From d07500f5dce839cad2df516c269c379e1a0864be Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Apr 2025 15:31:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-59gm-hhq4-vxjm.json | 9 +++- .../GHSA-7v3v-r482-rmfj.json | 4 +- .../GHSA-24v8-25pr-r3r4.json | 6 ++- .../GHSA-284c-r484-8cqh.json | 2 +- .../GHSA-28j3-x77x-9653.json | 10 ++++- .../GHSA-2vgc-685m-w42v.json | 2 +- .../GHSA-2wc2-77r7-4pm8.json | 2 +- .../GHSA-3r7c-wgmw-38g7.json | 6 ++- .../GHSA-42wf-78r8-wp79.json | 2 +- .../GHSA-4765-j7w9-p387.json | 6 ++- .../GHSA-4vwj-7pm2-257c.json | 4 +- .../GHSA-5459-wr9w-wpcp.json | 2 +- .../GHSA-54r9-6x6g-2vfv.json | 1 + .../GHSA-5grf-cv3x-c266.json | 2 +- .../GHSA-5h2w-44mr-8x27.json | 10 ++++- .../GHSA-5h75-x63q-jgxv.json | 6 ++- .../GHSA-5rm5-cw6f-p927.json | 13 +++++- .../GHSA-6gpj-r895-3gxv.json | 5 ++- .../GHSA-6pf3-q3cx-w87c.json | 2 +- .../GHSA-7526-6xhc-xh2w.json | 2 +- .../GHSA-7g3f-6r3q-3qmq.json | 4 +- .../GHSA-7mxj-29p2-6g84.json | 2 +- .../GHSA-82mr-6r7c-c49h.json | 6 ++- .../GHSA-87v5-p656-xr8x.json | 2 +- .../GHSA-8hg7-fgc2-26h6.json | 10 ++++- .../GHSA-8mqx-qm24-g4fh.json | 2 +- .../GHSA-8mr2-8r3v-fj69.json | 4 +- .../GHSA-9f66-rrvp-2m2v.json | 6 ++- .../GHSA-9p3c-x5jh-9p27.json | 2 +- .../GHSA-cpj8-ppjf-3vrf.json | 2 +- .../GHSA-fv4x-hrpq-wqgp.json | 6 ++- .../GHSA-g2g2-6grg-2jm4.json | 2 +- .../GHSA-g2h7-7gvv-x89v.json | 2 +- .../GHSA-g426-wcxv-272f.json | 2 +- .../GHSA-g83w-9px8-cmhv.json | 10 ++++- .../GHSA-g867-grx9-vj64.json | 2 +- .../GHSA-gf6p-963f-gv5h.json | 6 ++- .../GHSA-gfq4-pq7x-mq8c.json | 5 ++- .../GHSA-ggr5-58mq-975v.json | 10 ++++- .../GHSA-gvhf-4hjq-39hg.json | 6 ++- .../GHSA-gvhr-fq94-q7h9.json | 3 +- .../GHSA-h295-679q-mhm8.json | 2 +- .../GHSA-h3mp-j53v-44vx.json | 3 +- .../GHSA-hp2r-mwcp-253w.json | 10 ++++- .../GHSA-j5r5-jmr3-48c5.json | 2 +- .../GHSA-jx2q-hvww-224r.json | 6 ++- .../GHSA-jx63-7q59-f3fj.json | 10 ++++- .../GHSA-m847-mpgv-7mwr.json | 2 +- .../GHSA-m9xr-mrx5-456x.json | 2 +- .../GHSA-mg2x-8rwm-j9cx.json | 2 +- .../GHSA-mg8g-v5cr-wqjx.json | 2 +- .../GHSA-p2g9-fj77-vp3r.json | 4 +- .../GHSA-p5f8-m753-hvgf.json | 2 +- .../GHSA-pc7h-fmrf-pp2j.json | 2 +- .../GHSA-pvq5-77h5-rgw5.json | 4 +- .../GHSA-pwwf-7f48-895h.json | 6 ++- .../GHSA-q4r6-2rwg-f833.json | 10 ++++- .../GHSA-qg25-r8rj-7fhp.json | 2 +- .../GHSA-qh9q-rjpp-hqc3.json | 2 +- .../GHSA-qhr9-wjgv-2r72.json | 6 ++- .../GHSA-rf5c-p2xm-2r64.json | 2 +- .../GHSA-rgfq-ffxq-x68m.json | 10 ++++- .../GHSA-rhh8-vf3p-5mx3.json | 7 ++- .../GHSA-vp6m-9qxp-4j7m.json | 10 ++++- .../GHSA-w54j-3mgp-xm9q.json | 6 ++- .../GHSA-w657-6g6r-c5p3.json | 10 ++++- .../GHSA-w696-j5x3-hhvj.json | 6 ++- .../GHSA-w7vf-mp9x-925q.json | 2 +- .../GHSA-wcx8-5vxf-rv69.json | 6 ++- .../GHSA-wfp4-223f-x5rm.json | 2 +- .../GHSA-wh4p-p8wc-5h67.json | 10 ++++- .../GHSA-wpwv-wrpr-fm7f.json | 10 ++++- .../GHSA-ww43-23jx-qcpc.json | 2 +- .../GHSA-633m-2q58-q23r.json | 4 +- .../GHSA-2g84-5882-fhcm.json | 15 +++++-- .../GHSA-4j5r-8cvm-p98h.json | 15 +++++-- .../GHSA-592q-r679-2jpc.json | 15 +++++-- .../GHSA-5rg6-fchv-4f55.json | 6 ++- .../GHSA-6gh5-4fvc-rw6c.json | 15 +++++-- .../GHSA-7m9p-x22p-v2hg.json | 11 +++-- .../GHSA-7r4r-7wg2-96vj.json | 15 +++++-- .../GHSA-9h2w-crmf-mr2p.json | 15 +++++-- .../GHSA-fx88-897w-ccgj.json | 15 +++++-- .../GHSA-g7hp-hfwm-x3rp.json | 15 +++++-- .../GHSA-gmm6-5vw5-42h2.json | 6 ++- .../GHSA-jhxv-jq7p-9qhc.json | 15 +++++-- .../GHSA-mq3c-v59w-hjf6.json | 15 +++++-- .../GHSA-p579-25jc-wxr5.json | 15 +++++-- .../GHSA-pwg3-m7h4-xjvm.json | 15 +++++-- .../GHSA-q87j-52xg-48j5.json | 10 ++++- .../GHSA-qv94-9c4f-29wh.json | 15 +++++-- .../GHSA-x768-g2cv-hv4j.json | 15 +++++-- .../GHSA-xvxr-rrxw-rfp9.json | 15 +++++-- .../GHSA-24hh-5wmw-c8j8.json | 29 ++++++++++++ .../GHSA-24vc-7q35-w5rv.json | 11 +++-- .../GHSA-3w69-j4hp-rvh4.json | 40 +++++++++++++++++ .../GHSA-4h7q-pj8m-5675.json | 37 ++++++++++++++++ .../GHSA-4p7q-hmcp-j657.json | 44 +++++++++++++++++++ .../GHSA-5xpq-mc4q-22p9.json | 33 ++++++++++++++ .../GHSA-6f46-45q7-4jx2.json | 40 +++++++++++++++++ .../GHSA-6rrc-vwrv-cwxc.json | 37 ++++++++++++++++ .../GHSA-7768-6597-437r.json | 15 +++++-- .../GHSA-78fw-w53r-pgwg.json | 37 ++++++++++++++++ .../GHSA-89c2-gvr7-7r9w.json | 40 +++++++++++++++++ .../GHSA-94cq-g9vr-5q43.json | 44 +++++++++++++++++++ .../GHSA-9gxm-gppf-g7cc.json | 40 +++++++++++++++++ .../GHSA-9m7f-jxmp-5q59.json | 3 +- .../GHSA-9qmr-4gv6-xmf3.json | 11 +++-- .../GHSA-cmcg-w67x-52f7.json | 11 +++-- .../GHSA-f6c5-v8pr-pwg7.json | 36 +++++++++++++++ .../GHSA-fchw-692r-4w73.json | 33 ++++++++++++++ .../GHSA-fv46-7jp9-m2p3.json | 33 ++++++++++++++ .../GHSA-fvpc-gqmr-784w.json | 40 +++++++++++++++++ .../GHSA-g6gh-87cw-x396.json | 37 ++++++++++++++++ .../GHSA-h26x-295r-3cj4.json | 15 +++++-- .../GHSA-h44c-2324-c88q.json | 3 +- .../GHSA-hw2v-r646-wgxr.json | 4 +- .../GHSA-jcc3-vmjf-jfhj.json | 11 +++-- .../GHSA-jhgf-xqjm-37vh.json | 40 +++++++++++++++++ .../GHSA-mpvr-j99q-8c2v.json | 29 ++++++++++++ .../GHSA-pxfj-34h8-mjfc.json | 33 ++++++++++++++ .../GHSA-q7wx-4c6m-pm7w.json | 6 ++- .../GHSA-qc9g-vf45-fwfp.json | 33 ++++++++++++++ .../GHSA-vjhj-f8wp-4w4x.json | 3 +- .../GHSA-wghf-qmx9-35pp.json | 15 +++++-- .../GHSA-wpg4-89x4-3hj9.json | 33 ++++++++++++++ 126 files changed, 1301 insertions(+), 189 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3w69-j4hp-rvh4/GHSA-3w69-j4hp-rvh4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4p7q-hmcp-j657/GHSA-4p7q-hmcp-j657.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xpq-mc4q-22p9/GHSA-5xpq-mc4q-22p9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6f46-45q7-4jx2/GHSA-6f46-45q7-4jx2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-78fw-w53r-pgwg/GHSA-78fw-w53r-pgwg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-89c2-gvr7-7r9w/GHSA-89c2-gvr7-7r9w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-94cq-g9vr-5q43/GHSA-94cq-g9vr-5q43.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9gxm-gppf-g7cc/GHSA-9gxm-gppf-g7cc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f6c5-v8pr-pwg7/GHSA-f6c5-v8pr-pwg7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fv46-7jp9-m2p3/GHSA-fv46-7jp9-m2p3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fvpc-gqmr-784w/GHSA-fvpc-gqmr-784w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g6gh-87cw-x396/GHSA-g6gh-87cw-x396.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jhgf-xqjm-37vh/GHSA-jhgf-xqjm-37vh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mpvr-j99q-8c2v/GHSA-mpvr-j99q-8c2v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pxfj-34h8-mjfc/GHSA-pxfj-34h8-mjfc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qc9g-vf45-fwfp/GHSA-qc9g-vf45-fwfp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wpg4-89x4-3hj9/GHSA-wpg4-89x4-3hj9.json diff --git a/advisories/unreviewed/2022/02/GHSA-59gm-hhq4-vxjm/GHSA-59gm-hhq4-vxjm.json b/advisories/unreviewed/2022/02/GHSA-59gm-hhq4-vxjm/GHSA-59gm-hhq4-vxjm.json index bfc5595769e..36fa953424e 100644 --- a/advisories/unreviewed/2022/02/GHSA-59gm-hhq4-vxjm/GHSA-59gm-hhq4-vxjm.json +++ b/advisories/unreviewed/2022/02/GHSA-59gm-hhq4-vxjm/GHSA-59gm-hhq4-vxjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59gm-hhq4-vxjm", - "modified": "2022-02-20T00:00:42Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-02-15T00:02:48Z", "aliases": [ "CVE-2022-0176" ], "details": "The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/06/GHSA-7v3v-r482-rmfj/GHSA-7v3v-r482-rmfj.json b/advisories/unreviewed/2022/06/GHSA-7v3v-r482-rmfj/GHSA-7v3v-r482-rmfj.json index 4fada287f3d..3a3e9f7260e 100644 --- a/advisories/unreviewed/2022/06/GHSA-7v3v-r482-rmfj/GHSA-7v3v-r482-rmfj.json +++ b/advisories/unreviewed/2022/06/GHSA-7v3v-r482-rmfj/GHSA-7v3v-r482-rmfj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-24v8-25pr-r3r4/GHSA-24v8-25pr-r3r4.json b/advisories/unreviewed/2022/12/GHSA-24v8-25pr-r3r4/GHSA-24v8-25pr-r3r4.json index 2a33f13a1e6..c05ceddb052 100644 --- a/advisories/unreviewed/2022/12/GHSA-24v8-25pr-r3r4/GHSA-24v8-25pr-r3r4.json +++ b/advisories/unreviewed/2022/12/GHSA-24v8-25pr-r3r4/GHSA-24v8-25pr-r3r4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24v8-25pr-r3r4", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46879" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-284c-r484-8cqh/GHSA-284c-r484-8cqh.json b/advisories/unreviewed/2022/12/GHSA-284c-r484-8cqh/GHSA-284c-r484-8cqh.json index 1fe2182adcc..ef8af23d6c2 100644 --- a/advisories/unreviewed/2022/12/GHSA-284c-r484-8cqh/GHSA-284c-r484-8cqh.json +++ b/advisories/unreviewed/2022/12/GHSA-284c-r484-8cqh/GHSA-284c-r484-8cqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-284c-r484-8cqh", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45417" diff --git a/advisories/unreviewed/2022/12/GHSA-28j3-x77x-9653/GHSA-28j3-x77x-9653.json b/advisories/unreviewed/2022/12/GHSA-28j3-x77x-9653/GHSA-28j3-x77x-9653.json index fe2dbbceb9a..193c3200fbd 100644 --- a/advisories/unreviewed/2022/12/GHSA-28j3-x77x-9653/GHSA-28j3-x77x-9653.json +++ b/advisories/unreviewed/2022/12/GHSA-28j3-x77x-9653/GHSA-28j3-x77x-9653.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28j3-x77x-9653", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45707" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45707" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/HyEfIEpBj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/HyEfIEpBj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/HyEfIEpBj" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-2vgc-685m-w42v/GHSA-2vgc-685m-w42v.json b/advisories/unreviewed/2022/12/GHSA-2vgc-685m-w42v/GHSA-2vgc-685m-w42v.json index a2c850283e8..1b90cbf1959 100644 --- a/advisories/unreviewed/2022/12/GHSA-2vgc-685m-w42v/GHSA-2vgc-685m-w42v.json +++ b/advisories/unreviewed/2022/12/GHSA-2vgc-685m-w42v/GHSA-2vgc-685m-w42v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vgc-685m-w42v", - "modified": "2023-01-05T06:30:22Z", + "modified": "2025-04-15T15:30:46Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-44015" diff --git a/advisories/unreviewed/2022/12/GHSA-2wc2-77r7-4pm8/GHSA-2wc2-77r7-4pm8.json b/advisories/unreviewed/2022/12/GHSA-2wc2-77r7-4pm8/GHSA-2wc2-77r7-4pm8.json index 6c305c477db..001a359a305 100644 --- a/advisories/unreviewed/2022/12/GHSA-2wc2-77r7-4pm8/GHSA-2wc2-77r7-4pm8.json +++ b/advisories/unreviewed/2022/12/GHSA-2wc2-77r7-4pm8/GHSA-2wc2-77r7-4pm8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wc2-77r7-4pm8", - "modified": "2022-12-30T18:30:45Z", + "modified": "2025-04-15T15:30:40Z", "published": "2022-12-23T18:30:41Z", "aliases": [ "CVE-2022-47941" diff --git a/advisories/unreviewed/2022/12/GHSA-3r7c-wgmw-38g7/GHSA-3r7c-wgmw-38g7.json b/advisories/unreviewed/2022/12/GHSA-3r7c-wgmw-38g7/GHSA-3r7c-wgmw-38g7.json index eb2dc55406c..6f20e31c8b1 100644 --- a/advisories/unreviewed/2022/12/GHSA-3r7c-wgmw-38g7/GHSA-3r7c-wgmw-38g7.json +++ b/advisories/unreviewed/2022/12/GHSA-3r7c-wgmw-38g7/GHSA-3r7c-wgmw-38g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r7c-wgmw-38g7", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46878" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-42wf-78r8-wp79/GHSA-42wf-78r8-wp79.json b/advisories/unreviewed/2022/12/GHSA-42wf-78r8-wp79/GHSA-42wf-78r8-wp79.json index 9c52b729623..4c969c23c54 100644 --- a/advisories/unreviewed/2022/12/GHSA-42wf-78r8-wp79/GHSA-42wf-78r8-wp79.json +++ b/advisories/unreviewed/2022/12/GHSA-42wf-78r8-wp79/GHSA-42wf-78r8-wp79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-42wf-78r8-wp79", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45411" diff --git a/advisories/unreviewed/2022/12/GHSA-4765-j7w9-p387/GHSA-4765-j7w9-p387.json b/advisories/unreviewed/2022/12/GHSA-4765-j7w9-p387/GHSA-4765-j7w9-p387.json index 8c6c1097d82..08973acf445 100644 --- a/advisories/unreviewed/2022/12/GHSA-4765-j7w9-p387/GHSA-4765-j7w9-p387.json +++ b/advisories/unreviewed/2022/12/GHSA-4765-j7w9-p387/GHSA-4765-j7w9-p387.