diff --git a/advisories/unreviewed/2022/05/GHSA-frjj-4mjw-3gmf/GHSA-frjj-4mjw-3gmf.json b/advisories/unreviewed/2022/05/GHSA-frjj-4mjw-3gmf/GHSA-frjj-4mjw-3gmf.json
index 89ab12988ed..d6667be9e3a 100644
--- a/advisories/unreviewed/2022/05/GHSA-frjj-4mjw-3gmf/GHSA-frjj-4mjw-3gmf.json
+++ b/advisories/unreviewed/2022/05/GHSA-frjj-4mjw-3gmf/GHSA-frjj-4mjw-3gmf.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frjj-4mjw-3gmf",
- "modified": "2022-05-24T16:55:32Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2022-05-24T16:55:32Z",
"aliases": [
"CVE-2019-10891"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://github.com/Kirin-say/Vulnerabilities/blob/master/DIR-806_Code_Injection.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10282"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2022/05/GHSA-x629-5xff-w7qg/GHSA-x629-5xff-w7qg.json b/advisories/unreviewed/2022/05/GHSA-x629-5xff-w7qg/GHSA-x629-5xff-w7qg.json
index 7f7dd41f2af..99148b9c64e 100644
--- a/advisories/unreviewed/2022/05/GHSA-x629-5xff-w7qg/GHSA-x629-5xff-w7qg.json
+++ b/advisories/unreviewed/2022/05/GHSA-x629-5xff-w7qg/GHSA-x629-5xff-w7qg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x629-5xff-w7qg",
- "modified": "2024-07-03T18:31:15Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2022-05-17T03:11:58Z",
"aliases": [
"CVE-2015-2051"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2051"
},
+ {
+ "type": "WEB",
+ "url": "https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10282"
+ },
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/37171"
diff --git a/advisories/unreviewed/2022/08/GHSA-45v7-mh84-5f9p/GHSA-45v7-mh84-5f9p.json b/advisories/unreviewed/2022/08/GHSA-45v7-mh84-5f9p/GHSA-45v7-mh84-5f9p.json
index 5de57fd1845..5dd095f69fd 100644
--- a/advisories/unreviewed/2022/08/GHSA-45v7-mh84-5f9p/GHSA-45v7-mh84-5f9p.json
+++ b/advisories/unreviewed/2022/08/GHSA-45v7-mh84-5f9p/GHSA-45v7-mh84-5f9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45v7-mh84-5f9p",
- "modified": "2022-09-02T00:01:10Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2022-08-29T00:00:33Z",
"aliases": [
"CVE-2022-37055"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing"
},
+ {
+ "type": "WEB",
+ "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308"
+ },
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin"
diff --git a/advisories/unreviewed/2022/08/GHSA-8jw9-7jrj-wp3f/GHSA-8jw9-7jrj-wp3f.json b/advisories/unreviewed/2022/08/GHSA-8jw9-7jrj-wp3f/GHSA-8jw9-7jrj-wp3f.json
index 2ab21407afa..87277f730ab 100644
--- a/advisories/unreviewed/2022/08/GHSA-8jw9-7jrj-wp3f/GHSA-8jw9-7jrj-wp3f.json
+++ b/advisories/unreviewed/2022/08/GHSA-8jw9-7jrj-wp3f/GHSA-8jw9-7jrj-wp3f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jw9-7jrj-wp3f",
- "modified": "2022-09-02T00:01:05Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2022-08-29T00:00:33Z",
"aliases": [
"CVE-2022-37057"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://drive.google.com/file/d/1_UUpraFTxxB97ujrgVLQZXQ8Q8M58BAF/view?usp=sharing"
},
+ {
+ "type": "WEB",
+ "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308"
+ },
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin"
@@ -30,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2022/08/GHSA-9h5m-xxfw-pfmj/GHSA-9h5m-xxfw-pfmj.json b/advisories/unreviewed/2022/08/GHSA-9h5m-xxfw-pfmj/GHSA-9h5m-xxfw-pfmj.json
index 317111bb062..99a9eb5b488 100644
--- a/advisories/unreviewed/2022/08/GHSA-9h5m-xxfw-pfmj/GHSA-9h5m-xxfw-pfmj.json
+++ b/advisories/unreviewed/2022/08/GHSA-9h5m-xxfw-pfmj/GHSA-9h5m-xxfw-pfmj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h5m-xxfw-pfmj",
- "modified": "2022-09-02T00:01:10Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2022-08-29T00:00:33Z",
"aliases": [
"CVE-2022-37056"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://drive.google.com/file/d/127tqMUvAxQ4OlycoSNtcP0x2282Y75GJ/view?usp=sharing"
