86cv-946f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-wjv3-548m-qhxx/GHSA-wjv3-548m-qhxx.json b/advisories/unreviewed/2025/01/GHSA-wjv3-548m-qhxx/GHSA-wjv3-548m-qhxx.json index 9eada063610..4225609f497 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjv3-548m-qhxx/GHSA-wjv3-548m-qhxx.json +++ b/advisories/unreviewed/2025/01/GHSA-wjv3-548m-qhxx/GHSA-wjv3-548m-qhxx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-264g-h4m4-r2w6/GHSA-264g-h4m4-r2w6.json b/advisories/unreviewed/2025/02/GHSA-264g-h4m4-r2w6/GHSA-264g-h4m4-r2w6.json index e1d055606e4..ec13ab1b9fb 100644 --- a/advisories/unreviewed/2025/02/GHSA-264g-h4m4-r2w6/GHSA-264g-h4m4-r2w6.json +++ b/advisories/unreviewed/2025/02/GHSA-264g-h4m4-r2w6/GHSA-264g-h4m4-r2w6.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-264g-h4m4-r2w6", - "modified": "2025-02-19T09:33:30Z", + "modified": "2025-02-25T21:31:34Z", "published": "2025-02-19T09:33:29Z", "aliases": [ "CVE-2025-1135" ], "details": "A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the BatchWinnerEntry functionality. The CurrentFundraiser parameter is directly concatenated into an SQL query without sufficient sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. Please note the vulnerability requires Administrator privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2025/02/GHSA-2hv6-9hx6-7j2g/GHSA-2hv6-9hx6-7j2g.json b/advisories/unreviewed/2025/02/GHSA-2hv6-9hx6-7j2g/GHSA-2hv6-9hx6-7j2g.json new file mode 100644 index 00000000000..083225e5c50 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2hv6-9hx6-7j2g/GHSA-2hv6-9hx6-7j2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hv6-9hx6-7j2g", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-45426" + ], + "details": "Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45426" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-708" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2pq9-46mh-w84j/GHSA-2pq9-46mh-w84j.json b/advisories/unreviewed/2025/02/GHSA-2pq9-46mh-w84j/GHSA-2pq9-46mh-w84j.json index b4bd74dafdf..3852cd69820 100644 --- a/advisories/unreviewed/2025/02/GHSA-2pq9-46mh-w84j/GHSA-2pq9-46mh-w84j.json +++ b/advisories/unreviewed/2025/02/GHSA-2pq9-46mh-w84j/GHSA-2pq9-46mh-w84j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pq9-46mh-w84j", - "modified": "2025-02-14T06:30:36Z", + "modified": "2025-02-25T21:31:33Z", "published": "2025-02-14T06:30:36Z", "aliases": [ "CVE-2024-13692" @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2w4f-h4cf-767r/GHSA-2w4f-h4cf-767r.json b/advisories/unreviewed/2025/02/GHSA-2w4f-h4cf-767r/GHSA-2w4f-h4cf-767r.json new file mode 100644 index 00000000000..6d98fd6088a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2w4f-h4cf-767r/GHSA-2w4f-h4cf-767r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w4f-h4cf-767r", + "modified": "2025-02-25T21:31:43Z", + "published": "2025-02-25T21:31:43Z", + "aliases": [ + "CVE-2024-45421" + ], + "details": "Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45421" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-33xp-654m-3j2x/GHSA-33xp-654m-3j2x.json b/advisories/unreviewed/2025/02/GHSA-33xp-654m-3j2x/GHSA-33xp-654m-3j2x.json new file mode 100644 index 00000000000..2e597ded17c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-33xp-654m-3j2x/GHSA-33xp-654m-3j2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33xp-654m-3j2x", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53879" + ], + "details": "NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53879" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3w3w-mjc4-w534/GHSA-3w3w-mjc4-w534.json b/advisories/unreviewed/2025/02/GHSA-3w3w-mjc4-w534/GHSA-3w3w-mjc4-w534.json index c65b6cc4dc6..d871a923d71 100644 --- a/advisories/unreviewed/2025/02/GHSA-3w3w-mjc4-w534/GHSA-3w3w-mjc4-w534.json +++ b/advisories/unreviewed/2025/02/GHSA-3w3w-mjc4-w534/GHSA-3w3w-mjc4-w534.