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4765-j7w9-p387", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-31736" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-942" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4vwj-7pm2-257c/GHSA-4vwj-7pm2-257c.json b/advisories/unreviewed/2022/12/GHSA-4vwj-7pm2-257c/GHSA-4vwj-7pm2-257c.json index 1633b44250e..7f79c509af0 100644 --- a/advisories/unreviewed/2022/12/GHSA-4vwj-7pm2-257c/GHSA-4vwj-7pm2-257c.json +++ b/advisories/unreviewed/2022/12/GHSA-4vwj-7pm2-257c/GHSA-4vwj-7pm2-257c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-311" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-5459-wr9w-wpcp/GHSA-5459-wr9w-wpcp.json b/advisories/unreviewed/2022/12/GHSA-5459-wr9w-wpcp/GHSA-5459-wr9w-wpcp.json index c61f2a43711..d8a9bf1e254 100644 --- a/advisories/unreviewed/2022/12/GHSA-5459-wr9w-wpcp/GHSA-5459-wr9w-wpcp.json +++ b/advisories/unreviewed/2022/12/GHSA-5459-wr9w-wpcp/GHSA-5459-wr9w-wpcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5459-wr9w-wpcp", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-45407" diff --git a/advisories/unreviewed/2022/12/GHSA-54r9-6x6g-2vfv/GHSA-54r9-6x6g-2vfv.json b/advisories/unreviewed/2022/12/GHSA-54r9-6x6g-2vfv/GHSA-54r9-6x6g-2vfv.json index dfcd7a8e9a1..26fc532a2f5 100644 --- a/advisories/unreviewed/2022/12/GHSA-54r9-6x6g-2vfv/GHSA-54r9-6x6g-2vfv.json +++ b/advisories/unreviewed/2022/12/GHSA-54r9-6x6g-2vfv/GHSA-54r9-6x6g-2vfv.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-425", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-5grf-cv3x-c266/GHSA-5grf-cv3x-c266.json b/advisories/unreviewed/2022/12/GHSA-5grf-cv3x-c266/GHSA-5grf-cv3x-c266.json index 9f77266d3d0..8d9b1e53562 100644 --- a/advisories/unreviewed/2022/12/GHSA-5grf-cv3x-c266/GHSA-5grf-cv3x-c266.json +++ b/advisories/unreviewed/2022/12/GHSA-5grf-cv3x-c266/GHSA-5grf-cv3x-c266.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5grf-cv3x-c266", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T15:30:39Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46881" diff --git a/advisories/unreviewed/2022/12/GHSA-5h2w-44mr-8x27/GHSA-5h2w-44mr-8x27.json b/advisories/unreviewed/2022/12/GHSA-5h2w-44mr-8x27/GHSA-5h2w-44mr-8x27.json index 08aa7608688..9c869e7d17b 100644 --- a/advisories/unreviewed/2022/12/GHSA-5h2w-44mr-8x27/GHSA-5h2w-44mr-8x27.json +++ b/advisories/unreviewed/2022/12/GHSA-5h2w-44mr-8x27/GHSA-5h2w-44mr-8x27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5h2w-44mr-8x27", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45715" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45715" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/HkJ_o8Arj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/HkJ_o8Arj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/HkJ_o8Arj" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-5h75-x63q-jgxv/GHSA-5h75-x63q-jgxv.json b/advisories/unreviewed/2022/12/GHSA-5h75-x63q-jgxv/GHSA-5h75-x63q-jgxv.json index 21ede99fe77..ab054e433f5 100644 --- a/advisories/unreviewed/2022/12/GHSA-5h75-x63q-jgxv/GHSA-5h75-x63q-jgxv.json +++ b/advisories/unreviewed/2022/12/GHSA-5h75-x63q-jgxv/GHSA-5h75-x63q-jgxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5h75-x63q-jgxv", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46871" @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1104" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-5rm5-cw6f-p927/GHSA-5rm5-cw6f-p927.json b/advisories/unreviewed/2022/12/GHSA-5rm5-cw6f-p927/GHSA-5rm5-cw6f-p927.json index 6596af1a0d4..a925a7180a5 100644 --- a/advisories/unreviewed/2022/12/GHSA-5rm5-cw6f-p927/GHSA-5rm5-cw6f-p927.json +++ b/advisories/unreviewed/2022/12/GHSA-5rm5-cw6f-p927/GHSA-5rm5-cw6f-p927.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rm5-cw6f-p927", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45717" @@ -19,14 +19,23 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45717" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/By3Y6DRrj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/By3Y6DRrj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/By3Y6DRrj" } ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-6gpj-r895-3gxv/GHSA-6gpj-r895-3gxv.json b/advisories/unreviewed/2022/12/GHSA-6gpj-r895-3gxv/GHSA-6gpj-r895-3gxv.json index 559f192bef6..584d70da39d 100644 --- a/advisories/unreviewed/2022/12/GHSA-6gpj-r895-3gxv/GHSA-6gpj-r895-3gxv.json +++ b/advisories/unreviewed/2022/12/GHSA-6gpj-r895-3gxv/GHSA-6gpj-r895-3gxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gpj-r895-3gxv", - "modified": "2022-12-31T00:30:24Z", + "modified": "2025-04-15T15:30:45Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-44013" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-6pf3-q3cx-w87c/GHSA-6pf3-q3cx-w87c.json b/advisories/unreviewed/2022/12/GHSA-6pf3-q3cx-w87c/GHSA-6pf3-q3cx-w87c.json index 0ad5ffd5d80..ec54b160c52 100644 --- a/advisories/unreviewed/2022/12/GHSA-6pf3-q3cx-w87c/GHSA-6pf3-q3cx-w87c.json +++ b/advisories/unreviewed/2022/12/GHSA-6pf3-q3cx-w87c/GHSA-6pf3-q3cx-w87c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pf3-q3cx-w87c", - "modified": "2023-01-04T18:30:58Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45420" diff --git a/advisories/unreviewed/2022/12/GHSA-7526-6xhc-xh2w/GHSA-7526-6xhc-xh2w.json b/advisories/unreviewed/2022/12/GHSA-7526-6xhc-xh2w/GHSA-7526-6xhc-xh2w.json index ac8d4d054da..1a19c1ccbdc 100644 --- a/advisories/unreviewed/2022/12/GHSA-7526-6xhc-xh2w/GHSA-7526-6xhc-xh2w.json +++ b/advisories/unreviewed/2022/12/GHSA-7526-6xhc-xh2w/GHSA-7526-6xhc-xh2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7526-6xhc-xh2w", - "modified": "2023-01-04T03:30:30Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40961" diff --git a/advisories/unreviewed/2022/12/GHSA-7g3f-6r3q-3qmq/GHSA-7g3f-6r3q-3qmq.json b/advisories/unreviewed/2022/12/GHSA-7g3f-6r3q-3qmq/GHSA-7g3f-6r3q-3qmq.json index b887d7ce567..0a6cc421a3a 100644 --- a/advisories/unreviewed/2022/12/GHSA-7g3f-6r3q-3qmq/GHSA-7g3f-6r3q-3qmq.json +++ b/advisories/unreviewed/2022/12/GHSA-7g3f-6r3q-3qmq/GHSA-7g3f-6r3q-3qmq.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7mxj-29p2-6g84/GHSA-7mxj-29p2-6g84.json b/advisories/unreviewed/2022/12/GHSA-7mxj-29p2-6g84/GHSA-7mxj-29p2-6g84.json index ee1add5e4f6..5821150923f 100644 --- a/advisories/unreviewed/2022/12/GHSA-7mxj-29p2-6g84/GHSA-7mxj-29p2-6g84.json +++ b/advisories/unreviewed/2022/12/GHSA-7mxj-29p2-6g84/GHSA-7mxj-29p2-6g84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7mxj-29p2-6g84", - "modified": "2023-01-04T06:30:35Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40958" diff --git a/advisories/unreviewed/2022/12/GHSA-82mr-6r7c-c49h/GHSA-82mr-6r7c-c49h.json b/advisories/unreviewed/2022/12/GHSA-82mr-6r7c-c49h/GHSA-82mr-6r7c-c49h.json index aa5de518b4a..0adbffb20a3 100644 --- a/advisories/unreviewed/2022/12/GHSA-82mr-6r7c-c49h/GHSA-82mr-6r7c-c49h.json +++ b/advisories/unreviewed/2022/12/GHSA-82mr-6r7c-c49h/GHSA-82mr-6r7c-c49h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82mr-6r7c-c49h", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45408" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-87v5-p656-xr8x/GHSA-87v5-p656-xr8x.json b/advisories/unreviewed/2022/12/GHSA-87v5-p656-xr8x/GHSA-87v5-p656-xr8x.json index 7abf8c13307..e1933c94db6 100644 --- a/advisories/unreviewed/2022/12/GHSA-87v5-p656-xr8x/GHSA-87v5-p656-xr8x.json +++ b/advisories/unreviewed/2022/12/GHSA-87v5-p656-xr8x/GHSA-87v5-p656-xr8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87v5-p656-xr8x", - "modified": "2022-12-31T00:30:24Z", + "modified": "2025-04-15T15:30:46Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-44016" diff --git a/advisories/unreviewed/2022/12/GHSA-8hg7-fgc2-26h6/GHSA-8hg7-fgc2-26h6.json b/advisories/unreviewed/2022/12/GHSA-8hg7-fgc2-26h6/GHSA-8hg7-fgc2-26h6.json index e0d9d71cc2b..99e896db28f 100644 --- a/advisories/unreviewed/2022/12/GHSA-8hg7-fgc2-26h6/GHSA-8hg7-fgc2-26h6.json +++ b/advisories/unreviewed/2022/12/GHSA-8hg7-fgc2-26h6/GHSA-8hg7-fgc2-26h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8hg7-fgc2-26h6", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:40Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45706" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45706" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/SJZx0L0Sj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/SJZx0L0Sj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/SJZx0L0Sj" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-8mqx-qm24-g4fh/GHSA-8mqx-qm24-g4fh.json b/advisories/unreviewed/2022/12/GHSA-8mqx-qm24-g4fh/GHSA-8mqx-qm24-g4fh.json index ec7b530d09c..2929d713878 100644 --- a/advisories/unreviewed/2022/12/GHSA-8mqx-qm24-g4fh/GHSA-8mqx-qm24-g4fh.json +++ b/advisories/unreviewed/2022/12/GHSA-8mqx-qm24-g4fh/GHSA-8mqx-qm24-g4fh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mqx-qm24-g4fh", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-2200" diff --git a/advisories/unreviewed/2022/12/GHSA-8mr2-8r3v-fj69/GHSA-8mr2-8r3v-fj69.json b/advisories/unreviewed/2022/12/GHSA-8mr2-8r3v-fj69/GHSA-8mr2-8r3v-fj69.json index dc482d67756..c8417b2ab3b 100644 --- a/advisories/unreviewed/2022/12/GHSA-8mr2-8r3v-fj69/GHSA-8mr2-8r3v-fj69.json +++ b/advisories/unreviewed/2022/12/GHSA-8mr2-8r3v-fj69/GHSA-8mr2-8r3v-fj69.