},
+ {
+ "type": "WEB",
+ "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308"
+ },
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin"
@@ -30,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-q9cc-2q3j-jfm7/GHSA-q9cc-2q3j-jfm7.json b/advisories/unreviewed/2024/05/GHSA-q9cc-2q3j-jfm7/GHSA-q9cc-2q3j-jfm7.json
index 0de80cecd5a..85809b55272 100644
--- a/advisories/unreviewed/2024/05/GHSA-q9cc-2q3j-jfm7/GHSA-q9cc-2q3j-jfm7.json
+++ b/advisories/unreviewed/2024/05/GHSA-q9cc-2q3j-jfm7/GHSA-q9cc-2q3j-jfm7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9cc-2q3j-jfm7",
- "modified": "2024-08-05T21:31:19Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2024-05-06T15:30:39Z",
"aliases": [
"CVE-2024-33112"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33112"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/yj94/Yj_learning/blob/b597925953d8bbb286a63f0019bb547c1617cb61/Week16/D-LINK-POC.md"
+ },
{
"type": "WEB",
"url": "https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md"
@@ -26,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-77"
+ "CWE-77",
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-355x-frhv-pxh6/GHSA-355x-frhv-pxh6.json b/advisories/unreviewed/2024/12/GHSA-355x-frhv-pxh6/GHSA-355x-frhv-pxh6.json
index 900bd574415..7f72a679568 100644
--- a/advisories/unreviewed/2024/12/GHSA-355x-frhv-pxh6/GHSA-355x-frhv-pxh6.json
+++ b/advisories/unreviewed/2024/12/GHSA-355x-frhv-pxh6/GHSA-355x-frhv-pxh6.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-4mg3-889w-x7xm/GHSA-4mg3-889w-x7xm.json b/advisories/unreviewed/2024/12/GHSA-4mg3-889w-x7xm/GHSA-4mg3-889w-x7xm.json
index 25f94e0bb75..0d09816d765 100644
--- a/advisories/unreviewed/2024/12/GHSA-4mg3-889w-x7xm/GHSA-4mg3-889w-x7xm.json
+++ b/advisories/unreviewed/2024/12/GHSA-4mg3-889w-x7xm/GHSA-4mg3-889w-x7xm.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-4vc6-7qhx-wxq5/GHSA-4vc6-7qhx-wxq5.json b/advisories/unreviewed/2024/12/GHSA-4vc6-7qhx-wxq5/GHSA-4vc6-7qhx-wxq5.json
index 7b6117d1f4b..cd7a4b9d942 100644
--- a/advisories/unreviewed/2024/12/GHSA-4vc6-7qhx-wxq5/GHSA-4vc6-7qhx-wxq5.json
+++ b/advisories/unreviewed/2024/12/GHSA-4vc6-7qhx-wxq5/GHSA-4vc6-7qhx-wxq5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vc6-7qhx-wxq5",
- "modified": "2024-12-27T15:31:56Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2024-12-27T15:31:56Z",
"aliases": [
"CVE-2024-56674"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: correct netdev_tx_reset_queue() invocation point\n\nWhen virtnet_close is followed by virtnet_open, some TX completions can\npossibly remain unconsumed, until they are finally processed during the\nfirst NAPI poll after the netdev_tx_reset_queue(), resulting in a crash\n[1]. Commit b96ed2c97c79 (\"virtio_net: move netdev_tx_reset_queue() call\nbefore RX napi enable\") was not sufficient to eliminate all BQL crash\ncases for virtio-net.\n\nThis issue can be reproduced with the latest net-next master by running:\n`while :; do ip l set DEV down; ip l set DEV up; done` under heavy network\nTX load from inside the machine.\n\nnetdev_tx_reset_queue() can actually be dropped from virtnet_open path;\nthe device is not stopped in any case. For BQL core part, it's just like\ntraffic nearly ceases to exist for some period. For stall detector added\nto BQL, even if virtnet_close could somehow lead to some TX completions\ndelayed for long, followed by virtnet_open, we can just take it as stall\nas mentioned in commit 6025b9135f7a (\"net: dqs: add NIC stall detector\nbased on BQL\"). Note also that users can still reset stall_max via sysfs.