From cc6c42ee49f6208ec211cb4912b37ce0e046d4bf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 4 Mar 2025 21:32:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-56w7-9rqr-p4fc.json | 17 ++++- .../GHSA-5rw8-mcp9-pvpg.json | 10 ++- .../GHSA-rh9f-46xr-5c59.json | 14 ++++- .../GHSA-x476-7xh5-hq84.json | 14 ++++- .../GHSA-vm9v-45vg-q73f.json | 2 +- .../GHSA-wq34-qch7-hr2g.json | 4 +- .../GHSA-3vx4-pj97-vxc3.json | 3 +- .../GHSA-8h38-qx4m-2f5r.json | 1 + .../GHSA-6pc8-5263-hvgq.json | 15 +++-- .../GHSA-7xmw-644w-wp3m.json | 15 +++-- .../GHSA-f9rw-96g7-cwhw.json | 11 +++- .../GHSA-px94-7h5c-q5wh.json | 15 +++-- .../GHSA-2hvj-p59v-p559.json | 2 +- .../GHSA-2r4h-4cvr-v48c.json | 62 +++++++++++++++++++ .../GHSA-46f9-rmg7-hh9m.json | 29 +++++++++ .../GHSA-5fqj-hrv8-fhp4.json | 29 +++++++++ .../GHSA-5j8p-9vxc-hp7x.json | 36 +++++++++++ .../GHSA-6jf7-p33c-7gw9.json | 52 ++++++++++++++++ .../GHSA-7729-f2m7-vm5h.json | 52 ++++++++++++++++ .../GHSA-7vrc-3785-x4qx.json | 36 +++++++++++ .../GHSA-7w6g-vq95-c259.json | 52 ++++++++++++++++ .../GHSA-8383-r4v6-fx3q.json | 2 +- .../GHSA-8fjr-734h-7jj5.json | 36 +++++++++++ .../GHSA-cchf-xm65-f24c.json | 6 +- .../GHSA-f8xf-r8j3-6845.json | 15 +++-- .../GHSA-fc4v-676g-hqh4.json | 36 +++++++++++ .../GHSA-gcgr-r4x5-w79r.json | 36 +++++++++++ .../GHSA-gvcc-8cx2-3fp2.json | 56 +++++++++++++++++ .../GHSA-h2m9-38g2-xrh9.json | 36 +++++++++++ .../GHSA-h7wv-22h8-mr42.json | 36 +++++++++++ .../GHSA-h974-ghc6-x4xx.json | 37 +++++++++++ .../GHSA-jpcf-pv77-3mfc.json | 36 +++++++++++ .../GHSA-jv4f-v7gg-5mvh.json | 36 +++++++++++ .../GHSA-jxrw-5fgg-2485.json | 29 +++++++++ .../GHSA-mj8j-vjh6-hv23.json | 56 +++++++++++++++++ .../GHSA-mx2h-mfjv-7hjv.json | 4 +- .../GHSA-pf27-23g4-7wjj.json | 29 +++++++++ .../GHSA-pw35-2fx2-h8q7.json | 4 +- .../GHSA-qphr-fcm6-q558.json | 36 +++++++++++ .../GHSA-r55c-q3r9-vpfj.json | 4 +- .../GHSA-wf49-mp4g-xcg4.json | 36 +++++++++++ .../GHSA-wqvf-m58c-h7rw.json | 36 +++++++++++ .../GHSA-xg3r-8fjr-q2w2.json | 56 +++++++++++++++++ 43 files changed, 1095 insertions(+), 34 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2r4h-4cvr-v48c/GHSA-2r4h-4cvr-v48c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5fqj-hrv8-fhp4/GHSA-5fqj-hrv8-fhp4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5j8p-9vxc-hp7x/GHSA-5j8p-9vxc-hp7x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6jf7-p33c-7gw9/GHSA-6jf7-p33c-7gw9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7729-f2m7-vm5h/GHSA-7729-f2m7-vm5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7vrc-3785-x4qx/GHSA-7vrc-3785-x4qx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7w6g-vq95-c259/GHSA-7w6g-vq95-c259.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8fjr-734h-7jj5/GHSA-8fjr-734h-7jj5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fc4v-676g-hqh4/GHSA-fc4v-676g-hqh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gcgr-r4x5-w79r/GHSA-gcgr-r4x5-w79r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gvcc-8cx2-3fp2/GHSA-gvcc-8cx2-3fp2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h2m9-38g2-xrh9/GHSA-h2m9-38g2-xrh9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h7wv-22h8-mr42/GHSA-h7wv-22h8-mr42.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h974-ghc6-x4xx/GHSA-h974-ghc6-x4xx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jpcf-pv77-3mfc/GHSA-jpcf-pv77-3mfc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jv4f-v7gg-5mvh/GHSA-jv4f-v7gg-5mvh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mj8j-vjh6-hv23/GHSA-mj8j-vjh6-hv23.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pf27-23g4-7wjj/GHSA-pf27-23g4-7wjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qphr-fcm6-q558/GHSA-qphr-fcm6-q558.