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-9f66-rrvp-2m2v/GHSA-9f66-rrvp-2m2v.json b/advisories/unreviewed/2022/12/GHSA-9f66-rrvp-2m2v/GHSA-9f66-rrvp-2m2v.json index 789e9422fb9..f2c1f6593b5 100644 --- a/advisories/unreviewed/2022/12/GHSA-9f66-rrvp-2m2v/GHSA-9f66-rrvp-2m2v.json +++ b/advisories/unreviewed/2022/12/GHSA-9f66-rrvp-2m2v/GHSA-9f66-rrvp-2m2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f66-rrvp-2m2v", - "modified": "2022-12-31T00:30:24Z", + "modified": "2025-04-15T15:30:46Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-44014" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-9p3c-x5jh-9p27/GHSA-9p3c-x5jh-9p27.json b/advisories/unreviewed/2022/12/GHSA-9p3c-x5jh-9p27/GHSA-9p3c-x5jh-9p27.json index c0e6e569c8a..2b4bd24842a 100644 --- a/advisories/unreviewed/2022/12/GHSA-9p3c-x5jh-9p27/GHSA-9p3c-x5jh-9p27.json +++ b/advisories/unreviewed/2022/12/GHSA-9p3c-x5jh-9p27/GHSA-9p3c-x5jh-9p27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9p3c-x5jh-9p27", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45409" diff --git a/advisories/unreviewed/2022/12/GHSA-cpj8-ppjf-3vrf/GHSA-cpj8-ppjf-3vrf.json b/advisories/unreviewed/2022/12/GHSA-cpj8-ppjf-3vrf/GHSA-cpj8-ppjf-3vrf.json index f11340a0b37..3e0f11ec841 100644 --- a/advisories/unreviewed/2022/12/GHSA-cpj8-ppjf-3vrf/GHSA-cpj8-ppjf-3vrf.json +++ b/advisories/unreviewed/2022/12/GHSA-cpj8-ppjf-3vrf/GHSA-cpj8-ppjf-3vrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpj8-ppjf-3vrf", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T15:30:44Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-45891" diff --git a/advisories/unreviewed/2022/12/GHSA-fv4x-hrpq-wqgp/GHSA-fv4x-hrpq-wqgp.json b/advisories/unreviewed/2022/12/GHSA-fv4x-hrpq-wqgp/GHSA-fv4x-hrpq-wqgp.json index 5837f1f55a7..d5b622262e2 100644 --- a/advisories/unreviewed/2022/12/GHSA-fv4x-hrpq-wqgp/GHSA-fv4x-hrpq-wqgp.json +++ b/advisories/unreviewed/2022/12/GHSA-fv4x-hrpq-wqgp/GHSA-fv4x-hrpq-wqgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv4x-hrpq-wqgp", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29916" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-g2g2-6grg-2jm4/GHSA-g2g2-6grg-2jm4.json b/advisories/unreviewed/2022/12/GHSA-g2g2-6grg-2jm4/GHSA-g2g2-6grg-2jm4.json index 279ca91a763..8e4d670e918 100644 --- a/advisories/unreviewed/2022/12/GHSA-g2g2-6grg-2jm4/GHSA-g2g2-6grg-2jm4.json +++ b/advisories/unreviewed/2022/12/GHSA-g2g2-6grg-2jm4/GHSA-g2g2-6grg-2jm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2g2-6grg-2jm4", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45418" diff --git a/advisories/unreviewed/2022/12/GHSA-g2h7-7gvv-x89v/GHSA-g2h7-7gvv-x89v.json b/advisories/unreviewed/2022/12/GHSA-g2h7-7gvv-x89v/GHSA-g2h7-7gvv-x89v.json index 564a6304d30..9df32bca3d2 100644 --- a/advisories/unreviewed/2022/12/GHSA-g2h7-7gvv-x89v/GHSA-g2h7-7gvv-x89v.json +++ b/advisories/unreviewed/2022/12/GHSA-g2h7-7gvv-x89v/GHSA-g2h7-7gvv-x89v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2h7-7gvv-x89v", - "modified": "2022-12-30T18:30:45Z", + "modified": "2025-04-15T15:30:40Z", "published": "2022-12-23T18:30:41Z", "aliases": [ "CVE-2022-47942" diff --git a/advisories/unreviewed/2022/12/GHSA-g426-wcxv-272f/GHSA-g426-wcxv-272f.json b/advisories/unreviewed/2022/12/GHSA-g426-wcxv-272f/GHSA-g426-wcxv-272f.json index 2be20cb8221..ab16917413a 100644 --- a/advisories/unreviewed/2022/12/GHSA-g426-wcxv-272f/GHSA-g426-wcxv-272f.json +++ b/advisories/unreviewed/2022/12/GHSA-g426-wcxv-272f/GHSA-g426-wcxv-272f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g426-wcxv-272f", - "modified": "2023-01-05T15:30:31Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-2226" diff --git a/advisories/unreviewed/2022/12/GHSA-g83w-9px8-cmhv/GHSA-g83w-9px8-cmhv.json b/advisories/unreviewed/2022/12/GHSA-g83w-9px8-cmhv/GHSA-g83w-9px8-cmhv.json index 5325c7dc6f7..94dfb47c038 100644 --- a/advisories/unreviewed/2022/12/GHSA-g83w-9px8-cmhv/GHSA-g83w-9px8-cmhv.json +++ b/advisories/unreviewed/2022/12/GHSA-g83w-9px8-cmhv/GHSA-g83w-9px8-cmhv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g83w-9px8-cmhv", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:42Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45718" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45718" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/Hkb38vELj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/Hkb38vELj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/Hkb38vELj" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-g867-grx9-vj64/GHSA-g867-grx9-vj64.json b/advisories/unreviewed/2022/12/GHSA-g867-grx9-vj64/GHSA-g867-grx9-vj64.json index b59ec141233..b78efdb0844 100644 --- a/advisories/unreviewed/2022/12/GHSA-g867-grx9-vj64/GHSA-g867-grx9-vj64.json +++ b/advisories/unreviewed/2022/12/GHSA-g867-grx9-vj64/GHSA-g867-grx9-vj64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g867-grx9-vj64", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:39Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46885" diff --git a/advisories/unreviewed/2022/12/GHSA-gf6p-963f-gv5h/GHSA-gf6p-963f-gv5h.json b/advisories/unreviewed/2022/12/GHSA-gf6p-963f-gv5h/GHSA-gf6p-963f-gv5h.json index 52f5de379f7..d2a5afa3d34 100644 --- a/advisories/unreviewed/2022/12/GHSA-gf6p-963f-gv5h/GHSA-gf6p-963f-gv5h.json +++ b/advisories/unreviewed/2022/12/GHSA-gf6p-963f-gv5h/GHSA-gf6p-963f-gv5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf6p-963f-gv5h", - "modified": "2023-01-04T18:30:58Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45421" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-gfq4-pq7x-mq8c/GHSA-gfq4-pq7x-mq8c.json b/advisories/unreviewed/2022/12/GHSA-gfq4-pq7x-mq8c/GHSA-gfq4-pq7x-mq8c.json index 2caac48633a..01af4e590cf 100644 --- a/advisories/unreviewed/2022/12/GHSA-gfq4-pq7x-mq8c/GHSA-gfq4-pq7x-mq8c.json +++ b/advisories/unreviewed/2022/12/GHSA-gfq4-pq7x-mq8c/GHSA-gfq4-pq7x-mq8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfq4-pq7x-mq8c", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29917" @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-617" + "CWE-617", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-ggr5-58mq-975v/GHSA-ggr5-58mq-975v.json b/advisories/unreviewed/2022/12/GHSA-ggr5-58mq-975v/GHSA-ggr5-58mq-975v.json index 1ec714d11db..7964f4c99f9 100644 --- a/advisories/unreviewed/2022/12/GHSA-ggr5-58mq-975v/GHSA-ggr5-58mq-975v.json +++ b/advisories/unreviewed/2022/12/GHSA-ggr5-58mq-975v/GHSA-ggr5-58mq-975v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggr5-58mq-975v", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:42Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-45721" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45721" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/BJUfyuABo" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/BJUfyuABo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/BJUfyuABo" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-gvhf-4hjq-39hg/GHSA-gvhf-4hjq-39hg.json b/advisories/unreviewed/2022/12/GHSA-gvhf-4hjq-39hg/GHSA-gvhf-4hjq-39hg.json index 47fe12707c0..0ad66514cc7 100644 --- a/advisories/unreviewed/2022/12/GHSA-gvhf-4hjq-39hg/GHSA-gvhf-4hjq-39hg.json +++ b/advisories/unreviewed/2022/12/GHSA-gvhf-4hjq-39hg/GHSA-gvhf-4hjq-39hg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvhf-4hjq-39hg", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45410" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-gvhr-fq94-q7h9/GHSA-gvhr-fq94-q7h9.json b/advisories/unreviewed/2022/12/GHSA-gvhr-fq94-q7h9/GHSA-gvhr-fq94-q7h9.json index 7a5d01cbd34..90a7957a393 100644 --- a/advisories/unreviewed/2022/12/GHSA-gvhr-fq94-q7h9/GHSA-gvhr-fq94-q7h9.json +++ b/advisories/unreviewed/2022/12/GHSA-gvhr-fq94-q7h9/GHSA-gvhr-fq94-q7h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvhr-fq94-q7h9", - "modified": "2023-01-05T15:30:29Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45414" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-h295-679q-mhm8/GHSA-h295-679q-mhm8.json b/advisories/unreviewed/2022/12/GHSA-h295-679q-mhm8/GHSA-h295-679q-mhm8.json index f3045f9f55f..04160b8ca1d 100644 --- a/advisories/unreviewed/2022/12/GHSA-h295-679q-mhm8/GHSA-h295-679q-mhm8.json +++ b/advisories/unreviewed/2022/12/GHSA-h295-679q-mhm8/GHSA-h295-679q-mhm8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h295-679q-mhm8", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45413" diff --git a/advisories/unreviewed/2022/12/GHSA-h3mp-j53v-44vx/GHSA-h3mp-j53v-44vx.json b/advisories/unreviewed/2022/12/GHSA-h3mp-j53v-44vx/GHSA-h3mp-j53v-44vx.json index 049aecf0cae..16d43729324 100644 --- a/advisories/unreviewed/2022/12/GHSA-h3mp-j53v-44vx/GHSA-h3mp-j53v-44vx.json +++ b/advisories/unreviewed/2022/12/GHSA-h3mp-j53v-44vx/GHSA-h3mp-j53v-44vx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3mp-j53v-44vx", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-45406" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-hp2r-mwcp-253w/GHSA-hp2r-mwcp-253w.json b/advisories/unreviewed/2022/12/GHSA-hp2r-mwcp-253w/GHSA-hp2r-mwcp-253w.json index d750d688ea4..89a8c82f404 100644 --- a/advisories/unreviewed/2022/12/GHSA-hp2r-mwcp-253w/GHSA-hp2r-mwcp-253w.json +++ b/advisories/unreviewed/2022/12/GHSA-hp2r-mwcp-253w/GHSA-hp2r-mwcp-253w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp2r-mwcp-253w", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45708" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45708" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/B1rR3UArj" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/B1rR3UArj" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/B1rR3UArj" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-j5r5-jmr3-48c5/GHSA-j5r5-jmr3-48c5.json b/advisories/unreviewed/2022/12/GHSA-j5r5-jmr3-48c5/GHSA-j5r5-jmr3-48c5.json index b21cecd3418..52381e560d3 100644 --- a/advisories/unreviewed/2022/12/GHSA-j5r5-jmr3-48c5/GHSA-j5r5-jmr3-48c5.json +++ b/advisories/unreviewed/2022/12/GHSA-j5r5-jmr3-48c5/GHSA-j5r5-jmr3-48c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5r5-jmr3-48c5", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46880" diff --git a/advisories/unreviewed/2022/12/GHSA-jx2q-hvww-224r/GHSA-jx2q-hvww-224r.json b/advisories/unreviewed/2022/12/GHSA-jx2q-hvww-224r/GHSA-jx2q-hvww-224r.json index 