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w3w-mjc4-w534", - "modified": "2025-02-14T06:30:36Z", + "modified": "2025-02-25T21:31:33Z", "published": "2025-02-14T06:30:36Z", "aliases": [ "CVE-2024-13641" diff --git a/advisories/unreviewed/2025/02/GHSA-4776-6pq8-cq78/GHSA-4776-6pq8-cq78.json b/advisories/unreviewed/2025/02/GHSA-4776-6pq8-cq78/GHSA-4776-6pq8-cq78.json new file mode 100644 index 00000000000..ee2086bc4b4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4776-6pq8-cq78/GHSA-4776-6pq8-cq78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4776-6pq8-cq78", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53877" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause a NULL pointer exception by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53877" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4grm-xc99-7x47/GHSA-4grm-xc99-7x47.json b/advisories/unreviewed/2025/02/GHSA-4grm-xc99-7x47/GHSA-4grm-xc99-7x47.json new file mode 100644 index 00000000000..e1e177be8e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4grm-xc99-7x47/GHSA-4grm-xc99-7x47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4grm-xc99-7x47", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-27245" + ], + "details": "Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27245" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4jjw-p5j8-wcgh/GHSA-4jjw-p5j8-wcgh.json b/advisories/unreviewed/2025/02/GHSA-4jjw-p5j8-wcgh/GHSA-4jjw-p5j8-wcgh.json index 60b073e89ef..b41807aa284 100644 --- a/advisories/unreviewed/2025/02/GHSA-4jjw-p5j8-wcgh/GHSA-4jjw-p5j8-wcgh.json +++ b/advisories/unreviewed/2025/02/GHSA-4jjw-p5j8-wcgh/GHSA-4jjw-p5j8-wcgh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json b/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json index c175c643899..378a6754133 100644 --- a/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json +++ b/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-6753-7pjg-96pv/GHSA-6753-7pjg-96pv.json b/advisories/unreviewed/2025/02/GHSA-6753-7pjg-96pv/GHSA-6753-7pjg-96pv.json new file mode 100644 index 00000000000..6c604edcfe0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6753-7pjg-96pv/GHSA-6753-7pjg-96pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6753-7pjg-96pv", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-53875" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53875" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6ghc-h6hx-hq7x/GHSA-6ghc-h6hx-hq7x.json b/advisories/unreviewed/2025/02/GHSA-6ghc-h6hx-hq7x/GHSA-6ghc-h6hx-hq7x.json index 2a4de29f8ed..4997ff84b28 100644 --- a/advisories/unreviewed/2025/02/GHSA-6ghc-h6hx-hq7x/GHSA-6ghc-h6hx-hq7x.json +++ b/advisories/unreviewed/2025/02/GHSA-6ghc-h6hx-hq7x/GHSA-6ghc-h6hx-hq7x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6ghc-h6hx-hq7x", - "modified": "2025-02-19T09:33:29Z", + "modified": "2025-02-25T21:31:34Z", "published": "2025-02-19T09:33:29Z", "aliases": [ "CVE-2025-1133" ], "details": "A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query without proper sanitization, making it susceptible to SQL injection attacks. An attacker can manipulate the query, potentially leading to data exfiltration, modification, or deletion.  Please note that this vulnerability requires Administrator privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2025/02/GHSA-749j-r6jc-ghfj/GHSA-749j-r6jc-ghfj.json b/advisories/unreviewed/2025/02/GHSA-749j-r6jc-ghfj/GHSA-749j-r6jc-ghfj.json index 4d7dcfae4ea..15c24df0978 100644 --- a/advisories/unreviewed/2025/02/GHSA-749j-r6jc-ghfj/GHSA-749j-r6jc-ghfj.json +++ b/advisories/unreviewed/2025/02/GHSA-749j-r6jc-ghfj/GHSA-749j-r6jc-ghfj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-749j-r6jc-ghfj", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T21:31:40Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2024-53542" ], "details": "Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7wjm-v526-8p9w/GHSA-7wjm-v526-8p9w.json b/advisories/unreviewed/2025/02/GHSA-7wjm-v526-8p9w/GHSA-7wjm-v526-8p9w.json new file mode 100644 index 00000000000..5bb892115d8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7wjm-v526-8p9w/GHSA-7wjm-v526-8p9w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wjm-v526-8p9w", + "modified": "2025-02-25T21:31:43Z", + "published": "2025-02-25T21:31:43Z", + "aliases": [ + "CVE-2024-45424" + ], + "details": "Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45424" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24036" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-84p2-qp33-qgfg/GHSA-84p2-qp33-qgfg.json b/advisories/unreviewed/2025/02/GHSA-84p2-qp33-qgfg/GHSA-84p2-qp33-qgfg.json index a2c44df93be..a3776fec30d 100644 --- a/advisories/unreviewed/2025/02/GHSA-84p2-qp33-qgfg/GHSA-84p2-qp33-qgfg.json +++ b/advisories/unreviewed/2025/02/GHSA-84p2-qp33-qgfg/GHSA-84p2-qp33-qgfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84p2-qp33-qgfg", - "modified": "2025-02-14T09:31:22Z", + "modified": "2025-02-25T21:31:33Z", "published": "2025-02-14T09:31:22Z", "aliases": [ "CVE-2024-9601" diff --git a/advisories/unreviewed/2025/02/GHSA-8528-jjpw-q9wx/GHSA-8528-jjpw-q9wx.json b/advisories/unreviewed/2025/02/GHSA-8528-jjpw-q9wx/GHSA-8528-jjpw-q9wx.json index 483ce39fed8..00476e84bd1 100644 --- a/advisories/unreviewed/2025/02/GHSA-8528-jjpw-q9wx/GHSA-8528-jjpw-q9wx.json +++ b/advisories/unreviewed/2025/02/GHSA-8528-jjpw-q9wx/GHSA-8528-jjpw-q9wx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-8wc2-54gh-pq44/GHSA-8wc2-54gh-pq44.json b/advisories/unreviewed/2025/02/GHSA-8wc2-54gh-pq44/GHSA-8wc2-54gh-pq44.json new file mode 100644 index 00000000000..61b0b716658 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8wc2-54gh-pq44/GHSA-8wc2-54gh-pq44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wc2-54gh-pq44", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-27239" + ], + "details": "Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27239" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9733-vpvw-5rpc/GHSA-9733-vpvw-5rpc.json b/advisories/unreviewed/2025/02/GHSA-9733-vpvw-5rpc/GHSA-9733-vpvw-5rpc.json index af559dcc85f..cacb7de002d 100644 --- a/advisories/unreviewed/2025/02/GHSA-9733-vpvw-5rpc/GHSA-9733-vpvw-5rpc.json +++ b/advisories/unreviewed/2025/02/GHSA-9733-vpvw-5rpc/GHSA-9733-vpvw-5rpc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9733-vpvw-5rpc", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T21:31:40Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2024-57685" ], "details": "An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c499-vvj4-hwww/GHSA-c499-vvj4-hwww.json b/advisories/unreviewed/2025/02/GHSA-c499-vvj4-hwww/GHSA-c499-vvj4-hwww.json new file mode 100644 index 00000000000..1ba71798fc7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c499-vvj4-hwww/GHSA-c499-vvj4-hwww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c499-vvj4-hwww", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-53872" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53872" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c8j4-9hch-jp6v/GHSA-c8j4-9hch-jp6v.json b/advisories/unreviewed/2025/02/GHSA-c8j4-9hch-jp6v/GHSA-c8j4-9hch-jp6v.json index c1a67f2527b..977cf102ed1 100644 --- a/advisories/unreviewed/2025/02/GHSA-c8j4-9hch-jp6v/GHSA-c8j4-9hch-jp6v.json +++ b/advisories/unreviewed/2025/02/GHSA-c8j4-9hch-jp6v/GHSA-c8j4-9hch-jp6v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-cq9g-38fc-j53v/GHSA-cq9g-38fc-j53v.json b/advisories/unreviewed/2025/02/GHSA-cq9g-38fc-j53v/GHSA-cq9g-38fc-j53v.json index fc50916dede..286f8be453a 100644 --- a/advisories/unreviewed/2025/02/GHSA-cq9g-38fc-j53v/GHSA-cq9g-38fc-j53v.json +++ b/advisories/unreviewed/2025/02/GHSA-cq9g-38fc-j53v/GHSA-cq9g-38fc-j53v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq9g-38fc-j53v", - "modified": "2025-02-20T06:31:03Z", + "modified": "2025-02-25T21:31:37Z", "published": "2025-02-20T06:31:03Z", "aliases": [ "CVE-2024-13445" diff --git a/advisories/unreviewed/2025/02/GHSA-fvhg-h82j-jfjq/GHSA-fvhg-h82j-jfjq.json b/advisories/unreviewed/2025/02/GHSA-fvhg-h82j-jfjq/GHSA-fvhg-h82j-jfjq.json new file mode 100644 index 00000000000..c1d63585b40 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fvhg-h82j-jfjq/GHSA-fvhg-h82j-jfjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvhg-h82j-jfjq", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-53874" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53874" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json