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wf49-mp4g-xcg4/GHSA-wf49-mp4g-xcg4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wqvf-m58c-h7rw/GHSA-wqvf-m58c-h7rw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xg3r-8fjr-q2w2/GHSA-xg3r-8fjr-q2w2.json diff --git a/advisories/unreviewed/2022/05/GHSA-56w7-9rqr-p4fc/GHSA-56w7-9rqr-p4fc.json b/advisories/unreviewed/2022/05/GHSA-56w7-9rqr-p4fc/GHSA-56w7-9rqr-p4fc.json index a8c377576fd..a738a600720 100644 --- a/advisories/unreviewed/2022/05/GHSA-56w7-9rqr-p4fc/GHSA-56w7-9rqr-p4fc.json +++ b/advisories/unreviewed/2022/05/GHSA-56w7-9rqr-p4fc/GHSA-56w7-9rqr-p4fc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56w7-9rqr-p4fc", - "modified": "2022-05-24T16:49:49Z", + "modified": "2025-03-04T21:30:51Z", "published": "2022-05-24T16:49:49Z", "aliases": [ "CVE-2019-13454" ], "details": "ImageMagick 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -26,6 +31,10 @@ "type": "WEB", "url": "https://github.com/ImageMagick/ImageMagick6/commit/4f31d78716ac94c85c244efcea368fea202e2ed4" }, + { + "type": "WEB", + "url": "https://github.com/ImageMagick/ImageMagick/blob/7.0.1-0/MagickCore/layer.c#L1618" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00030.html" @@ -48,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-369" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rw8-mcp9-pvpg/GHSA-5rw8-mcp9-pvpg.json b/advisories/unreviewed/2022/05/GHSA-5rw8-mcp9-pvpg/GHSA-5rw8-mcp9-pvpg.json index b6be5aae2e3..6664f706342 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rw8-mcp9-pvpg/GHSA-5rw8-mcp9-pvpg.json +++ b/advisories/unreviewed/2022/05/GHSA-5rw8-mcp9-pvpg/GHSA-5rw8-mcp9-pvpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rw8-mcp9-pvpg", - "modified": "2022-06-30T00:00:30Z", + "modified": "2025-03-04T21:30:52Z", "published": "2022-05-24T17:25:33Z", "aliases": [ "CVE-2020-16304" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=701816" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/base/gxicolor.c?h=ghostscript-9.18#n825" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00032.html" @@ -39,6 +43,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2020/dsa-4748" }, + { + "type": "WEB", + "url": "http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=027c546e0dd11e0526f1780a7f3c2c66acffe209" + }, { "type": "WEB", "url": "http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=027c546e0dd11e0526f1780a7f3c2c66acffe209" diff --git a/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json b/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json index 2b45002226c..99832f26c30 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json +++ b/advisories/unreviewed/2022/05/GHSA-rh9f-46xr-5c59/GHSA-rh9f-46xr-5c59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh9f-46xr-5c59", - "modified": "2022-08-25T00:00:26Z", + "modified": "2025-03-04T21:30:51Z", "published": "2022-05-24T17:25:32Z", "aliases": [ "CVE-2020-16291" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=701787" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=4f73e8b4d578e69a17f452fa60d2130c5faaefd6" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/gdevdj9.c?h=ghostpdl-9.18#n824" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00032.html" @@ -39,6 +47,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2020/dsa-4748" }, + { + "type": "WEB", + "url": "http://git.ghostscript.com/?p=ghostpdl.git%3Bh=4f73e8b4d578e69a17f452fa60d2130c5faaefd6" + }, { "type": "WEB", "url": "http://git.ghostscript.com/?p=ghostpdl.git;h=4f73e8b4d578e69a17f452fa60d2130c5faaefd6" diff --git a/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json b/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json index d2b6a02b72b..4aa7c6f90cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json +++ b/advisories/unreviewed/2022/05/GHSA-x476-7xh5-hq84/GHSA-x476-7xh5-hq84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x476-7xh5-hq84", - "modified": "2022-08-25T00:00:26Z", + "modified": "2025-03-04T21:30:52Z", "published": "2022-05-24T17:25:32Z", "aliases": [ "CVE-2020-16297" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=701800" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/gdevbjca.c?h=ghostpdl-9.18#n659" + }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39" + }, { "type": "WEB", "url": "https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=bf72f1a3dd5392ee8291e3b1518a0c2c5dc6ba39" diff --git