34143e9d8e2..03ae07ee49c 100644 --- a/advisories/unreviewed/2022/12/GHSA-jx2q-hvww-224r/GHSA-jx2q-hvww-224r.json +++ b/advisories/unreviewed/2022/12/GHSA-jx2q-hvww-224r/GHSA-jx2q-hvww-224r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx2q-hvww-224r", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45415" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-jx63-7q59-f3fj/GHSA-jx63-7q59-f3fj.json b/advisories/unreviewed/2022/12/GHSA-jx63-7q59-f3fj/GHSA-jx63-7q59-f3fj.json index 16c39bff76b..862ddae2c55 100644 --- a/advisories/unreviewed/2022/12/GHSA-jx63-7q59-f3fj/GHSA-jx63-7q59-f3fj.json +++ b/advisories/unreviewed/2022/12/GHSA-jx63-7q59-f3fj/GHSA-jx63-7q59-f3fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jx63-7q59-f3fj", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45712" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45712" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/r1pG4cori" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/r1pG4cori" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/r1pG4cori" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-m847-mpgv-7mwr/GHSA-m847-mpgv-7mwr.json b/advisories/unreviewed/2022/12/GHSA-m847-mpgv-7mwr/GHSA-m847-mpgv-7mwr.json index c32b13e544f..fc12b045523 100644 --- a/advisories/unreviewed/2022/12/GHSA-m847-mpgv-7mwr/GHSA-m847-mpgv-7mwr.json +++ b/advisories/unreviewed/2022/12/GHSA-m847-mpgv-7mwr/GHSA-m847-mpgv-7mwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m847-mpgv-7mwr", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:40Z", "published": "2022-12-23T18:30:40Z", "aliases": [ "CVE-2022-47943" diff --git a/advisories/unreviewed/2022/12/GHSA-m9xr-mrx5-456x/GHSA-m9xr-mrx5-456x.json b/advisories/unreviewed/2022/12/GHSA-m9xr-mrx5-456x/GHSA-m9xr-mrx5-456x.json index 98c2e75bcf1..93ab83e455c 100644 --- a/advisories/unreviewed/2022/12/GHSA-m9xr-mrx5-456x/GHSA-m9xr-mrx5-456x.json +++ b/advisories/unreviewed/2022/12/GHSA-m9xr-mrx5-456x/GHSA-m9xr-mrx5-456x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9xr-mrx5-456x", - "modified": "2023-01-13T15:30:27Z", + "modified": "2025-04-15T15:30:43Z", "published": "2022-12-24T00:30:19Z", "aliases": [ "CVE-2022-45798" diff --git a/advisories/unreviewed/2022/12/GHSA-mg2x-8rwm-j9cx/GHSA-mg2x-8rwm-j9cx.json b/advisories/unreviewed/2022/12/GHSA-mg2x-8rwm-j9cx/GHSA-mg2x-8rwm-j9cx.json index d0e370a9560..acf7b6efdc9 100644 --- a/advisories/unreviewed/2022/12/GHSA-mg2x-8rwm-j9cx/GHSA-mg2x-8rwm-j9cx.json +++ b/advisories/unreviewed/2022/12/GHSA-mg2x-8rwm-j9cx/GHSA-mg2x-8rwm-j9cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mg2x-8rwm-j9cx", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-2505" diff --git a/advisories/unreviewed/2022/12/GHSA-mg8g-v5cr-wqjx/GHSA-mg8g-v5cr-wqjx.json b/advisories/unreviewed/2022/12/GHSA-mg8g-v5cr-wqjx/GHSA-mg8g-v5cr-wqjx.json index 63d0104c807..dd21c521f6c 100644 --- a/advisories/unreviewed/2022/12/GHSA-mg8g-v5cr-wqjx/GHSA-mg8g-v5cr-wqjx.json +++ b/advisories/unreviewed/2022/12/GHSA-mg8g-v5cr-wqjx/GHSA-mg8g-v5cr-wqjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mg8g-v5cr-wqjx", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T15:30:44Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-44012" diff --git a/advisories/unreviewed/2022/12/GHSA-p2g9-fj77-vp3r/GHSA-p2g9-fj77-vp3r.json b/advisories/unreviewed/2022/12/GHSA-p2g9-fj77-vp3r/GHSA-p2g9-fj77-vp3r.json index e59435d0031..bae6014ab90 100644 --- a/advisories/unreviewed/2022/12/GHSA-p2g9-fj77-vp3r/GHSA-p2g9-fj77-vp3r.json +++ b/advisories/unreviewed/2022/12/GHSA-p2g9-fj77-vp3r/GHSA-p2g9-fj77-vp3r.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-p5f8-m753-hvgf/GHSA-p5f8-m753-hvgf.json b/advisories/unreviewed/2022/12/GHSA-p5f8-m753-hvgf/GHSA-p5f8-m753-hvgf.json index eeb261fa19c..1ebc57ca90d 100644 --- a/advisories/unreviewed/2022/12/GHSA-p5f8-m753-hvgf/GHSA-p5f8-m753-hvgf.json +++ b/advisories/unreviewed/2022/12/GHSA-p5f8-m753-hvgf/GHSA-p5f8-m753-hvgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5f8-m753-hvgf", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46873" diff --git a/advisories/unreviewed/2022/12/GHSA-pc7h-fmrf-pp2j/GHSA-pc7h-fmrf-pp2j.json b/advisories/unreviewed/2022/12/GHSA-pc7h-fmrf-pp2j/GHSA-pc7h-fmrf-pp2j.json index d4486b0a858..8ccfe117190 100644 --- a/advisories/unreviewed/2022/12/GHSA-pc7h-fmrf-pp2j/GHSA-pc7h-fmrf-pp2j.json +++ b/advisories/unreviewed/2022/12/GHSA-pc7h-fmrf-pp2j/GHSA-pc7h-fmrf-pp2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7h-fmrf-pp2j", - "modified": "2023-01-04T06:30:36Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40959" diff --git a/advisories/unreviewed/2022/12/GHSA-pvq5-77h5-rgw5/GHSA-pvq5-77h5-rgw5.json b/advisories/unreviewed/2022/12/GHSA-pvq5-77h5-rgw5/GHSA-pvq5-77h5-rgw5.json index 44f8dcd707c..f742ff86b24 100644 --- a/advisories/unreviewed/2022/12/GHSA-pvq5-77h5-rgw5/GHSA-pvq5-77h5-rgw5.json +++ b/advisories/unreviewed/2022/12/GHSA-pvq5-77h5-rgw5/GHSA-pvq5-77h5-rgw5.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-755" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-pwwf-7f48-895h/GHSA-pwwf-7f48-895h.json b/advisories/unreviewed/2022/12/GHSA-pwwf-7f48-895h/GHSA-pwwf-7f48-895h.json index 5f88b2a5a23..23a37fe862d 100644 --- a/advisories/unreviewed/2022/12/GHSA-pwwf-7f48-895h/GHSA-pwwf-7f48-895h.json +++ b/advisories/unreviewed/2022/12/GHSA-pwwf-7f48-895h/GHSA-pwwf-7f48-895h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pwwf-7f48-895h", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46874" @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-q4r6-2rwg-f833/GHSA-q4r6-2rwg-f833.json b/advisories/unreviewed/2022/12/GHSA-q4r6-2rwg-f833/GHSA-q4r6-2rwg-f833.json index a8f5dbedd11..98a4007de56 100644 --- a/advisories/unreviewed/2022/12/GHSA-q4r6-2rwg-f833/GHSA-q4r6-2rwg-f833.json +++ b/advisories/unreviewed/2022/12/GHSA-q4r6-2rwg-f833/GHSA-q4r6-2rwg-f833.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q4r6-2rwg-f833", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:42Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45719" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45719" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/BJ8I_DCBi" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/BJ8I_DCBi" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/BJ8I_DCBi" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-qg25-r8rj-7fhp/GHSA-qg25-r8rj-7fhp.json b/advisories/unreviewed/2022/12/GHSA-qg25-r8rj-7fhp/GHSA-qg25-r8rj-7fhp.json index 29c2c09b040..fc09e176daa 100644 --- a/advisories/unreviewed/2022/12/GHSA-qg25-r8rj-7fhp/GHSA-qg25-r8rj-7fhp.json +++ b/advisories/unreviewed/2022/12/GHSA-qg25-r8rj-7fhp/GHSA-qg25-r8rj-7fhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg25-r8rj-7fhp", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45419" diff --git a/advisories/unreviewed/2022/12/GHSA-qh9q-rjpp-hqc3/GHSA-qh9q-rjpp-hqc3.json b/advisories/unreviewed/2022/12/GHSA-qh9q-rjpp-hqc3/GHSA-qh9q-rjpp-hqc3.json index 03fb328b708..94da7329733 100644 --- a/advisories/unreviewed/2022/12/GHSA-qh9q-rjpp-hqc3/GHSA-qh9q-rjpp-hqc3.json +++ b/advisories/unreviewed/2022/12/GHSA-qh9q-rjpp-hqc3/GHSA-qh9q-rjpp-hqc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qh9q-rjpp-hqc3", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:39Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46882" diff --git a/advisories/unreviewed/2022/12/GHSA-qhr9-wjgv-2r72/GHSA-qhr9-wjgv-2r72.json b/advisories/unreviewed/2022/12/GHSA-qhr9-wjgv-2r72/GHSA-qhr9-wjgv-2r72.json index f36040d74a1..e5293b0ce4e 100644 --- a/advisories/unreviewed/2022/12/GHSA-qhr9-wjgv-2r72/GHSA-qhr9-wjgv-2r72.json +++ b/advisories/unreviewed/2022/12/GHSA-qhr9-wjgv-2r72/GHSA-qhr9-wjgv-2r72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhr9-wjgv-2r72", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46877" @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-rf5c-p2xm-2r64/GHSA-rf5c-p2xm-2r64.json b/advisories/unreviewed/2022/12/GHSA-rf5c-p2xm-2r64/GHSA-rf5c-p2xm-2r64.json index 192125dbbff..e0ed58c5858 100644 --- a/advisories/unreviewed/2022/12/GHSA-rf5c-p2xm-2r64/GHSA-rf5c-p2xm-2r64.json +++ b/advisories/unreviewed/2022/12/GHSA-rf5c-p2xm-2r64/GHSA-rf5c-p2xm-2r64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf5c-p2xm-2r64", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T15:30:34Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29918" diff --git a/advisories/unreviewed/2022/12/GHSA-rgfq-ffxq-x68m/GHSA-rgfq-ffxq-x68m.json b/advisories/unreviewed/2022/12/GHSA-rgfq-ffxq-x68m/GHSA-rgfq-ffxq-x68m.json index cc2ed736a78..4864e131f0a 100644 --- a/advisories/unreviewed/2022/12/GHSA-rgfq-ffxq-x68m/GHSA-rgfq-ffxq-x68m.json +++ b/advisories/unreviewed/2022/12/GHSA-rgfq-ffxq-x68m/GHSA-rgfq-ffxq-x68m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgfq-ffxq-x68m", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45710" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45710" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/B1XG-5iSo" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/B1XG-5iSo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/B1XG-5iSo" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-rhh8-vf3p-5mx3/GHSA-rhh8-vf3p-5mx3.json b/advisories/unreviewed/2022/12/GHSA-rhh8-vf3p-5mx3/GHSA-rhh8-vf3p-5mx3.json index 37ddc9f783f..bb8ff52982e 100644 --- a/advisories/unreviewed/2022/12/GHSA-rhh8-vf3p-5mx3/GHSA-rhh8-vf3p-5mx3.json +++ b/advisories/unreviewed/2022/12/GHSA-rhh8-vf3p-5mx3/GHSA-rhh8-vf3p-5mx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rhh8-vf3p-5mx3", - "modified": "2023-01-04T21:30:17Z", + "modified": "2025-04-15T15:30:39Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46883" @@ -29,7 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787", + "CWE-88" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vp6m-9qxp-4j7m/GHSA-vp6m-9qxp-4j7m.json b/advisories/unreviewed/2022/12/GHSA-vp6m-9qxp-4j7m/GHSA-vp6m-9qxp-4j7m.json index 9e2611a1fd4..b4d5a0abc7b 100644 --- a/advisories/unreviewed/2022/12/GHSA-vp6m-9qxp-4j7m/GHSA-vp6m-9qxp-4j7m.json +++ b/advisories/unreviewed/2022/12/GHSA-vp6m-9qxp-4j7m/GHSA-vp6m-9qxp-4j7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vp6m-9qxp-4j7m", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45709" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45709" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/BkFpXcsSs" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/BkFpXcsSs" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/BkFpXcsSs" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-w54j-3mgp-xm9q/GHSA-w54j-3mgp-xm9q.json