\n\nSo, drop netdev_tx_reset_queue() from virtnet_enable_queue_pair(). This\neliminates the BQL crashes. As a result, netdev_tx_reset_queue() is now\nexplicitly required in freeze/restore path. This patch adds it to\nimmediately after free_unused_bufs(), following the rule of thumb:\nnetdev_tx_reset_queue() should follow any SKB freeing not followed by\nnetdev_tx_completed_queue(). This seems the most consistent and\nstreamlined approach, and now netdev_tx_reset_queue() runs whenever\nfree_unused_bufs() is done.\n\n[1]:\n------------[ cut here ]------------\nkernel BUG at lib/dynamic_queue_limits.c:99!\nOops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 7 UID: 0 PID: 1598 Comm: ip Tainted: G N 6.12.0net-next_main+ #2\nTainted: [N]=TEST\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), \\\nBIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:dql_completed+0x26b/0x290\nCode: b7 c2 49 89 e9 44 89 da 89 c6 4c 89 d7 e8 ed 17 47 00 58 65 ff 0d\n4d 27 90 7e 0f 85 fd fe ff ff e8 ea 53 8d ff e9 f3 fe ff ff <0f> 0b 01\nd2 44 89 d1 29 d1 ba 00 00 00 00 0f 48 ca e9 28 ff ff ff\nRSP: 0018:ffffc900002b0d08 EFLAGS: 00010297\nRAX: 0000000000000000 RBX: ffff888102398c80 RCX: 0000000080190009\nRDX: 0000000000000000 RSI: 000000000000006a RDI: 0000000000000000\nRBP: ffff888102398c00 R08: 0000000000000000 R09: 0000000000000000\nR10: 00000000000000ca R11: 0000000000015681 R12: 0000000000000001\nR13: ffffc900002b0d68 R14: ffff88811115e000 R15: ffff8881107aca40\nFS: 00007f41ded69500(0000) GS:ffff888667dc0000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000556ccc2dc1a0 CR3: 0000000104fd8003 CR4: 0000000000772ef0\nPKRU: 55555554\nCall Trace:\n \n ? die+0x32/0x80\n ? do_trap+0xd9/0x100\n ? dql_completed+0x26b/0x290\n ? dql_completed+0x26b/0x290\n ? do_error_trap+0x6d/0xb0\n ? dql_completed+0x26b/0x290\n ? exc_invalid_op+0x4c/0x60\n ? dql_completed+0x26b/0x290\n ? asm_exc_invalid_op+0x16/0x20\n ? dql_completed+0x26b/0x290\n __free_old_xmit+0xff/0x170 [virtio_net]\n free_old_xmit+0x54/0xc0 [virtio_net]\n virtnet_poll+0xf4/0xe30 [virtio_net]\n ? __update_load_avg_cfs_rq+0x264/0x2d0\n ? update_curr+0x35/0x260\n ? reweight_entity+0x1be/0x260\n __napi_poll.constprop.0+0x28/0x1c0\n net_rx_action+0x329/0x420\n ? enqueue_hrtimer+0x35/0x90\n ? trace_hardirqs_on+0x1d/0x80\n ? kvm_sched_clock_read+0xd/0x20\n ? sched_clock+0xc/0x30\n ? kvm_sched_clock_read+0xd/0x20\n ? sched_clock+0xc/0x30\n ? sched_clock_cpu+0xd/0x1a0\n handle_softirqs+0x138/0x3e0\n do_softirq.part.0+0x89/0xc0\n \n \n __local_bh_enable_ip+0xa7/0xb0\n virtnet_open+0xc8/0x310 [virtio_net]\n __dev_open+0xfa/0x1b0\n __dev_change_flags+0x1de/0x250\n dev_change_flags+0x22/0x60\n do_setlink.isra.0+0x2df/0x10b0\n ? rtnetlink_rcv_msg+0x34f/0x3f0\n ? netlink_rcv_skb+0x54/0x100\n ? netlink_unicas\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-672"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:27Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-58c3-gqj2-fvq8/GHSA-58c3-gqj2-fvq8.json b/advisories/unreviewed/2024/12/GHSA-58c3-gqj2-fvq8/GHSA-58c3-gqj2-fvq8.json
index 56a55b3d7ac..b2707cc51ca 100644
--- a/advisories/unreviewed/2024/12/GHSA-58c3-gqj2-fvq8/GHSA-58c3-gqj2-fvq8.json
+++ b/advisories/unreviewed/2024/12/GHSA-58c3-gqj2-fvq8/GHSA-58c3-gqj2-fvq8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58c3-gqj2-fvq8",
- "modified": "2024-12-27T15:31:56Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2024-12-27T15:31:56Z",
"aliases": [
