From b498d52c6f372b9d066585b1352e059f4d94f59f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 00:32:23 +0000 Subject: [PATCH] Publish Advisories GHSA-7chv-rrw6-w6fc GHSA-23vx-xx4m-jf8w GHSA-2qv8-5g35-4jxg GHSA-427v-vg76-wcjg GHSA-54p7-6g3w-c6qg GHSA-85xp-66c9-65fx GHSA-8849-3gmw-cqc7 GHSA-92x5-3wh4-435c GHSA-93qg-f4mj-vh6p GHSA-9fwx-p432-xmr2 GHSA-f7qj-xcc8-v25j GHSA-fg49-2894-qr7w GHSA-g8qx-492c-9982 GHSA-m66r-fg5x-99cr GHSA-qv5g-75w4-jq79 GHSA-xc75-cc6q-49fg GHSA-xpp4-mh2g-6345 --- .../GHSA-7chv-rrw6-w6fc.json | 18 +++++- .../GHSA-23vx-xx4m-jf8w.json | 56 +++++++++++++++++++ .../GHSA-2qv8-5g35-4jxg.json | 52 +++++++++++++++++ .../GHSA-427v-vg76-wcjg.json | 44 +++++++++++++++ .../GHSA-54p7-6g3w-c6qg.json | 6 +- .../GHSA-85xp-66c9-65fx.json | 44 +++++++++++++++ .../GHSA-8849-3gmw-cqc7.json | 29 ++++++++++ .../GHSA-92x5-3wh4-435c.json | 37 ++++++++++++ .../GHSA-93qg-f4mj-vh6p.json | 52 +++++++++++++++++ .../GHSA-9fwx-p432-xmr2.json | 37 ++++++++++++ .../GHSA-f7qj-xcc8-v25j.json | 44 +++++++++++++++ .../GHSA-fg49-2894-qr7w.json | 44 +++++++++++++++ .../GHSA-g8qx-492c-9982.json | 37 ++++++++++++ .../GHSA-m66r-fg5x-99cr.json | 41 ++++++++++++++ .../GHSA-qv5g-75w4-jq79.json | 29 ++++++++++ .../GHSA-xc75-cc6q-49fg.json | 37 ++++++++++++ .../GHSA-xpp4-mh2g-6345.json | 37 ++++++++++++ 17 files changed, 642 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-23vx-xx4m-jf8w/GHSA-23vx-xx4m-jf8w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-2qv8-5g35-4jxg/GHSA-2qv8-5g35-4jxg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-427v-vg76-wcjg/GHSA-427v-vg76-wcjg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-85xp-66c9-65fx/GHSA-85xp-66c9-65fx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8849-3gmw-cqc7/GHSA-8849-3gmw-cqc7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-92x5-3wh4-435c/GHSA-92x5-3wh4-435c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-93qg-f4mj-vh6p/GHSA-93qg-f4mj-vh6p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9fwx-p432-xmr2/GHSA-9fwx-p432-xmr2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f7qj-xcc8-v25j/GHSA-f7qj-xcc8-v25j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fg49-2894-qr7w/GHSA-fg49-2894-qr7w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g8qx-492c-9982/GHSA-g8qx-492c-9982.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m66r-fg5x-99cr/GHSA-m66r-fg5x-99cr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qv5g-75w4-jq79/GHSA-qv5g-75w4-jq79.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xc75-cc6q-49fg/GHSA-xc75-cc6q-49fg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xpp4-mh2g-6345/GHSA-xpp4-mh2g-6345.json diff --git a/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json b/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json index 15fcae4d670..23c9891a2e3 100644 --- a/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json +++ b/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7chv-rrw6-w6fc", - "modified": "2025-05-29T23:28:48Z", + "modified": "2025-05-30T00:31:13Z", "published": "2021-05-18T18:36:27Z", "aliases": [ "CVE-2021-29505" @@ -92,6 +92,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/07/msg00004.html" @@ -100,6 +112,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/r8ee51debf7fd184b6a6b020dc31df25118b0aa612885f12fbe77f04f@%3Cdev.jmeter.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r8ee51debf7fd184b6a6b020dc31df25118b0aa612885f12fbe77f04f%40%3Cdev.jmeter.apache.org%3E" + }, { "type": "PACKAGE", "url": "https://github.com/x-stream/xstream" diff --git a/advisories/unreviewed/2025/05/GHSA-23vx-xx4m-jf8w/GHSA-23vx-xx4m-jf8w.json b/advisories/unreviewed/2025/05/GHSA-23vx-xx4m-jf8w/GHSA-23vx-xx4m-jf8w.json new file mode 100644 index 00000000000..58590d26a9e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-23vx-xx4m-jf8w/GHSA-23vx-xx4m-jf8w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23vx-xx4m-jf8w", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-5332" + ], + "details": "A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5332" + }, + { + "type": "WEB", + "url": "https://github.com/ubfbuz3/cve/issues/16" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2qv8-5g35-4jxg/GHSA-2qv8-5g35-4jxg.json b/advisories/unreviewed/2025/05/GHSA-2qv8-5g35-4jxg/GHSA-2qv8-5g35-4jxg.json new file mode 100644 index 00000000000..c4cfd88cbe1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2qv8-5g35-4jxg/GHSA-2qv8-5g35-4jxg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qv8-5g35-4jxg", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-5330" + ], + "details": "A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component RETR Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5330" + }, + { + "type": "WEB", + "url": "https://github.com/r3ng4f/FreeFloat_1/blob/main/01-exploit.