a/advisories/unreviewed/2023/03/GHSA-vm9v-45vg-q73f/GHSA-vm9v-45vg-q73f.json b/advisories/unreviewed/2023/03/GHSA-vm9v-45vg-q73f/GHSA-vm9v-45vg-q73f.json index 3e4084f27a6..54c49ce0655 100644 --- a/advisories/unreviewed/2023/03/GHSA-vm9v-45vg-q73f/GHSA-vm9v-45vg-q73f.json +++ b/advisories/unreviewed/2023/03/GHSA-vm9v-45vg-q73f/GHSA-vm9v-45vg-q73f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vm9v-45vg-q73f", - "modified": "2023-03-14T21:30:20Z", + "modified": "2025-03-04T21:30:52Z", "published": "2023-03-08T21:30:23Z", "aliases": [ "CVE-2023-22892" diff --git a/advisories/unreviewed/2023/03/GHSA-wq34-qch7-hr2g/GHSA-wq34-qch7-hr2g.json b/advisories/unreviewed/2023/03/GHSA-wq34-qch7-hr2g/GHSA-wq34-qch7-hr2g.json index 7c9bea875eb..96e5de57172 100644 --- a/advisories/unreviewed/2023/03/GHSA-wq34-qch7-hr2g/GHSA-wq34-qch7-hr2g.json +++ b/advisories/unreviewed/2023/03/GHSA-wq34-qch7-hr2g/GHSA-wq34-qch7-hr2g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-749" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3vx4-pj97-vxc3/GHSA-3vx4-pj97-vxc3.json b/advisories/unreviewed/2025/01/GHSA-3vx4-pj97-vxc3/GHSA-3vx4-pj97-vxc3.json index 5954827b93f..2c765bdec9c 100644 --- a/advisories/unreviewed/2025/01/GHSA-3vx4-pj97-vxc3/GHSA-3vx4-pj97-vxc3.json +++ b/advisories/unreviewed/2025/01/GHSA-3vx4-pj97-vxc3/GHSA-3vx4-pj97-vxc3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json b/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json index 283ec8f3b4f..bc531726b21 100644 --- a/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json +++ b/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json b/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json index 98006197d64..1135949d85f 100644 --- a/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json +++ b/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pc8-5263-hvgq", - "modified": "2025-02-27T00:30:27Z", + "modified": "2025-03-04T21:30:54Z", "published": "2025-02-27T00:30:26Z", "aliases": [ "CVE-2024-55581" ], "details": "When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-26T22:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json b/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json index 556ac2b734f..3bbeaa422a3 100644 --- a/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json +++ b/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xmw-644w-wp3m", - "modified": "2025-02-27T00:30:27Z", + "modified": "2025-03-04T21:30:54Z", "published": "2025-02-27T00:30:27Z", "aliases": [ "CVE-2024-53573" ], "details": "Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-26T22:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json b/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json index 254cb35f4eb..7d435c32a8d 100644 --- a/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json +++ b/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9rw-96g7-cwhw", - "modified": "2025-02-11T18:31:43Z", + "modified": "2025-03-04T21:30:53Z", "published": "2025-02-11T18:31:43Z", "aliases": [ "CVE-2025-26495" ], "details": "Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T18:15:47Z" diff --git a/advisories/unreviewed/2025/02/GHSA-px94-7h5c-q5wh/GHSA-px94-7h5c-q5wh.json b/advisories/unreviewed/2025/02/GHSA-px94-7h5c-q5wh/GHSA-px94-7h5c-q5wh.json index 1103a38490e..202aeeffd7e 100644 --- a/advisories/unreviewed/2025/02/GHSA-px94-7h5c-q5wh/GHSA-px94-7h5c-q5wh.json +++ b/advisories/unreviewed/2025/02/GHSA-px94-7h5c-q5wh/GHSA-px94-7h5c-q5wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px94-7h5c-q5wh", - "modified": "2025-02-26T21:30:32Z", + "modified": "2025-03-04T21:30:54Z", "published": "2025-02-26T21:30:32Z", "aliases": [ "CVE-2024-57423" ], "details": "A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-26T21:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2hvj-p59v-p559/GHSA-2hvj-p59v-p559.json b/advisories/unreviewed/2025/03/GHSA-2hvj-p59v-p559/GHSA-2hvj-p59v-p559.json index 869ad26fef1..3b7428bc647 100644 --- a/advisories/unreviewed/2025/03/GHSA-2hvj-p59v-p559/GHSA-2hvj-p59v-p559.json +++ b/advisories/unreviewed/2025/03/GHSA-2hvj-p59v-p559/GHSA-2hvj-p59v-p559.