"CVE-2024-56673"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: mm: Do not call pmd dtor on vmemmap page table teardown\n\nThe vmemmap's, which is used for RV64 with SPARSEMEM_VMEMMAP, page\ntables are populated using pmd (page middle directory) hugetables.\nHowever, the pmd allocation is not using the generic mechanism used by\nthe VMA code (e.g. pmd_alloc()), or the RISC-V specific\ncreate_pgd_mapping()/alloc_pmd_late(). Instead, the vmemmap page table\ncode allocates a page, and calls vmemmap_set_pmd(). This results in\nthat the pmd ctor is *not* called, nor would it make sense to do so.\n\nNow, when tearing down a vmemmap page table pmd, the cleanup code\nwould unconditionally, and incorrectly call the pmd dtor, which\nresults in a crash (best case).\n\nThis issue was found when running the HMM selftests:\n\n | tools/testing/selftests/mm# ./test_hmm.sh smoke\n | ... # when unloading the test_hmm.ko module\n | page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10915b\n | flags: 0x1000000000000000(node=0|zone=1)\n | raw: 1000000000000000 0000000000000000 dead000000000122 0000000000000000\n | raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000\n | page dumped because: VM_BUG_ON_PAGE(ptdesc->pmd_huge_pte)\n | ------------[ cut here ]------------\n | kernel BUG at include/linux/mm.h:3080!\n | Kernel BUG [#1]\n | Modules linked in: test_hmm(-) sch_fq_codel fuse drm drm_panel_orientation_quirks backlight dm_mod\n | CPU: 1 UID: 0 PID: 514 Comm: modprobe Tainted: G W 6.12.0-00982-gf2a4f1682d07 #2\n | Tainted: [W]=WARN\n | Hardware name: riscv-virtio qemu/qemu, BIOS 2024.10 10/01/2024\n | epc : remove_pgd_mapping+0xbec/0x1070\n | ra : remove_pgd_mapping+0xbec/0x1070\n | epc : ffffffff80010a68 ra : ffffffff80010a68 sp : ff20000000a73940\n | gp : ffffffff827b2d88 tp : ff6000008785da40 t0 : ffffffff80fbce04\n | t1 : 0720072007200720 t2 : 706d756420656761 s0 : ff20000000a73a50\n | s1 : ff6000008915cff8 a0 : 0000000000000039 a1 : 0000000000000008\n | a2 : ff600003fff0de20 a3 : 0000000000000000 a4 : 0000000000000000\n | a5 : 0000000000000000 a6 : c0000000ffffefff a7 : ffffffff824469b8\n | s2 : ff1c0000022456c0 s3 : ff1ffffffdbfffff s4 : ff6000008915c000\n | s5 : ff6000008915c000 s6 : ff6000008915c000 s7 : ff1ffffffdc00000\n | s8 : 0000000000000001 s9 : ff1ffffffdc00000 s10: ffffffff819a31f0\n | s11: ffffffffffffffff t3 : ffffffff8000c950 t4 : ff60000080244f00\n | t5 : ff60000080244000 t6 : ff20000000a73708\n | status: 0000000200000120 badaddr: ffffffff80010a68 cause: 0000000000000003\n | [] remove_pgd_mapping+0xbec/0x1070\n | [] vmemmap_free+0x14/0x1e\n | [] section_deactivate+0x220/0x452\n | [] sparse_remove_section+0x4a/0x58\n | [] __remove_pages+0x7e/0xba\n | [] memunmap_pages+0x2bc/0x3fe\n | [] dmirror_device_remove_chunks+0x2ea/0x518 [test_hmm]\n | [] hmm_dmirror_exit+0x3e/0x1018 [test_hmm]\n | [] __riscv_sys_delete_module+0x15a/0x2a6\n | [] do_trap_ecall_u+0x1f2/0x266\n | [] _new_vmalloc_restore_context_a0+0xc6/0xd2\n | Code: bf51 7597 0184 8593 76a5 854a 4097 0029 80e7 2c00 (9002) 7597\n | ---[ end trace 0000000000000000 ]---\n | Kernel panic - not syncing: Fatal exception in interrupt\n\nAdd a check to avoid calling the pmd dtor, if the calling context is\nvmemmap_free().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:27Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6895-2frg-pq5j/GHSA-6895-2frg-pq5j.json b/advisories/unreviewed/2024/12/GHSA-6895-2frg-pq5j/GHSA-6895-2frg-pq5j.json
index 96eff00d581..f412fcaa1da 100644
--- a/advisories/unreviewed/2024/12/GHSA-6895-2frg-pq5j/GHSA-6895-2frg-pq5j.json
+++ b/advisories/unreviewed/2024/12/GHSA-6895-2frg-pq5j/GHSA-6895-2frg-pq5j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6895-2frg-pq5j",
- "modified": "2024-12-19T00:37:35Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2024-12-19T00:37:35Z",
"aliases": [
"CVE-2024-12695"
],
"details": "Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-18T22:15:06Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6chf-57fp-7vxm/GHSA-6chf-57fp-7vxm.json b/advisories/unreviewed/2024/12/GHSA-6chf-57fp-7vxm/GHSA-6chf-57fp-7vxm.json
index e63e806052c..5b5adae2068 100644
--- a/advisories/unreviewed/2024/12/GHSA-6chf-57fp-7vxm/GHSA-6chf-57fp-7vxm.json
+++ b/advisories/unreviewed/2024/12/GHSA-6chf-57fp-7vxm/GHSA-6chf-57fp-7vxm.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json b/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json