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585402" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-427v-vg76-wcjg/GHSA-427v-vg76-wcjg.json b/advisories/unreviewed/2025/05/GHSA-427v-vg76-wcjg/GHSA-427v-vg76-wcjg.json new file mode 100644 index 00000000000..fc9ca77e841 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-427v-vg76-wcjg/GHSA-427v-vg76-wcjg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-427v-vg76-wcjg", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-46352" + ], + "details": "The CS5000 Fire Panel is vulnerable due to a hard-coded password that \nruns on a VNC server and is visible as a string in the binary \nresponsible for running VNC. This password cannot be altered, allowing \nanyone with knowledge of it to gain remote access to the panel. Such \naccess could enable an attacker to operate the panel remotely, \npotentially putting the fire panel into a non-functional state and \ncausing serious safety issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46352" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-148-03" + }, + { + "type": "WEB", + "url": "https://www.consiliumsafety.com/en/support" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json b/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json index a99f7bd070c..3c099601d1c 100644 --- a/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json +++ b/advisories/unreviewed/2025/05/GHSA-54p7-6g3w-c6qg/GHSA-54p7-6g3w-c6qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54p7-6g3w-c6qg", - "modified": "2025-05-07T15:31:44Z", + "modified": "2025-05-30T00:31:13Z", "published": "2025-05-07T15:31:44Z", "aliases": [ "CVE-2025-47497" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47497" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00044.html" + }, { "type": "WEB", "url": "https://patchstack.com/database/wordpress/plugin/logo-showcase/vulnerability/wordpress-logo-showcase-3-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-85xp-66c9-65fx/GHSA-85xp-66c9-65fx.json b/advisories/unreviewed/2025/05/GHSA-85xp-66c9-65fx/GHSA-85xp-66c9-65fx.json new file mode 100644 index 00000000000..61da1b1f0fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-85xp-66c9-65fx/GHSA-85xp-66c9-65fx.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85xp-66c9-65fx", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-41438" + ], + "details": "The CS5000 Fire Panel is vulnerable due to a default account that exists\n on the panel. Even though it is possible to change this by SSHing into \nthe device, it has remained unchanged on every installed system \nobserved. This account is not root but holds high-level permissions that\n could severely impact the device's operation if exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41438" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-148-03" + }, + { + "type": "WEB", + "url": "https://www.consiliumsafety.com/en/support" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8849-3gmw-cqc7/GHSA-8849-3gmw-cqc7.json b/advisories/unreviewed/2025/05/GHSA-8849-3gmw-cqc7/GHSA-8849-3gmw-cqc7.json new file mode 100644 index 00000000000..4444aa1ab4d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8849-3gmw-cqc7/GHSA-8849-3gmw-cqc7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8849-3gmw-cqc7", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-31263" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31263" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-92x5-3wh4-435c/GHSA-92x5-3wh4-435c.json b/advisories/unreviewed/2025/05/GHSA-92x5-3wh4-435c/GHSA-92x5-3wh4-435c.json new file mode 100644 index 00000000000..29639b8245a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-92x5-3wh4-435c/GHSA-92x5-3wh4-435c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92x5-3wh4-435c", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-31264" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with physical access to a locked device may be able to view sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31264" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-93qg-f4mj-vh6p/GHSA-93qg-f4mj-vh6p.json b/advisories/unreviewed/2025/05/GHSA-93qg-f4mj-vh6p/GHSA-93qg-f4mj-vh6p.json new file mode 100644 index 00000000000..640169e0d8f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-93qg-f4mj-vh6p/GHSA-93qg-f4mj-vh6p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93qg-f4mj-vh6p", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-5331" + ], + "details": "A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5331" + }, + { + "type": "WEB", + "url": "https://github.com/r3ng4f/PCMan_1/blob/main/exploit02.