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hvj-p59v-p559", - "modified": "2025-03-04T09:30:40Z", + "modified": "2025-03-04T21:30:55Z", "published": "2025-03-04T09:30:40Z", "aliases": [ "CVE-2025-0433" diff --git a/advisories/unreviewed/2025/03/GHSA-2r4h-4cvr-v48c/GHSA-2r4h-4cvr-v48c.json b/advisories/unreviewed/2025/03/GHSA-2r4h-4cvr-v48c/GHSA-2r4h-4cvr-v48c.json new file mode 100644 index 00000000000..b5642e77364 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2r4h-4cvr-v48c/GHSA-2r4h-4cvr-v48c.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r4h-4cvr-v48c", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2025-1953" + ], + "details": "A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.3.0 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1953" + }, + { + "type": "WEB", + "url": "https://github.com/vllm-project/aibrix/issues/749" + }, + { + "type": "WEB", + "url": "https://github.com/vllm-project/aibrix/issues/749#event-16488517974" + }, + { + "type": "WEB", + "url": "https://github.com/vllm-project/aibrix/pull/752" + }, + { + "type": "WEB", + "url": "https://github.com/vllm-project/aibrix/pull/752/commits/3d25d95aebd66f24a549200edcebc5ea423b317a" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298543" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298543" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.509958" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json b/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json new file mode 100644 index 00000000000..889d61e2060 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46f9-rmg7-hh9m", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2020-23438" + ], + "details": "Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23438" + }, + { + "type": "WEB", + "url": "https://cvewalkthrough.com/cve-2020-23438-wondershare-filmora-9-2-11-trojan-dll-hijacking-leading-to-privilege-escalation" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fqj-hrv8-fhp4/GHSA-5fqj-hrv8-fhp4.json b/advisories/unreviewed/2025/03/GHSA-5fqj-hrv8-fhp4/GHSA-5fqj-hrv8-fhp4.json new file mode 100644 index 00000000000..ce82695c1fb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fqj-hrv8-fhp4/GHSA-5fqj-hrv8-fhp4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fqj-hrv8-fhp4", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2025-26136" + ], + "details": "A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26136" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xiadmin6/6d664692d31a04eb59096a488b9f3712" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5j8p-9vxc-hp7x/GHSA-5j8p-9vxc-hp7x.json b/advisories/unreviewed/2025/03/GHSA-5j8p-9vxc-hp7x/GHSA-5j8p-9vxc-hp7x.json new file mode 100644 index 00000000000..e45246972a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5j8p-9vxc-hp7x/GHSA-5j8p-9vxc-hp7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8p-9vxc-hp7x", + "modified": "2025-03-04T21:30:56Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2020-3122" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3122" + }, + { + "type": "WEB", + "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr92383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6jf7-p33c-7gw9/GHSA-6jf7-p33c-7gw9.json b/advisories/unreviewed/2025/03/GHSA-6jf7-p33c-7gw9/GHSA-6jf7-p33c-7gw9.json new file mode 100644 index 00000000000..5038633d2db --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6jf7-p33c-7gw9/GHSA-6jf7-p33c-7gw9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jf7-p33c-7gw9", + "modified": "2025-03-04T21:30:56Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2025-1947" + ], + "details": "A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1947" + }, + { + "type": "WEB", + "url": "https://github.com/heiheixz/report/blob/main/nxb_2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298521" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298521" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.506659" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7729-f2m7-vm5h/GHSA-7729-f2m7-vm5h.json