index 2d99ecd131d..2e53a067b21 100644
--- a/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json
+++ b/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-281"
+ "CWE-281",
+ "CWE-59"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json b/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json
index 222f619000f..91bd7ddedcd 100644
--- a/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json
+++ b/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json b/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json
index 3fec81eee80..7a3b9074a4a 100644
--- a/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json
+++ b/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m84q-p89f-6cc5",
- "modified": "2024-12-19T00:37:35Z",
+ "modified": "2025-01-06T15:30:58Z",
"published": "2024-12-19T00:37:35Z",
"aliases": [
"CVE-2024-12693"
],
"details": "Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-18T22:15:06Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-ppp3-73jm-5rm6/GHSA-ppp3-73jm-5rm6.json b/advisories/unreviewed/2024/12/GHSA-ppp3-73jm-5rm6/GHSA-ppp3-73jm-5rm6.json
index 8d13767bc36..f41e6a59e2b 100644
--- a/advisories/unreviewed/2024/12/GHSA-ppp3-73jm-5rm6/GHSA-ppp3-73jm-5rm6.json
+++ b/advisories/unreviewed/2024/12/GHSA-ppp3-73jm-5rm6/GHSA-ppp3-73jm-5rm6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppp3-73jm-5rm6",
- "modified": "2024-12-27T15:31:56Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2024-12-27T15:31:56Z",
"aliases": [
"CVE-2024-56675"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors\n\nUprobes always use bpf_prog_run_array_uprobe() under tasks-trace-RCU\nprotection. But it is possible to attach a non-sleepable BPF program to a\nuprobe, and non-sleepable BPF programs are freed via normal RCU (see\n__bpf_prog_put_noref()). This leads to UAF of the bpf_prog because a normal\nRCU grace period does not imply a tasks-trace-RCU grace period.\n\nFix it by explicitly waiting for a tasks-trace-RCU grace period after\nremoving the attachment of a bpf_prog to a perf_event.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:27Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json b/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json
index ba075f8e6ba..54c48f79872 100644
--- a/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json
+++ b/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json b/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json
index 04f30927f23..04881894b07 100644
--- a/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json
+++ b/advisories/unreviewed/2025/01/GHSA-24m8-vx7p-q7mf/GHSA-24m8-vx7p-q7mf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24m8-vx7p-q7mf",
- "modified": "2025-01-06T06:30:46Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-12302"
],
"details": "The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T06:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-2h9f-xm25-q379/GHSA-2h9f-xm25-q379.json b/advisories/unreviewed/2025/01/GHSA-2h9f-xm25-q379/GHSA-2h9f-xm25-q379.json
index 2dc4267f5be..197039a8f95 100644
--- a/advisories/unreviewed/2025/01/GHSA-2h9f-xm25-q379/GHSA-2h9f-xm25-q379.json
+++ b/advisories/unreviewed/2025/01/GHSA-2h9f-xm25-q379/GHSA-2h9f-xm25-q379.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2h9f-xm25-q379",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20153"
],
"details": "In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-304"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-52qc-q82v-p8hj/GHSA-52qc-q82v-p8hj.json b/advisories/unreviewed/2025/01/GHSA-52qc-q82v-p8hj/GHSA-52qc-q82v-p8hj.json
index 0c8037f1215..9b31b84d5c6 100644
--- a/advisories/unreviewed/2025/01/GHSA-52qc-q82v-p8hj/GHSA-52qc-q82v-p8hj.json