b/advisories/unreviewed/2022/12/GHSA-w54j-3mgp-xm9q/GHSA-w54j-3mgp-xm9q.json index f057c4b4cc6..c970de9362b 100644 --- a/advisories/unreviewed/2022/12/GHSA-w54j-3mgp-xm9q/GHSA-w54j-3mgp-xm9q.json +++ b/advisories/unreviewed/2022/12/GHSA-w54j-3mgp-xm9q/GHSA-w54j-3mgp-xm9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w54j-3mgp-xm9q", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:38Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46875" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w657-6g6r-c5p3/GHSA-w657-6g6r-c5p3.json b/advisories/unreviewed/2022/12/GHSA-w657-6g6r-c5p3/GHSA-w657-6g6r-c5p3.json index a57d4f61198..3aaab5d0c5d 100644 --- a/advisories/unreviewed/2022/12/GHSA-w657-6g6r-c5p3/GHSA-w657-6g6r-c5p3.json +++ b/advisories/unreviewed/2022/12/GHSA-w657-6g6r-c5p3/GHSA-w657-6g6r-c5p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w657-6g6r-c5p3", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45714" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45714" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/S1QhLw0Ss" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/S1QhLw0Ss" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/S1QhLw0Ss" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-w696-j5x3-hhvj/GHSA-w696-j5x3-hhvj.json b/advisories/unreviewed/2022/12/GHSA-w696-j5x3-hhvj/GHSA-w696-j5x3-hhvj.json index 58590907311..20b73d67cc9 100644 --- a/advisories/unreviewed/2022/12/GHSA-w696-j5x3-hhvj/GHSA-w696-j5x3-hhvj.json +++ b/advisories/unreviewed/2022/12/GHSA-w696-j5x3-hhvj/GHSA-w696-j5x3-hhvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w696-j5x3-hhvj", - "modified": "2023-01-04T15:30:20Z", + "modified": "2025-04-15T15:30:37Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-46872" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w7vf-mp9x-925q/GHSA-w7vf-mp9x-925q.json b/advisories/unreviewed/2022/12/GHSA-w7vf-mp9x-925q/GHSA-w7vf-mp9x-925q.json index 55d3909cf9a..514434b680f 100644 --- a/advisories/unreviewed/2022/12/GHSA-w7vf-mp9x-925q/GHSA-w7vf-mp9x-925q.json +++ b/advisories/unreviewed/2022/12/GHSA-w7vf-mp9x-925q/GHSA-w7vf-mp9x-925q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7vf-mp9x-925q", - "modified": "2023-01-04T03:30:30Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40960" diff --git a/advisories/unreviewed/2022/12/GHSA-wcx8-5vxf-rv69/GHSA-wcx8-5vxf-rv69.json b/advisories/unreviewed/2022/12/GHSA-wcx8-5vxf-rv69/GHSA-wcx8-5vxf-rv69.json index e608d03096b..04381ce132d 100644 --- a/advisories/unreviewed/2022/12/GHSA-wcx8-5vxf-rv69/GHSA-wcx8-5vxf-rv69.json +++ b/advisories/unreviewed/2022/12/GHSA-wcx8-5vxf-rv69/GHSA-wcx8-5vxf-rv69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcx8-5vxf-rv69", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T15:30:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40962" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-wfp4-223f-x5rm/GHSA-wfp4-223f-x5rm.json b/advisories/unreviewed/2022/12/GHSA-wfp4-223f-x5rm/GHSA-wfp4-223f-x5rm.json index 6cc796340e2..5728afb25d8 100644 --- a/advisories/unreviewed/2022/12/GHSA-wfp4-223f-x5rm/GHSA-wfp4-223f-x5rm.json +++ b/advisories/unreviewed/2022/12/GHSA-wfp4-223f-x5rm/GHSA-wfp4-223f-x5rm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfp4-223f-x5rm", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45416" diff --git a/advisories/unreviewed/2022/12/GHSA-wh4p-p8wc-5h67/GHSA-wh4p-p8wc-5h67.json b/advisories/unreviewed/2022/12/GHSA-wh4p-p8wc-5h67/GHSA-wh4p-p8wc-5h67.json index c52e767e6ae..3a604eb9070 100644 --- a/advisories/unreviewed/2022/12/GHSA-wh4p-p8wc-5h67/GHSA-wh4p-p8wc-5h67.json +++ b/advisories/unreviewed/2022/12/GHSA-wh4p-p8wc-5h67/GHSA-wh4p-p8wc-5h67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wh4p-p8wc-5h67", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:41Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45716" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45716" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/rywHivCBo" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/rywHivCBo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/rywHivCBo" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-wpwv-wrpr-fm7f/GHSA-wpwv-wrpr-fm7f.json b/advisories/unreviewed/2022/12/GHSA-wpwv-wrpr-fm7f/GHSA-wpwv-wrpr-fm7f.json index a7d3d710043..74871f5907f 100644 --- a/advisories/unreviewed/2022/12/GHSA-wpwv-wrpr-fm7f/GHSA-wpwv-wrpr-fm7f.json +++ b/advisories/unreviewed/2022/12/GHSA-wpwv-wrpr-fm7f/GHSA-wpwv-wrpr-fm7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpwv-wrpr-fm7f", - "modified": "2023-01-04T21:30:18Z", + "modified": "2025-04-15T15:30:42Z", "published": "2022-12-23T21:30:18Z", "aliases": [ "CVE-2022-45720" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45720" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40AAN506JzR6urM5U8fNh1ng/SkCD5PEUo" + }, { "type": "WEB", "url": "https://hackmd.io/@AAN506JzR6urM5U8fNh1ng/SkCD5PEUo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@chaosisaladdar/SkCD5PEUo" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-ww43-23jx-qcpc/GHSA-ww43-23jx-qcpc.json b/advisories/unreviewed/2022/12/GHSA-ww43-23jx-qcpc/GHSA-ww43-23jx-qcpc.json index d0054736141..5db61502ba6 100644 --- a/advisories/unreviewed/2022/12/GHSA-ww43-23jx-qcpc/GHSA-ww43-23jx-qcpc.json +++ b/advisories/unreviewed/2022/12/GHSA-ww43-23jx-qcpc/GHSA-ww43-23jx-qcpc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ww43-23jx-qcpc", - "modified": "2023-01-05T15:30:30Z", + "modified": "2025-04-15T15:30:36Z", "published": "2022-12-22T21:30:27Z", "aliases": [ "CVE-2022-45412" diff --git a/advisories/unreviewed/2024/02/GHSA-633m-2q58-q23r/GHSA-633m-2q58-q23r.json b/advisories/unreviewed/2024/02/GHSA-633m-2q58-q23r/GHSA-633m-2q58-q23r.json index 8c645cee2fc..5da8538d5fd 100644 --- a/advisories/unreviewed/2024/02/GHSA-633m-2q58-q23r/GHSA-633m-2q58-q23r.json +++ b/advisories/unreviewed/2024/02/GHSA-633m-2q58-q23r/GHSA-633m-2q58-q23r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-633m-2q58-q23r", - "modified": "2024-02-21T09:31:01Z", + "modified": "2025-04-15T15:30:46Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2024-25905" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json b/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json index ae118f99057..29286bf0f1e 100644 --- a/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json +++ b/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2g84-5882-fhcm", - "modified": "2025-03-27T18:31:27Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-03-27T18:31:27Z", "aliases": [ "CVE-2023-52994" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: Fix suspend with Xen PV\n\nCommit f1e525009493 (\"x86/boot: Skip realmode init code when running as\nXen PV guest\") missed one code path accessing real_mode_header, leading\nto dereferencing NULL when suspending the system under Xen:\n\n [ 348.284004] PM: suspend entry (deep)\n [ 348.289532] Filesystems sync: 0.005 seconds\n [ 348.291545] Freezing user space processes ... (elapsed 0.000 seconds) done.\n [ 348.292457] OOM killer disabled.\n [ 348.292462] Freezing remaining freezable tasks ... (elapsed 0.104 seconds) done.\n [ 348.396612] printk: Suspending console(s) (use no_console_suspend to debug)\n [ 348.749228] PM: suspend devices took 0.352 seconds\n [ 348.769713] ACPI: EC: interrupt blocked\n [ 348.816077] BUG: kernel NULL pointer dereference, address: 000000000000001c\n [ 348.816080] #PF: supervisor read access in kernel mode\n [ 348.816081] #PF: error_code(0x0000) - not-present page\n [ 348.816083] PGD 0 P4D 0\n [ 348.816086] Oops: 0000 [#1] PREEMPT SMP NOPTI\n [ 348.816089] CPU: 0 PID: 6764 Comm: systemd-sleep Not tainted 6.1.3-1.fc32.qubes.x86_64 #1\n [ 348.816092] Hardware name: Star Labs StarBook/StarBook, BIOS 8.01 07/03/2022\n [ 348.816093] RIP: e030:acpi_get_wakeup_address+0xc/0x20\n\nFix that by adding an optional acpi callback allowing to skip setting\nthe wakeup address, as in the Xen PV case this will be handled by the\nhypervisor anyway.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:47Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json b/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json index cc840270ec9..528b6c9ba00 100644 --- a/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json +++ b/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4j5r-8cvm-p98h", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:49Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52988" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path()\n\nsnd_hda_get_connections() can return a negative error code.\nIt may lead to accessing 'conn' array at a negative index.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:46Z" diff --git a/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json b/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json index 2e511d0a343..407baa0ff7f 100644 --- a/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json +++ b/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-592q-r679-2jpc", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:48Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsquashfs: harden sanity check in squashfs_read_xattr_id_table\n\nWhile mounting a corrupted filesystem, a signed integer '*xattr_ids' can\nbecome less than zero. This leads to the incorrect computation of 'len'\nand 'indexes' values which can cause null-ptr-deref in copy_bio_to_actor()\nor out-of-bounds accesses in the next sanity checks inside\nsquashfs_read_xattr_id_table().