b/advisories/unreviewed/2025/03/GHSA-7729-f2m7-vm5h/GHSA-7729-f2m7-vm5h.json new file mode 100644 index 00000000000..2050173222c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7729-f2m7-vm5h/GHSA-7729-f2m7-vm5h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7729-f2m7-vm5h", + "modified": "2025-03-04T21:30:56Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2025-1946" + ], + "details": "A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF. The manipulation of the argument id leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1946" + }, + { + "type": "WEB", + "url": "https://github.com/heiheixz/report/blob/main/nxb_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298520" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298520" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.506657" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7vrc-3785-x4qx/GHSA-7vrc-3785-x4qx.json b/advisories/unreviewed/2025/03/GHSA-7vrc-3785-x4qx/GHSA-7vrc-3785-x4qx.json new file mode 100644 index 00000000000..cd0cb036737 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7vrc-3785-x4qx/GHSA-7vrc-3785-x4qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vrc-3785-x4qx", + "modified": "2025-03-04T21:30:56Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2019-1815" + ], + "details": "A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the files holding debugging and maintenance information, and is only exploitable when the local status page is enabled on the device. An attacker exploiting this vulnerability may obtain access to wireless pre-shared keys, Site-to-Site VPN key and other sensitive information. Under certain circumstances, this information may allow an attacker to obtain administrative-level access to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-1815" + }, + { + "type": "WEB", + "url": "https://documentation.meraki.com/General_Administration/Privacy_and_Security/Cisco_Meraki_MX67_and_MX68_Sensitive_Information_Disclosure_Vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7w6g-vq95-c259/GHSA-7w6g-vq95-c259.json b/advisories/unreviewed/2025/03/GHSA-7w6g-vq95-c259/GHSA-7w6g-vq95-c259.json new file mode 100644 index 00000000000..a70aecaa8dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7w6g-vq95-c259/GHSA-7w6g-vq95-c259.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w6g-vq95-c259", + "modified": "2025-03-04T21:30:56Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2025-1949" + ], + "details": "A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1949" + }, + { + "type": "WEB", + "url": "https://github.com/Sinon2003/cve/blob/main/zzcms/xss-register_nodb.php.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298541" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298541" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.508909" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8383-r4v6-fx3q/GHSA-8383-r4v6-fx3q.json b/advisories/unreviewed/2025/03/GHSA-8383-r4v6-fx3q/GHSA-8383-r4v6-fx3q.json index cd67630f719..b5748d04561 100644 --- a/advisories/unreviewed/2025/03/GHSA-8383-r4v6-fx3q/GHSA-8383-r4v6-fx3q.json +++ b/advisories/unreviewed/2025/03/GHSA-8383-r4v6-fx3q/GHSA-8383-r4v6-fx3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8383-r4v6-fx3q", - "modified": "2025-03-04T09:30:40Z", + "modified": "2025-03-04T21:30:55Z", "published": "2025-03-04T09:30:40Z", "aliases": [ "CVE-2024-9618" diff --git a/advisories/unreviewed/2025/03/GHSA-8fjr-734h-7jj5/GHSA-8fjr-734h-7jj5.json b/advisories/unreviewed/2025/03/GHSA-8fjr-734h-7jj5/GHSA-8fjr-734h-7jj5.json new file mode 100644 index 00000000000..001af1be2d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8fjr-734h-7jj5/GHSA-8fjr-734h-7jj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fjr-734h-7jj5", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2024-8000" + ], + "details": "On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. \n\nNote: supplicants with pending captive-portal authentication during ASU would be impacted with this bug.