+++ b/advisories/unreviewed/2025/01/GHSA-52qc-q82v-p8hj/GHSA-52qc-q82v-p8hj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52qc-q82v-p8hj",
- "modified": "2025-01-04T03:33:08Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-04T03:33:08Z",
"aliases": [
"CVE-2025-22388"
],
"details": "An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-04T02:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-5669-3g9q-8x32/GHSA-5669-3g9q-8x32.json b/advisories/unreviewed/2025/01/GHSA-5669-3g9q-8x32/GHSA-5669-3g9q-8x32.json
index fb39f5f0d6f..45e7dab14c5 100644
--- a/advisories/unreviewed/2025/01/GHSA-5669-3g9q-8x32/GHSA-5669-3g9q-8x32.json
+++ b/advisories/unreviewed/2025/01/GHSA-5669-3g9q-8x32/GHSA-5669-3g9q-8x32.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5669-3g9q-8x32",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20105"
],
"details": "In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09062027; Issue ID: MSV-1743.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-6752-2m67-2m5v/GHSA-6752-2m67-2m5v.json b/advisories/unreviewed/2025/01/GHSA-6752-2m67-2m5v/GHSA-6752-2m67-2m5v.json
index 7ab483a6840..026057131a6 100644
--- a/advisories/unreviewed/2025/01/GHSA-6752-2m67-2m5v/GHSA-6752-2m67-2m5v.json
+++ b/advisories/unreviewed/2025/01/GHSA-6752-2m67-2m5v/GHSA-6752-2m67-2m5v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6752-2m67-2m5v",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20151"
],
"details": "In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01399339; Issue ID: MSV-1928.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-7545-6w3x-8r4v/GHSA-7545-6w3x-8r4v.json b/advisories/unreviewed/2025/01/GHSA-7545-6w3x-8r4v/GHSA-7545-6w3x-8r4v.json
index 6ddc39c95b3..468567289b8 100644
--- a/advisories/unreviewed/2025/01/GHSA-7545-6w3x-8r4v/GHSA-7545-6w3x-8r4v.json
+++ b/advisories/unreviewed/2025/01/GHSA-7545-6w3x-8r4v/GHSA-7545-6w3x-8r4v.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-79xq-2cpc-pjfm/GHSA-79xq-2cpc-pjfm.json b/advisories/unreviewed/2025/01/GHSA-79xq-2cpc-pjfm/GHSA-79xq-2cpc-pjfm.json
index c876352a23e..80a0222bb22 100644
--- a/advisories/unreviewed/2025/01/GHSA-79xq-2cpc-pjfm/GHSA-79xq-2cpc-pjfm.json
+++ b/advisories/unreviewed/2025/01/GHSA-79xq-2cpc-pjfm/GHSA-79xq-2cpc-pjfm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79xq-2cpc-pjfm",
- "modified": "2025-01-04T03:33:08Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-04T03:33:08Z",
"aliases": [
"CVE-2025-22383"
],
"details": "An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us functionality. This allows visitors to send e-mail messages that could contain unfiltered HTML markup in specific scenarios.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-04T02:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-7fhf-99f5-2645/GHSA-7fhf-99f5-2645.json b/advisories/unreviewed/2025/01/GHSA-7fhf-99f5-2645/GHSA-7fhf-99f5-2645.json
index 32852319ca1..2217d223789 100644
--- a/advisories/unreviewed/2025/01/GHSA-7fhf-99f5-2645/GHSA-7fhf-99f5-2645.json
+++ b/advisories/unreviewed/2025/01/GHSA-7fhf-99f5-2645/GHSA-7fhf-99f5-2645.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fhf-99f5-2645",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20149"
],
"details": "In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01231341 / MOLY01263331 / MOLY01233835; Issue ID: MSV-2165.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-1284"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json b/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json
index bfa6d99c40e..5ed899aa283 100644
--- a/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json
+++ b/advisories/unreviewed/2025/01/GHSA-7mxj-3f68-p2v6/GHSA-7mxj-3f68-p2v6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mxj-3f68-p2v6",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-11849"
],