\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:45Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json b/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json index 6b6930a6ee5..5ba526d1ece 100644 --- a/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json +++ b/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rg6-fchv-4f55", - "modified": "2025-03-28T18:33:11Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:23Z", "aliases": [ "CVE-2025-28135" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28135" }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28135.md" + }, { "type": "WEB", "url": "https://sudsy-eyeliner-a59.notion.site/BufferOverflow-V4-1-2cu-5182_B20201026-19872b8cd95f80808902fac8449fee64" diff --git a/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json b/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json index 00b59277aed..c27f5d60fa0 100644 --- a/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json +++ b/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6gh5-4fvc-rw6c", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52938" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Don't attempt to resume the ports before they exist\n\nThis will fix null pointer dereference that was caused by\nthe driver attempting to resume ports that were not yet\nregistered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json b/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json index f7d982a5ab6..a35aae2e12a 100644 --- a/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json +++ b/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7m9p-x22p-v2hg", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:47Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52978" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: kprobe: Fixup kernel panic when probing an illegal position\n\nThe kernel would panic when probed for an illegal position. eg:\n\n(CONFIG_RISCV_ISA_C=n)\n\necho 'p:hello kernel_clone+0x16 a0=%a0' >> kprobe_events\necho 1 > events/kprobes/hello/enable\ncat trace\n\nKernel panic - not syncing: stack-protector: Kernel stack\nis corrupted in: __do_sys_newfstatat+0xb8/0xb8\nCPU: 0 PID: 111 Comm: sh Not tainted\n6.2.0-rc1-00027-g2d398fe49a4d #490\nHardware name: riscv-virtio,qemu (DT)\nCall Trace:\n[] dump_backtrace+0x38/0x48\n[] show_stack+0x50/0x68\n[] dump_stack_lvl+0x60/0x84\n[] dump_stack+0x20/0x30\n[] panic+0x160/0x374\n[] generic_handle_arch_irq+0x0/0xa8\n[] sys_newstat+0x0/0x30\n[] sys_clone+0x20/0x30\n[] ret_from_syscall+0x0/0x4\n---[ end Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: __do_sys_newfstatat+0xb8/0xb8 ]---\n\nThat is because the kprobe's ebreak instruction broke the kernel's\noriginal code. The user should guarantee the correction of the probe\nposition, but it couldn't make the kernel panic.\n\nThis patch adds arch_check_kprobe in arch_prepare_kprobe to prevent an\nillegal position (Such as the middle of an instruction).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json b/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json index 5b95d3721d1..237ad04a263 100644 --- a/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json +++ b/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7r4r-7wg2-96vj", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:48Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52984" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: dp83822: Fix null pointer access on DP83825/DP83826 devices\n\nThe probe() function is only used for the DP83822 PHY, leaving the\nprivate data pointer uninitialized for the smaller DP83825/26 models.\nWhile all uses of the private data structure are hidden in 82822 specific\ncallbacks, configuring the interrupt is shared across all models.\nThis causes a NULL pointer dereference on the smaller PHYs as it accesses\nthe private data unchecked. Verifying the pointer avoids that.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:45Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json b/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json index e95d4764bdc..c4f717cb891 100644 --- a/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json +++ b/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9h2w-crmf-mr2p", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52991" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer in skb_segment_list\n\nCommit 3a1296a38d0c (\"net: Support GRO/GSO fraglist chaining.\")\nintroduced UDP listifyed GRO. The segmentation relies on frag_list being\nuntouched when passing through the network stack. This assumption can be\nbroken sometimes, where frag_list itself gets pulled into linear area,\nleaving frag_list being NULL. When this happens it can trigger\nfollowing NULL pointer dereference, and panic the kernel. Reverse the\ntest condition should fix it.\n\n[19185.577801][ C1] BUG: kernel NULL pointer dereference, address:\n...\n[19185.663775][ C1] RIP: 0010:skb_segment_list+0x1cc/0x390\n...\n[19185.834644][ C1] Call Trace:\n[19185.841730][ C1] \n[19185.848563][ C1] __udp_gso_segment+0x33e/0x510\n[19185.857370][ C1] inet_gso_segment+0x15b/0x3e0\n[19185.866059][ C1] skb_mac_gso_segment+0x97/0x110\n[19185.874939][ C1] __skb_gso_segment+0xb2/0x160\n[19185.883646][ C1] udp_queue_rcv_skb+0xc3/0x1d0\n[19185.892319][ C1] udp_unicast_rcv_skb+0x75/0x90\n[19185.900979][ C1] ip_protocol_deliver_rcu+0xd2/0x200\n[19185.910003][ C1] ip_local_deliver_finish+0x44/0x60\n[19185.918757][ C1] __netif_receive_skb_one_core+0x8b/0xa0\n[19185.927834][ C1] process_backlog+0x88/0x130\n[19185.935840][ C1] __napi_poll+0x27/0x150\n[19185.943447][ C1] net_rx_action+0x27e/0x5f0\n[19185.951331][ C1] ? mlx5_cq_tasklet_cb+0x70/0x160 [mlx5_core]\n[19185.960848][ C1] __do_softirq+0xbc/0x25d\n[19185.968607][ C1] irq_exit_rcu+0x83/0xb0\n[19185.976247][ C1] common_interrupt+0x43/0xa0\n[19185.984235][ C1] asm_common_interrupt+0x22/0x40\n...\n[19186.094106][ C1] ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:46Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json b/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json index 4f51910ab33..9fbcde33769 100644 --- a/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json +++ b/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx88-897w-ccgj", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:47Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52976" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: fix potential NULL deref in efi_mem_reserve_persistent\n\nWhen iterating on a linked list, a result of memremap is dereferenced\nwithout checking it for NULL.\n\nThis patch adds a check that falls back on allocating a new page in\ncase memremap doesn't succeed.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[ardb: return -ENOMEM instead of breaking out of the loop]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json b/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json index 9a074056e22..bba79209304 100644 --- a/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json +++ b/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7hp-hfwm-x3rp", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52993" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/i8259: Mark legacy PIC interrupts with IRQ_LEVEL\n\nBaoquan reported that after triggering a crash the subsequent crash-kernel\nfails to boot about half of the time. It triggers a NULL pointer\ndereference in the periodic tick code.\n\nThis happens because the legacy timer interrupt (IRQ0) is resent in\nsoftware which happens in soft interrupt (tasklet) context. In this context\nget_irq_regs() returns NULL which leads to the NULL pointer dereference.\n\nThe reason for the resend is a spurious APIC interrupt on the IRQ0 vector\nwhich is captured and leads to a resend when the legacy timer interrupt is\nenabled. This is wrong because the legacy PIC interrupts are level\ntriggered and therefore should never be resent in software, but nothing\never sets the IRQ_LEVEL flag on those interrupts, so the core code does not\nknow about their trigger type.\n\nEnsure that IRQ_LEVEL is set when the legacy PCI interrupts are set up.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:46Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json b/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json index c970e8a48b7..a4c5ede06ff 100644 --- a/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json +++ b/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmm6-5vw5-42h2", - "modified": "2025-03-28T18:33:11Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:23Z", "aliases": [ "CVE-2025-28138" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28138" }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28138.md" + }, { "type": "WEB", "url": "https://sudsy-eyeliner-a59.notion.site/RCE2-1ac72b8cd95f8055a76ee0ca262aac1a?pvs=4" diff --git a/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json b/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json index 7fc879621e3..b2ca88fdd2d 100644 --- a/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json +++ b/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhxv-jq7p-9qhc", - "modified": "2025-03-27T18:31:24Z", + "modified": "2025-04-15T15:30:47Z", "published": "2025-03-27T18:31:24Z", "aliases": [ "CVE-2022-49759" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Use threaded irqs instead of tasklets\n\nThe vmci_dispatch_dgs() tasklet function calls vmci_read_data()\nwhich uses wait_event() resulting in invalid sleep in an atomic\ncontext (and therefore potentially in a deadlock).\n\nUse threaded irqs to fix this issue and completely remove usage\nof tasklets.\n\n[ 20.264639] BUG: sleeping function called from invalid context at drivers/misc/vmw_vmci/vmci_guest.c:145\n[ 20.264643] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 762, name: vmtoolsd\n[ 20.264645] preempt_count: 101, expected: 0\n[ 20.264646] RCU nest depth: 0, expected: 0\n[ 20.264647] 1 lock held by vmtoolsd/762:\n[ 20.264648] #0: ffff0000874ae440 (sk_lock-AF_VSOCK){+.+.