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8000" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21086-security-advisory-0109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json b/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json index 440fb009401..b954f048be4 100644 --- a/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json +++ b/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cchf-xm65-f24c", - "modified": "2025-03-04T18:33:44Z", + "modified": "2025-03-04T21:30:55Z", "published": "2025-03-04T18:33:44Z", "aliases": [ "CVE-2024-41147" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2063" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2063" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json b/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json index b18817426d8..d3890b956ef 100644 --- a/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json +++ b/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f8xf-r8j3-6845", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-04T21:30:55Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1938" ], "details": "Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fc4v-676g-hqh4/GHSA-fc4v-676g-hqh4.json b/advisories/unreviewed/2025/03/GHSA-fc4v-676g-hqh4/GHSA-fc4v-676g-hqh4.json new file mode 100644 index 00000000000..64e4443d091 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fc4v-676g-hqh4/GHSA-fc4v-676g-hqh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc4v-676g-hqh4", + "modified": "2025-03-04T21:30:53Z", + "published": "2025-03-04T21:30:53Z", + "aliases": [ + "CVE-2024-39349" + ], + "details": "A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39349" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gcgr-r4x5-w79r/GHSA-gcgr-r4x5-w79r.json b/advisories/unreviewed/2025/03/GHSA-gcgr-r4x5-w79r/GHSA-gcgr-r4x5-w79r.json new file mode 100644 index 00000000000..0c5b87cbeb9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gcgr-r4x5-w79r/GHSA-gcgr-r4x5-w79r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcgr-r4x5-w79r", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2025-1080" + ], + "details": "LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments.\nThis issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1080" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gvcc-8cx2-3fp2/GHSA-gvcc-8cx2-3fp2.json b/advisories/unreviewed/2025/03/GHSA-gvcc-8cx2-3fp2/GHSA-gvcc-8cx2-3fp2.json new file mode 100644 index 00000000000..6f7e55b8d3f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gvcc-8cx2-3fp2/GHSA-gvcc-8cx2-3fp2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvcc-8cx2-3fp2", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2025-1954" + ], + "details": "A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1954" + }, + { + "type": "WEB", + "url": "https://github.com/sorcha-l/cve/blob/main/Human%20Metapneumovirus%20(HMPV)%20%E2%80%93%20Testing%20Management%20System%20%20SQL%20Injection%20Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298555" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298555" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2m9-38g2-xrh9/GHSA-h2m9-38g2-xrh9.json b/advisories/unreviewed/2025/03/GHSA-h2m9-38g2-xrh9/GHSA-h2m9-38g2-xrh9.json new file mode 100644 index 00000000000..4621c5a756b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h2m9-38g2-xrh9/GHSA-h2m9-38g2-xrh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2m9-38g2-xrh9", + "modified": "2025-03-04T21:30:53Z", + "published": "2025-03-04T21:30:53Z", + "aliases": [ + "CVE-2024-39352" + ], + "details": "A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39352" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h7wv-22h8-mr42/GHSA-h7wv-22h8-mr42.json b/advisories/unreviewed/2025/03/GHSA-h7wv-22h8-mr42/GHSA-h7wv-22h8-mr42.json new file mode 100644 index 00000000000..f912e00f162 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h7wv-22h8-mr42/GHSA-h7wv-22h8-mr42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7wv-22h8-mr42", + "modified": "2025-03-04T21:30:52Z", + "published": "2025-03-04T21:30:52Z", + "aliases": [ + "CVE-2023-47802" + ], + "details": "A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47802" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h974-ghc6-x4xx/GHSA-h974-ghc6-x4xx.json b/advisories/unreviewed/2025/03/GHSA-h974-ghc6-x4xx/GHSA-h974-ghc6-x4xx.json new file mode 100644 index 00000000000..be15abff568 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h974-ghc6-x4xx/GHSA-h974-ghc6-x4xx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h974-ghc6-x4xx", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2025-26202" + ], + "details": "Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the \"Click here to display\" option on the Status page", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26202" + }, + { + "type": "WEB", + "url": "https://github.com/A17-ba/CVE-2025-26202-Details" + }, + { + "type": "WEB", + "url": "http://dzs.com" + }, + { + "type": "WEB", + "url": "http://znid-gpon-2428b1-0st.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jpcf-pv77-3mfc/GHSA-jpcf-pv77-3mfc.json b/advisories/unreviewed/2025/03/GHSA-jpcf-pv77-3mfc/GHSA-jpcf-pv77-3mfc.json new file mode 100644 index 00000000000..82540d61e27 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jpcf-pv77-3mfc/GHSA-jpcf-pv77-3mfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpcf-pv77-3mfc", + "modified": "2025-03-04T21:30:53Z", + "published": "2025-03-04T21:30:53Z", + "aliases": [ + "CVE-2024-39351" + ], + "details": "A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39351" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jv4f-v7gg-5mvh/GHSA-jv4f-v7gg-5mvh.json b/advisories/unreviewed/2025/03/GHSA-jv4f-v7gg-5mvh/GHSA-jv4f-v7gg-5mvh.json new file mode 100644 index 00000000000..da5dd63210f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jv4f-v7gg-5mvh/GHSA-jv4f-v7gg-5mvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv4f-v7gg-5mvh", + "modified": "2025-03-04T21:30:53Z", + "published": "2025-03-04T21:30:53Z", + "aliases": [ + "CVE-2023-47803" + ], + "details": "A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers to read specific files containing non-sensitive information via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47803" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json b/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json new file mode 100644 index 00000000000..8be3dd2b0d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxrw-5fgg-2485", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2025-26318" + ], + "details": "Insecure permissions in TSplus Remote Access v17.30 allow attackers to retrieve a list of all domain accounts currently connected to the application.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26318" + }, + { + "type": "WEB", + "url": "https://github.com/Frozenka/CVE-2025-26318" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mj8j-vjh6-hv23/GHSA-mj8j-vjh6-hv23.json b/advisories/unreviewed/2025/03/GHSA-mj8j-vjh6-hv23/GHSA-mj8j-vjh6-hv23.json new file mode 100644 index 00000000000..59a732abde2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mj8j-vjh6-hv23/GHSA-mj8j-vjh6-hv23.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj8j-vjh6-hv23", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2025-1955" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1955" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://hexotion.notion.site/Online-Class-and-Exam-Scheduling-System-in-PHP-has-Stored-Cross-Site-Scripting-vulnerability-in-prof-1a7bb766cf32809b9f0be980e90d83f7?pvs=73" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mx2h-mfjv-7hjv/GHSA-mx2h-mfjv-7hjv.json b/advisories/unreviewed/2025/03/GHSA-mx2h-mfjv-7hjv/GHSA-mx2h-mfjv-7hjv.json index c7044583119..62bc4a3be99 100644 --- a/advisories/unreviewed/2025/03/GHSA-mx2h-mfjv-7hjv/GHSA-mx2h-mfjv-7hjv.json +++ b/advisories/unreviewed/2025/03/GHSA-mx2h-mfjv-7hjv/GHSA-mx2h-mfjv-7hjv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-pf27-23g4-7wjj/GHSA-pf27-23g4-7wjj.json b/advisories/unreviewed/2025/03/GHSA-pf27-23g4-7wjj/GHSA-pf27-23g4-7wjj.json new file mode 100644 index 