"details": "The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T06:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-88jr-vqf8-xrxx/GHSA-88jr-vqf8-xrxx.json b/advisories/unreviewed/2025/01/GHSA-88jr-vqf8-xrxx/GHSA-88jr-vqf8-xrxx.json
index dc10e8a0987..cb51f6f8cbf 100644
--- a/advisories/unreviewed/2025/01/GHSA-88jr-vqf8-xrxx/GHSA-88jr-vqf8-xrxx.json
+++ b/advisories/unreviewed/2025/01/GHSA-88jr-vqf8-xrxx/GHSA-88jr-vqf8-xrxx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88jr-vqf8-xrxx",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20152"
],
"details": "In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-617"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-98mp-fxmm-38qm/GHSA-98mp-fxmm-38qm.json b/advisories/unreviewed/2025/01/GHSA-98mp-fxmm-38qm/GHSA-98mp-fxmm-38qm.json
index 7ab0da66852..3f9824e1fce 100644
--- a/advisories/unreviewed/2025/01/GHSA-98mp-fxmm-38qm/GHSA-98mp-fxmm-38qm.json
+++ b/advisories/unreviewed/2025/01/GHSA-98mp-fxmm-38qm/GHSA-98mp-fxmm-38qm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-98mp-fxmm-38qm",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20145"
],
"details": "In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json b/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json
index 98e0f8a9834..71656ef7ac4 100644
--- a/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json
+++ b/advisories/unreviewed/2025/01/GHSA-c797-jx9v-f674/GHSA-c797-jx9v-f674.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c797-jx9v-f674",
- "modified": "2025-01-06T06:30:46Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-12311"
],
"details": "The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T06:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-cqhv-985j-2frf/GHSA-cqhv-985j-2frf.json b/advisories/unreviewed/2025/01/GHSA-cqhv-985j-2frf/GHSA-cqhv-985j-2frf.json
index 11178db3a4a..201d4a8eb6a 100644
--- a/advisories/unreviewed/2025/01/GHSA-cqhv-985j-2frf/GHSA-cqhv-985j-2frf.json
+++ b/advisories/unreviewed/2025/01/GHSA-cqhv-985j-2frf/GHSA-cqhv-985j-2frf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqhv-985j-2frf",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20148"
],
"details": "In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json b/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json
new file mode 100644
index 00000000000..8a7e8836c09
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f2h8-4w6p-535w",
+ "modified": "2025-01-06T15:31:00Z",
+ "published": "2025-01-06T15:31:00Z",
+ "aliases": [
+ "CVE-2024-5594"
+ ],
+ "details": "OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5594"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-5594"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1287"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-06T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-fvq7-q423-52g3/GHSA-fvq7-q423-52g3.json b/advisories/unreviewed/2025/01/GHSA-fvq7-q423-52g3/GHSA-fvq7-q423-52g3.json
index e9b66581fff..a254b46c700 100644
--- a/advisories/unreviewed/2025/01/GHSA-fvq7-q423-52g3/GHSA-fvq7-q423-52g3.json
+++ b/advisories/unreviewed/2025/01/GHSA-fvq7-q423-52g3/GHSA-fvq7-q423-52g3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvq7-q423-52g3",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20146"
],
"details": "In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json b/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json
index f79783e2f0c..8fa77a37364 100644
--- a/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json
+++ b/advisories/unreviewed/2025/01/GHSA-hj25-chfx-qmx5/GHSA-hj25-chfx-qmx5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hj25-chfx-qmx5",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-11356"
],
"details": "The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T06:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-j8fj-42m7-7578/GHSA-j8fj-42m7-7578.json b/advisories/unreviewed/2025/01/GHSA-j8fj-42m7-7578/GHSA-j8fj-42m7-7578.json