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.585404" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9fwx-p432-xmr2/GHSA-9fwx-p432-xmr2.json b/advisories/unreviewed/2025/05/GHSA-9fwx-p432-xmr2/GHSA-9fwx-p432-xmr2.json new file mode 100644 index 00000000000..c48c749b455 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9fwx-p432-xmr2/GHSA-9fwx-p432-xmr2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fwx-p432-xmr2", + "modified": "2025-05-30T00:31:13Z", + "published": "2025-05-30T00:31:13Z", + "aliases": [ + "CVE-2025-31199" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31199" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f7qj-xcc8-v25j/GHSA-f7qj-xcc8-v25j.json b/advisories/unreviewed/2025/05/GHSA-f7qj-xcc8-v25j/GHSA-f7qj-xcc8-v25j.json new file mode 100644 index 00000000000..d698ce9efd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f7qj-xcc8-v25j/GHSA-f7qj-xcc8-v25j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7qj-xcc8-v25j", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-1907" + ], + "details": "Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1907" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-148-04" + }, + { + "type": "WEB", + "url": "https://www.instantel.com/service-and-support/contact-technical-support" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fg49-2894-qr7w/GHSA-fg49-2894-qr7w.json b/advisories/unreviewed/2025/05/GHSA-fg49-2894-qr7w/GHSA-fg49-2894-qr7w.json new file mode 100644 index 00000000000..2a13fd66610 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fg49-2894-qr7w/GHSA-fg49-2894-qr7w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg49-2894-qr7w", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-5307" + ], + "details": "Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue to potentially disclose information and to execute arbitrary code on affected installations of Sante DICOM Viewer Pro.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5307" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-148-01" + }, + { + "type": "WEB", + "url": "https://www.santesoft.com/win/sante-dicom-viewer-pro/download.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g8qx-492c-9982/GHSA-g8qx-492c-9982.json b/advisories/unreviewed/2025/05/GHSA-g8qx-492c-9982/GHSA-g8qx-492c-9982.json new file mode 100644 index 00000000000..34334878398 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g8qx-492c-9982/GHSA-g8qx-492c-9982.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8qx-492c-9982", + "modified": "2025-05-30T00:31:13Z", + "published": "2025-05-30T00:31:13Z", + "aliases": [ + "CVE-2025-31189" + ], + "details": "A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31189" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m66r-fg5x-99cr/GHSA-m66r-fg5x-99cr.json b/advisories/unreviewed/2025/05/GHSA-m66r-fg5x-99cr/GHSA-m66r-fg5x-99cr.json new file mode 100644 index 00000000000..97b8a753600 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m66r-fg5x-99cr/GHSA-m66r-fg5x-99cr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m66r-fg5x-99cr", + "modified": "2025-05-30T00:31:13Z", + "published": "2025-05-30T00:31:13Z", + "aliases": [ + "CVE-2025-30466" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, visionOS 2.4, macOS Sequoia 15.4. A website may be able to bypass Same Origin Policy.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30466" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122379" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qv5g-75w4-jq79/GHSA-qv5g-75w4-jq79.json b/advisories/unreviewed/2025/05/GHSA-qv5g-75w4-jq79/GHSA-qv5g-75w4-jq79.json new file mode 100644 index 00000000000..b2a770c3301 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qv5g-75w4-jq79/GHSA-qv5g-75w4-jq79.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv5g-75w4-jq79", + "modified": "2025-05-30T00:31:13Z", + "published": "2025-05-30T00:31:13Z", + "aliases": [ + "CVE-2025-31231" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31231" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xc75-cc6q-49fg/GHSA-xc75-cc6q-49fg.json b/advisories/unreviewed/2025/05/GHSA-xc75-cc6q-49fg/GHSA-xc75-cc6q-49fg.json new file mode 100644 index 00000000000..f93040bfbbe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xc75-cc6q-49fg/GHSA-xc75-cc6q-49fg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc75-cc6q-49fg", + "modified": "2025-05-30T00:31:13Z", + "published": "2025-05-30T00:31:13Z", + "aliases": [ + "CVE-2025-31198" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A path handling issue was addressed with improved validation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31198" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xpp4-mh2g-6345/GHSA-xpp4-mh2g-6345.json b/advisories/unreviewed/2025/05/GHSA-xpp4-mh2g-6345/GHSA-xpp4-mh2g-6345.json new file mode 100644 index 00000000000..685eeab2406 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xpp4-mh2g-6345/GHSA-xpp4-mh2g-6345.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpp4-mh2g-6345", + "modified": "2025-05-30T00:31:14Z", + "published": "2025-05-30T00:31:14Z", + "aliases": [ + "CVE-2025-31261" + ], + "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31261" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T22:15:22Z" + } +} \ No newline at end of file