}-{0:0}, at: vsock_connect+0x60/0x330 [vsock]\n[ 20.264658] Preemption disabled at:\n[ 20.264659] [] vmci_send_datagram+0x44/0xa0 [vmw_vmci]\n[ 20.264665] CPU: 0 PID: 762 Comm: vmtoolsd Not tainted 5.19.0-0.rc8.20220727git39c3c396f813.60.fc37.aarch64 #1\n[ 20.264667] Hardware name: VMware, Inc. VBSA/VBSA, BIOS VEFI 12/31/2020\n[ 20.264668] Call trace:\n[ 20.264669] dump_backtrace+0xc4/0x130\n[ 20.264672] show_stack+0x24/0x80\n[ 20.264673] dump_stack_lvl+0x88/0xb4\n[ 20.264676] dump_stack+0x18/0x34\n[ 20.264677] __might_resched+0x1a0/0x280\n[ 20.264679] __might_sleep+0x58/0x90\n[ 20.264681] vmci_read_data+0x74/0x120 [vmw_vmci]\n[ 20.264683] vmci_dispatch_dgs+0x64/0x204 [vmw_vmci]\n[ 20.264686] tasklet_action_common.constprop.0+0x13c/0x150\n[ 20.264688] tasklet_action+0x40/0x50\n[ 20.264689] __do_softirq+0x23c/0x6b4\n[ 20.264690] __irq_exit_rcu+0x104/0x214\n[ 20.264691] irq_exit_rcu+0x1c/0x50\n[ 20.264693] el1_interrupt+0x38/0x6c\n[ 20.264695] el1h_64_irq_handler+0x18/0x24\n[ 20.264696] el1h_64_irq+0x68/0x6c\n[ 20.264697] preempt_count_sub+0xa4/0xe0\n[ 20.264698] _raw_spin_unlock_irqrestore+0x64/0xb0\n[ 20.264701] vmci_send_datagram+0x7c/0xa0 [vmw_vmci]\n[ 20.264703] vmci_datagram_dispatch+0x84/0x100 [vmw_vmci]\n[ 20.264706] vmci_datagram_send+0x2c/0x40 [vmw_vmci]\n[ 20.264709] vmci_transport_send_control_pkt+0xb8/0x120 [vmw_vsock_vmci_transport]\n[ 20.264711] vmci_transport_connect+0x40/0x7c [vmw_vsock_vmci_transport]\n[ 20.264713] vsock_connect+0x278/0x330 [vsock]\n[ 20.264715] __sys_connect_file+0x8c/0xc0\n[ 20.264718] __sys_connect+0x84/0xb4\n[ 20.264720] __arm64_sys_connect+0x2c/0x3c\n[ 20.264721] invoke_syscall+0x78/0x100\n[ 20.264723] el0_svc_common.constprop.0+0x68/0x124\n[ 20.264724] do_el0_svc+0x38/0x4c\n[ 20.264725] el0_svc+0x60/0x180\n[ 20.264726] el0t_64_sync_handler+0x11c/0x150\n[ 20.264728] el0t_64_sync+0x190/0x194", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json b/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json index 8943798618b..83f58563800 100644 --- a/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json +++ b/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mq3c-v59w-hjf6", - "modified": "2025-03-27T18:31:27Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-03-27T18:31:27Z", "aliases": [ "CVE-2023-53001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/drm_vma_manager: Add drm_vma_node_allow_once()\n\nCurrently there is no easy way for a drm driver to safely check and allow\ndrm_vma_offset_node for a drm file just once. Allow drm drivers to call\nnon-refcounted version of drm_vma_node_allow() so that a driver doesn't\nneed to keep track of each drm_vma_node_allow() to call subsequent\ndrm_vma_node_revoke() to prevent memory leak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:48Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json b/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json index 2d34ab86227..022b7b29f29 100644 --- a/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json +++ b/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p579-25jc-wxr5", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52939" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath()\n\nAs commit 18365225f044 (\"hwpoison, memcg: forcibly uncharge LRU pages\"),\nhwpoison will forcibly uncharg a LRU hwpoisoned page, the folio_memcg\ncould be NULl, then, mem_cgroup_track_foreign_dirty_slowpath() could\noccurs a NULL pointer dereference, let's do not record the foreign\nwritebacks for folio memcg is null in mem_cgroup_track_foreign_dirty() to\nfix it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json b/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json index 03879bcd87b..235e654b996 100644 --- a/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json +++ b/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pwg3-m7h4-xjvm", - "modified": "2025-03-27T18:31:24Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:24Z", "aliases": [ "CVE-2022-49758" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nreset: uniphier-glue: Fix possible null-ptr-deref\n\nIt will cause null-ptr-deref when resource_size(res) invoked,\nif platform_get_resource() returns NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json index 0b22b5c8f70..b49166a7972 100644 --- a/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json +++ b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q87j-52xg-48j5", - "modified": "2025-04-01T21:30:46Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-03-28T21:30:47Z", "aliases": [ "CVE-2025-22953" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22953" }, + { + "type": "WEB", + "url": "https://github.com/maliktawfiq/CVE-2025-22953" + }, { "type": "WEB", "url": "https://tinted-hollyhock-92d.notion.site/EPICOR-HCM-Unauthenticated-Blind-SQL-Injection-CVE-2025-22953-170f1fdee211803988d1c9255a8cb904?pvs=4" + }, + { + "type": "WEB", + "url": "https://www.epiusers.help/t/alert-hcm-security-patch/124777" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json b/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json index feab90c7cab..4f97e2491ef 100644 --- a/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json +++ b/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv94-9c4f-29wh", - "modified": "2025-03-27T18:31:26Z", + "modified": "2025-04-15T15:30:47Z", "published": "2025-03-27T18:31:26Z", "aliases": [ "CVE-2023-52977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix flow memory leak in ovs_flow_cmd_new\n\nSyzkaller reports a memory leak of new_flow in ovs_flow_cmd_new() as it is\nnot freed when an allocation of a key fails.\n\nBUG: memory leak\nunreferenced object 0xffff888116668000 (size 632):\n comm \"syz-executor231\", pid 1090, jiffies 4294844701 (age 18.871s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000defa3494>] kmem_cache_zalloc include/linux/slab.h:654 [inline]\n [<00000000defa3494>] ovs_flow_alloc+0x19/0x180 net/openvswitch/flow_table.c:77\n [<00000000c67d8873>] ovs_flow_cmd_new+0x1de/0xd40 net/openvswitch/datapath.c:957\n [<0000000010a539a8>] genl_family_rcv_msg_doit+0x22d/0x330 net/netlink/genetlink.c:739\n [<00000000dff3302d>] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline]\n [<00000000dff3302d>] genl_rcv_msg+0x328/0x590 net/netlink/genetlink.c:800\n [<000000000286dd87>] netlink_rcv_skb+0x153/0x430 net/netlink/af_netlink.c:2515\n [<0000000061fed410>] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811\n [<000000009dc0f111>] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n [<000000009dc0f111>] netlink_unicast+0x545/0x7f0 net/netlink/af_netlink.c:1339\n [<000000004a5ee816>] netlink_sendmsg+0x8e7/0xde0 net/netlink/af_netlink.c:1934\n [<00000000482b476f>] sock_sendmsg_nosec net/socket.c:651 [inline]\n [<00000000482b476f>] sock_sendmsg+0x152/0x190 net/socket.c:671\n [<00000000698574ba>] ____sys_sendmsg+0x70a/0x870 net/socket.c:2356\n [<00000000d28d9e11>] ___sys_sendmsg+0xf3/0x170 net/socket.c:2410\n [<0000000083ba9120>] __sys_sendmsg+0xe5/0x1b0 net/socket.c:2439\n [<00000000c00628f8>] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46\n [<000000004abfdcf4>] entry_SYSCALL_64_after_hwframe+0x61/0xc6\n\nTo fix this the patch rearranges the goto labels to reflect the order of\nobject allocations and adds appropriate goto statements on the error\npaths.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json b/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json index 5087bfbaaa4..34a23bc9c0d 100644 --- a/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json +++ b/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x768-g2cv-hv4j", - "modified": "2025-03-27T18:31:27Z", + "modified": "2025-04-15T15:30:49Z", "published": "2025-03-27T18:31:27Z", "aliases": [ "CVE-2023-52989" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: fix memory leak for payload of request subaction to IEC 61883-1 FCP region\n\nThis patch is fix for Linux kernel v2.6.33 or later.\n\nFor request subaction to IEC 61883-1 FCP region, Linux FireWire subsystem\nhave had an issue of use-after-free. The subsystem allows multiple\nuser space listeners to the region, while data of the payload was likely\nreleased before the listeners execute read(2) to access to it for copying\nto user space.\n\nThe issue was fixed by a commit 281e20323ab7 (\"firewire: core: fix\nuse-after-free regression in FCP handler\"). The object of payload is\nduplicated in kernel space for each listener. When the listener executes\nioctl(2) with FW_CDEV_IOC_SEND_RESPONSE request, the object is going to\nbe released.\n\nHowever, it causes memory leak since the commit relies on call of\nrelease_request() in drivers/firewire/core-cdev.c. Against the\nexpectation, the function is never called due to the design of\nrelease_client_resource(). The function delegates release task\nto caller when called with non-NULL fourth argument. The implementation\nof ioctl_send_response() is the case. It should release the object\nexplicitly.\n\nThis commit fixes the bug.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:46Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json b/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json index 49739c22d98..f9b74b298b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json +++ b/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xvxr-rrxw-rfp9", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T15:30:46Z", "published": "2025-03-27T18:31:24Z", "aliases": [ "CVE-2022-49757" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/highbank: Fix memory leak in highbank_mc_probe()\n\nWhen devres_open_group() fails, it returns -ENOMEM without freeing memory\nallocated by edac_mc_alloc().\n\nCall edac_mc_free() on the error handling path to avoid a memory leak.\n\n [ bp: Massage commit message. ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:40Z" diff --git a/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json b/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json new file mode 100644 index 00000000000..522c5497bdf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24hh-5wmw-c8j8", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-29280" + ], + "details": "Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29280" + }, + { + "type": "WEB", + "url": "https://github.com/Cray0nLee/CVE/issues/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json index 55dfe7ff86f..7fc2541d9db 100644 --- a/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json +++ b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24vc-7q35-w5rv", - "modified": "2025-04-15T06:30:34Z", + "modified": "2025-04-15T15:30:53Z", "published": "2025-04-15T06:30:34Z", "aliases": [ "CVE-2024-13207" ], "details": "The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T06:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3w69-j4hp-rvh4/GHSA-3w69-j4hp-rvh4.json b/advisories/unreviewed/2025/04/GHSA-3w69-j4hp-rvh4/GHSA-3w69-j4hp-rvh4.json new file mode 100644 index 00000000000..d9cfb4cb9e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w69-j4hp-rvh4/GHSA-3w69-j4hp-rvh4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w69-j4hp-rvh4", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32947" + ], + "details": "This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the \"inbox\" endpoint when receiving crafted ActivityPub activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32947" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-activitypub-crawl-dos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json b/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json new file mode 100644 index 00000000000..022a21241d6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h7q-pj8m-5675", + "modified": "2025-04-15T15:30:54Z", + "published": "2025-04-15T15:30:54Z", + "aliases": [ + "CVE-2025-3523" + ], + "details": "When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3523" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1958385" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-26" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4p7q-hmcp-j657/GHSA-4p7q-hmcp-j657.json b/advisories/unreviewed/2025/04/GHSA-4p7q-hmcp-j657/GHSA-4p7q-hmcp-j657.json new file mode 100644 index 00000000000..c208989bb3a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4p7q-hmcp-j657/GHSA-4p7q-hmcp-j657.