b/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json index 63492e2cc2e..a798ca87e0e 100644 --- a/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json +++ b/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvx6-jx94-49qx", - "modified": "2025-02-25T06:30:52Z", + "modified": "2025-02-25T21:31:40Z", "published": "2025-02-25T06:30:52Z", "aliases": [ "CVE-2025-22210" ], "details": "A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-25T06:15:23Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gw2v-7p5h-4fwr/GHSA-gw2v-7p5h-4fwr.json b/advisories/unreviewed/2025/02/GHSA-gw2v-7p5h-4fwr/GHSA-gw2v-7p5h-4fwr.json index 7450adc74e3..3612eb35a46 100644 --- a/advisories/unreviewed/2025/02/GHSA-gw2v-7p5h-4fwr/GHSA-gw2v-7p5h-4fwr.json +++ b/advisories/unreviewed/2025/02/GHSA-gw2v-7p5h-4fwr/GHSA-gw2v-7p5h-4fwr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gw2v-7p5h-4fwr", - "modified": "2025-02-19T09:33:29Z", + "modified": "2025-02-25T21:31:34Z", "published": "2025-02-19T09:33:29Z", "aliases": [ "CVE-2025-1134" ], "details": "A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser parameter is directly concatenated into an SQL query without sufficient sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. Please note that this vulnerability requires Administrator privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2025/02/GHSA-hjmv-v6c5-x23j/GHSA-hjmv-v6c5-x23j.json b/advisories/unreviewed/2025/02/GHSA-hjmv-v6c5-x23j/GHSA-hjmv-v6c5-x23j.json index a3ea5a43875..9a907338c4b 100644 --- a/advisories/unreviewed/2025/02/GHSA-hjmv-v6c5-x23j/GHSA-hjmv-v6c5-x23j.json +++ b/advisories/unreviewed/2025/02/GHSA-hjmv-v6c5-x23j/GHSA-hjmv-v6c5-x23j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjmv-v6c5-x23j", - "modified": "2025-02-25T00:31:49Z", + "modified": "2025-02-25T21:31:40Z", "published": "2025-02-25T00:31:48Z", "aliases": [ "CVE-2024-57608" ], "details": "An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T22:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hp33-4xv5-445m/GHSA-hp33-4xv5-445m.json b/advisories/unreviewed/2025/02/GHSA-hp33-4xv5-445m/GHSA-hp33-4xv5-445m.json new file mode 100644 index 00000000000..28b255e0d70 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hp33-4xv5-445m/GHSA-hp33-4xv5-445m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp33-4xv5-445m", + "modified": "2025-02-25T21:31:43Z", + "published": "2025-02-25T21:31:43Z", + "aliases": [ + "CVE-2024-45425" + ], + "details": "Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45425" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json b/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json index 5b7a413952c..01064c293a6 100644 --- a/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json +++ b/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-jv6c-2mw3-h322/GHSA-jv6c-2mw3-h322.json b/advisories/unreviewed/2025/02/GHSA-jv6c-2mw3-h322/GHSA-jv6c-2mw3-h322.json new file mode 100644 index 00000000000..be67f0738d3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jv6c-2mw3-h322/GHSA-jv6c-2mw3-h322.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv6c-2mw3-h322", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53870" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53870" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m95x-5www-9p45/GHSA-m95x-5www-9p45.json b/advisories/unreviewed/2025/02/GHSA-m95x-5www-9p45/GHSA-m95x-5www-9p45.json new file mode 100644 index 00000000000..25eec36fb66 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m95x-5www-9p45/GHSA-m95x-5www-9p45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m95x-5www-9p45", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53878" + ], + "details": "NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53878" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json index a5cc3d60dc5..db330e59eb2 100644 --- a/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json +++ b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2h9-63jc-gj67", - "modified": "2025-02-11T15:32:24Z", + "modified": "2025-02-25T21:31:28Z", "published": "2025-02-11T12:30:54Z", "aliases": [ "CVE-2025-0526" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://advisories.octopus.com/post/2024/sa2025-03" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2025/sa2025-03" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-ppxx-pr9w-7ww8/GHSA-ppxx-pr9w-7ww8.json b/advisories/unreviewed/2025/02/GHSA-ppxx-pr9w-7ww8/GHSA-ppxx-pr9w-7ww8.json new file mode 100644 index 00000000000..a085564bb92 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ppxx-pr9w-7ww8/GHSA-ppxx-pr9w-7ww8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppxx-pr9w-7ww8", + "modified": "2025-02-25T21:31:44Z", + "published": "2025-02-25T21:31:44Z", + "aliases": [ + "CVE-2024-0148" + ], + "details": "NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0148" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5617" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-447" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pvq4-rqfr-rc8r/GHSA-pvq4-rqfr-rc8r.json b/advisories/unreviewed/2025/02/GHSA-pvq4-rqfr-rc8r/GHSA-pvq4-rqfr-rc8r.json new file mode 100644 index 00000000000..0e9ae7b6472 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pvq4-rqfr-rc8r/GHSA-pvq4-rqfr-rc8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvq4-rqfr-rc8r", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-27246" + ], + "details": "Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27246" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pvxx-h279-jv5h/GHSA-pvxx-h279-jv5h.json b/advisories/unreviewed/2025/02/GHSA-pvxx-h279-jv5h/GHSA-pvxx-h279-jv5h.json new file mode 100644 index 00000000000..634023c3a08 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pvxx-h279-jv5h/GHSA-pvxx-h279-jv5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvxx-h279-jv5h", + "modified": "2025-02-25T21:31:42Z", + "published": "2025-02-25T21:31:42Z", + "aliases": [ + "CVE-2024-45417" + ], + "details": "Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45417" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-708" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q7mr-3qgg-qjxx/GHSA-q7mr-3qgg-qjxx.json b/advisories/unreviewed/2025/02/GHSA-q7mr-3qgg-qjxx/GHSA-q7mr-3qgg-qjxx.json new file mode 100644 index 00000000000..9612e3158c3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q7mr-3qgg-qjxx/GHSA-q7mr-3qgg-qjxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7mr-3qgg-qjxx", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53871" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53871" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json b/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json index 3b410f0d4c8..c9de5bf3753 100644 --- a/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json +++ b/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfxj-99gm-r9jr", - "modified": "2025-02-25T15:34:36Z", + "modified": "2025-02-25T21:31:41Z", "published": "2025-02-25T15:34:36Z", "aliases": [ "CVE-2024-34036" ], "details": "An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection between a gNB and the Near RT-RIC by inundating the system with a high volume of subscription requests via an xApp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-25T15:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json b/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json index 73906eec3e7..aacb37550d4 100644 --- a/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json +++ b/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr8x-m34w-97pj", - "modified": "2025-02-12T15:31:58Z", + "modified": "2025-02-25T21:31:29Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2025-0506" diff --git a/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json b/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json index fb2fcd0d403..fb0edf2f129 100644 --- a/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json +++ b/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg35-696m-j8xx", - "modified": "2025-02-25T15:34:36Z", + "modified": "2025-02-25T21:31:41Z", "published": "2025-02-25T15:34:36Z", "aliases": [ "CVE-2024-34035" ], "details": "An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a significant quantity of E2 Subscription Requests originating from an xApp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-25T15:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vqx6-86fx-35gx/GHSA-vqx6-86fx-35gx.json b/advisories/unreviewed/2025/02/GHSA-vqx6-86fx-35gx/GHSA-vqx6-86fx-35gx.json index dcf3c41d5ee..0d19bf8488c 100644 --- a/advisories/unreviewed/2025/02/GHSA-vqx6-86fx-35gx/GHSA-vqx6-86fx-35gx.json +++ b/advisories/unreviewed/2025/02/GHSA-vqx6-86fx-35gx/GHSA-vqx6-86fx-35gx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vqx6-86fx-35gx", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T21:31:40Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2024-53543" ], "details": "NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-w3pv-gx2c-27p2/GHSA-w3pv-gx2c-27p2.json b/advisories/unreviewed/2025/02/GHSA-w3pv-gx2c-27p2/GHSA-w3pv-gx2c-27p2.json new file mode 100644 index 00000000000..6033f6b9ae6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w3pv-gx2c-27p2/GHSA-w3pv-gx2c-27p2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3pv-gx2c-27p2", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53873" + ], + "details": "NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53873" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w56m-wcpr-36rf/GHSA-w56m-wcpr-36rf.json b/advisories/unreviewed/2025/02/GHSA-w56m-wcpr-36rf/GHSA-w56m-wcpr-36rf.json index 7b5069e4e12..298bdca24a8 100644 --- a/advisories/unreviewed/2025/02/GHSA-w56m-wcpr-36rf/GHSA-w56m-wcpr-36rf.json +++ b/advisories/unreviewed/2025/02/GHSA-w56m-wcpr-36rf/GHSA-w56m-wcpr-36rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w56m-wcpr-36rf", - "modified": "2025-02-20T09:31:36Z", + "modified": "2025-02-25T21:31:39Z", "published": "2025-02-20T09:31:36Z", "aliases": [ "CVE-2025-0897" diff --git a/advisories/unreviewed/2025/02/GHSA-wg6m-8vxm-79gv/GHSA-wg6m-8vxm-79gv.json b/advisories/unreviewed/2025/02/GHSA-wg6m-8vxm-79gv/GHSA-wg6m-8vxm-79gv.json new file mode 100644 index 00000000000..13b89d43251 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wg6m-8vxm-79gv/GHSA-wg6m-8vxm-79gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg6m-8vxm-79gv", + "modified": "2025-02-25T21:31:45Z", + "published": "2025-02-25T21:31:45Z", + "aliases": [ + "CVE-2024-53876" + ], + "details": "NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53876" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x3g3-3qwm-w95x/GHSA-x3g3-3qwm-w95x.json b/advisories/unreviewed/2025/02/GHSA-x3g3-3qwm-w95x/GHSA-x3g3-3qwm-w95x.json new file mode 100644 index 00000000000..1095b169c48 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x3g3-3qwm-w95x/GHSA-x3g3-3qwm-w95x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3g3-3qwm-w95x", + "modified": "2025-02-25T21:31:42Z", + "published": "2025-02-25T21:31:42Z", + "aliases": [ + "CVE-2024-36259" + ], + "details": "Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36259" + }, + { + "type": "WEB", + "url": "https://github.com/odoo/odoo/issues/199330" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json b/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json new file mode 100644 index 00000000000..a62ef374902 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjc3-vjh6-m283", + "modified": "2025-02-25T21:31:43Z", + "published": "2025-02-25T21:31:43Z", + "aliases": [ + "CVE-2024-45418" + ], + "details": "Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45418" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24040" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json b/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json index 9a6347021b9..21bf3e911b0 100644 --- a/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json +++ b/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xvm3-w96c-9whc", - "modified": "2025-02-25T15:34:36Z", + "modified": "2025-02-25T21:31:41Z", "published": "2025-02-25T15:34:36Z", "aliases": [ "CVE-2024-34034" ], "details": "An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-25T15:15:21Z"