00000000000..3ba24e54add --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pf27-23g4-7wjj/GHSA-pf27-23g4-7wjj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf27-23g4-7wjj", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2021-41719" + ], + "details": "Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41719" + }, + { + "type": "WEB", + "url": "https://cvewalkthrough.com/cve-2021-41719-mseb-ios-application-sensitive-information-exposure" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pw35-2fx2-h8q7/GHSA-pw35-2fx2-h8q7.json b/advisories/unreviewed/2025/03/GHSA-pw35-2fx2-h8q7/GHSA-pw35-2fx2-h8q7.json index 70ee06fd190..dbbeadb0c7b 100644 --- a/advisories/unreviewed/2025/03/GHSA-pw35-2fx2-h8q7/GHSA-pw35-2fx2-h8q7.json +++ b/advisories/unreviewed/2025/03/GHSA-pw35-2fx2-h8q7/GHSA-pw35-2fx2-h8q7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-qphr-fcm6-q558/GHSA-qphr-fcm6-q558.json b/advisories/unreviewed/2025/03/GHSA-qphr-fcm6-q558/GHSA-qphr-fcm6-q558.json new file mode 100644 index 00000000000..31c5b19b743 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qphr-fcm6-q558/GHSA-qphr-fcm6-q558.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qphr-fcm6-q558", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2025-1260" + ], + "details": "On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1260" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21098-security-advisory-0111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r55c-q3r9-vpfj/GHSA-r55c-q3r9-vpfj.json b/advisories/unreviewed/2025/03/GHSA-r55c-q3r9-vpfj/GHSA-r55c-q3r9-vpfj.json index bcfe0b7e181..ae6a3a55dfc 100644 --- a/advisories/unreviewed/2025/03/GHSA-r55c-q3r9-vpfj/GHSA-r55c-q3r9-vpfj.json +++ b/advisories/unreviewed/2025/03/GHSA-r55c-q3r9-vpfj/GHSA-r55c-q3r9-vpfj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-wf49-mp4g-xcg4/GHSA-wf49-mp4g-xcg4.json b/advisories/unreviewed/2025/03/GHSA-wf49-mp4g-xcg4/GHSA-wf49-mp4g-xcg4.json new file mode 100644 index 00000000000..4b7d07f6a72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wf49-mp4g-xcg4/GHSA-wf49-mp4g-xcg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf49-mp4g-xcg4", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:57Z", + "aliases": [ + "CVE-2025-1259" + ], + "details": "On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1259" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21098-security-advisory-0111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqvf-m58c-h7rw/GHSA-wqvf-m58c-h7rw.json b/advisories/unreviewed/2025/03/GHSA-wqvf-m58c-h7rw/GHSA-wqvf-m58c-h7rw.json new file mode 100644 index 00000000000..fdf01f6679e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqvf-m58c-h7rw/GHSA-wqvf-m58c-h7rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqvf-m58c-h7rw", + "modified": "2025-03-04T21:30:58Z", + "published": "2025-03-04T21:30:58Z", + "aliases": [ + "CVE-2024-9135" + ], + "details": "On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9135" + }, + { + "type": "WEB", + "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21092-security-advisory-0110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xg3r-8fjr-q2w2/GHSA-xg3r-8fjr-q2w2.json b/advisories/unreviewed/2025/03/GHSA-xg3r-8fjr-q2w2/GHSA-xg3r-8fjr-q2w2.json new file mode 100644 index 00000000000..74c98fb2369 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xg3r-8fjr-q2w2/GHSA-xg3r-8fjr-q2w2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg3r-8fjr-q2w2", + "modified": "2025-03-04T21:30:57Z", + "published": "2025-03-04T21:30:56Z", + "aliases": [ + "CVE-2025-1952" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. The manipulation of the argument username/mobileno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1952" + }, + { + "type": "WEB", + "url": "https://github.com/zrlianc/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298542" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298542" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.509955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T19:15:38Z" + } +} \ No newline at end of file