index a034d01f109..f83e1365d15 100644
--- a/advisories/unreviewed/2025/01/GHSA-j8fj-42m7-7578/GHSA-j8fj-42m7-7578.json
+++ b/advisories/unreviewed/2025/01/GHSA-j8fj-42m7-7578/GHSA-j8fj-42m7-7578.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-p22m-5prx-9rm7/GHSA-p22m-5prx-9rm7.json b/advisories/unreviewed/2025/01/GHSA-p22m-5prx-9rm7/GHSA-p22m-5prx-9rm7.json
index f8debdbb323..a73f0b98adb 100644
--- a/advisories/unreviewed/2025/01/GHSA-p22m-5prx-9rm7/GHSA-p22m-5prx-9rm7.json
+++ b/advisories/unreviewed/2025/01/GHSA-p22m-5prx-9rm7/GHSA-p22m-5prx-9rm7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p22m-5prx-9rm7",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20150"
],
"details": "In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01412526; Issue ID: MSV-2018.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-502"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-pch9-mchm-3m6c/GHSA-pch9-mchm-3m6c.json b/advisories/unreviewed/2025/01/GHSA-pch9-mchm-3m6c/GHSA-pch9-mchm-3m6c.json
index bb8cc47ddcc..5a3d58f8c1a 100644
--- a/advisories/unreviewed/2025/01/GHSA-pch9-mchm-3m6c/GHSA-pch9-mchm-3m6c.json
+++ b/advisories/unreviewed/2025/01/GHSA-pch9-mchm-3m6c/GHSA-pch9-mchm-3m6c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pch9-mchm-3m6c",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20143"
],
"details": "In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-pvvw-qrf9-xpmc/GHSA-pvvw-qrf9-xpmc.json b/advisories/unreviewed/2025/01/GHSA-pvvw-qrf9-xpmc/GHSA-pvvw-qrf9-xpmc.json
index 5f1bcf1d519..5a7a9784ecc 100644
--- a/advisories/unreviewed/2025/01/GHSA-pvvw-qrf9-xpmc/GHSA-pvvw-qrf9-xpmc.json
+++ b/advisories/unreviewed/2025/01/GHSA-pvvw-qrf9-xpmc/GHSA-pvvw-qrf9-xpmc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvvw-qrf9-xpmc",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20140"
],
"details": "In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json b/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json
new file mode 100644
index 00000000000..ed8d2a8984c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qcg2-98h8-485j",
+ "modified": "2025-01-06T15:31:00Z",
+ "published": "2025-01-06T15:31:00Z",
+ "aliases": [
+ "CVE-2024-8474"
+ ],
+ "details": "OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8474"
+ },
+ {
+ "type": "WEB",
+ "url": "https://openvpn.net/connect-docs/android-release-notes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-212"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-06T15:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-vvc3-x74m-rg8v/GHSA-vvc3-x74m-rg8v.json b/advisories/unreviewed/2025/01/GHSA-vvc3-x74m-rg8v/GHSA-vvc3-x74m-rg8v.json
index 7dacaf4a4b8..e51f6a87c7a 100644
--- a/advisories/unreviewed/2025/01/GHSA-vvc3-x74m-rg8v/GHSA-vvc3-x74m-rg8v.json
+++ b/advisories/unreviewed/2025/01/GHSA-vvc3-x74m-rg8v/GHSA-vvc3-x74m-rg8v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvc3-x74m-rg8v",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20154"
],
"details": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-121"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-w82h-8c9g-f268/GHSA-w82h-8c9g-f268.json b/advisories/unreviewed/2025/01/GHSA-w82h-8c9g-f268/GHSA-w82h-8c9g-f268.json
index 13818d68dca..22a9d23e6a5 100644
--- a/advisories/unreviewed/2025/01/GHSA-w82h-8c9g-f268/GHSA-w82h-8c9g-f268.json
+++ b/advisories/unreviewed/2025/01/GHSA-w82h-8c9g-f268/GHSA-w82h-8c9g-f268.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w82h-8c9g-f268",
- "modified": "2025-01-06T06:30:45Z",
+ "modified": "2025-01-06T15:30:59Z",
"published": "2025-01-06T06:30:45Z",
"aliases": [
"CVE-2024-20144"
],
"details": "In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T04:15:06Z"