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p7q-hmcp-j657", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32102" + ], + "details": "CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32102" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190460" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2025/Apr/17" + }, + { + "type": "WEB", + "url": "https://www.crushftp.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xpq-mc4q-22p9/GHSA-5xpq-mc4q-22p9.json b/advisories/unreviewed/2025/04/GHSA-5xpq-mc4q-22p9/GHSA-5xpq-mc4q-22p9.json new file mode 100644 index 00000000000..e40cd3fee85 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xpq-mc4q-22p9/GHSA-5xpq-mc4q-22p9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xpq-mc4q-22p9", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28142" + ], + "details": "Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28142" + }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/fb033d40b9d0245c36e520eeb34b7e76" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6f46-45q7-4jx2/GHSA-6f46-45q7-4jx2.json b/advisories/unreviewed/2025/04/GHSA-6f46-45q7-4jx2/GHSA-6f46-45q7-4jx2.json new file mode 100644 index 00000000000..45e57b6b63a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6f46-45q7-4jx2/GHSA-6f46-45q7-4jx2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f46-45q7-4jx2", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32946" + ], + "details": "This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32946" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-arbitrary-playlist-creation-activitypub" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json new file mode 100644 index 00000000000..cacfbdc02df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rrc-vwrv-cwxc", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-3608" + ], + "details": "A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3608" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1951554" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2025-3608" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-25" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7768-6597-437r/GHSA-7768-6597-437r.json b/advisories/unreviewed/2025/04/GHSA-7768-6597-437r/GHSA-7768-6597-437r.json index 24a6ff85e92..9b2e4beb32c 100644 --- a/advisories/unreviewed/2025/04/GHSA-7768-6597-437r/GHSA-7768-6597-437r.json +++ b/advisories/unreviewed/2025/04/GHSA-7768-6597-437r/GHSA-7768-6597-437r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7768-6597-437r", - "modified": "2025-04-02T03:31:43Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-02T03:31:43Z", "aliases": [ "CVE-2025-3073" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T01:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-78fw-w53r-pgwg/GHSA-78fw-w53r-pgwg.json b/advisories/unreviewed/2025/04/GHSA-78fw-w53r-pgwg/GHSA-78fw-w53r-pgwg.json new file mode 100644 index 00000000000..7b2ff94d8cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-78fw-w53r-pgwg/GHSA-78fw-w53r-pgwg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78fw-w53r-pgwg", + "modified": "2025-04-15T15:30:54Z", + "published": "2025-04-15T15:30:54Z", + "aliases": [ + "CVE-2025-3522" + ], + "details": "Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3522" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1955372" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-26" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89c2-gvr7-7r9w/GHSA-89c2-gvr7-7r9w.json b/advisories/unreviewed/2025/04/GHSA-89c2-gvr7-7r9w/GHSA-89c2-gvr7-7r9w.json new file mode 100644 index 00000000000..c6565bcc5da --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89c2-gvr7-7r9w/GHSA-89c2-gvr7-7r9w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89c2-gvr7-7r9w", + "modified": "2025-04-15T15:30:54Z", + "published": "2025-04-15T15:30:54Z", + "aliases": [ + "CVE-2025-32949" + ], + "details": "This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb. \n\nIf user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. The yauzl library does not contain any mechanism to detect or prevent extraction of a Zip Bomb https://en.wikipedia.org/wiki/Zip_bomb . Therefore, when using the User Import functionality with a Zip Bomb, PeerTube will try extracting the archive which will cause a disk space resource exhaustion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32949" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-archive-resource-exhaustion" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-409" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94cq-g9vr-5q43/GHSA-94cq-g9vr-5q43.json b/advisories/unreviewed/2025/04/GHSA-94cq-g9vr-5q43/GHSA-94cq-g9vr-5q43.json new file mode 100644 index 00000000000..5feee23f1a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94cq-g9vr-5q43/GHSA-94cq-g9vr-5q43.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94cq-g9vr-5q43", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32103" + ], + "details": "CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32103" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190460" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2025/Apr/17" + }, + { + "type": "WEB", + "url": "https://www.crushftp.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-40" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9gxm-gppf-g7cc/GHSA-9gxm-gppf-g7cc.json b/advisories/unreviewed/2025/04/GHSA-9gxm-gppf-g7cc/GHSA-9gxm-gppf-g7cc.json new file mode 100644 index 00000000000..9a27ab85e61 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gxm-gppf-g7cc/GHSA-9gxm-gppf-g7cc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gxm-gppf-g7cc", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32945" + ], + "details": "The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32945" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-arbitrary-playlist-creation-rest" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9m7f-jxmp-5q59/GHSA-9m7f-jxmp-5q59.json b/advisories/unreviewed/2025/04/GHSA-9m7f-jxmp-5q59/GHSA-9m7f-jxmp-5q59.json index 034f1e8ad74..cf57161b90e 100644 --- a/advisories/unreviewed/2025/04/GHSA-9m7f-jxmp-5q59/GHSA-9m7f-jxmp-5q59.json +++ b/advisories/unreviewed/2025/04/GHSA-9m7f-jxmp-5q59/GHSA-9m7f-jxmp-5q59.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json b/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json index 915f532d4d4..5a35f087092 100644 --- a/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json +++ b/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9qmr-4gv6-xmf3", - "modified": "2025-04-03T00:31:32Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-03T00:31:32Z", "aliases": [ "CVE-2025-3129" ], "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-307" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T22:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json b/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json index b755afdd1ec..3f90126501f 100644 --- a/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json +++ b/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmcg-w67x-52f7", - "modified": "2025-04-04T18:30:55Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-04T18:30:55Z", "aliases": [ "CVE-2025-25178" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-04T16:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f6c5-v8pr-pwg7/GHSA-f6c5-v8pr-pwg7.json b/advisories/unreviewed/2025/04/GHSA-f6c5-v8pr-pwg7/GHSA-f6c5-v8pr-pwg7.json new file mode 100644 index 00000000000..3bd26093c17 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6c5-v8pr-pwg7/GHSA-f6c5-v8pr-pwg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6c5-v8pr-pwg7", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-29281" + ], + "details": "In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29281" + }, + { + "type": "WEB", + "url": "https://github.com/Cray0nLee/CVE/issues/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json b/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json new file mode 100644 index 00000000000..a2fb3a734f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fchw-692r-4w73", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28137" + ], + "details": "The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28137" + }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md" + }, + { + "type": "WEB", + "url": "https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv46-7jp9-m2p3/GHSA-fv46-7jp9-m2p3.json b/advisories/unreviewed/2025/04/GHSA-fv46-7jp9-m2p3/GHSA-fv46-7jp9-m2p3.json new file mode 100644 index 00000000000..76643ff8050 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fv46-7jp9-m2p3/GHSA-fv46-7jp9-m2p3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv46-7jp9-m2p3", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28145" + ], + "details": "Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28145" + }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/cee49ede0f576447cc4b1bb078e7a981" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fvpc-gqmr-784w/GHSA-fvpc-gqmr-784w.json b/advisories/unreviewed/2025/04/GHSA-fvpc-gqmr-784w/GHSA-fvpc-gqmr-784w.json new file mode 100644 index 00000000000..031b7fc8e72 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fvpc-gqmr-784w/GHSA-fvpc-gqmr-784w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvpc-gqmr-784w", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32944" + ], + "details": "The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32944" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-archive-persistent-dos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g6gh-87cw-x396/GHSA-g6gh-87cw-x396.json b/advisories/unreviewed/2025/04/GHSA-g6gh-87cw-x396/GHSA-g6gh-87cw-x396.json new file mode 100644 index 00000000000..a81b76a1bba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6gh-87cw-x396/GHSA-g6gh-87cw-x396.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6gh-87cw-x396", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-2830" + ], + "details": "By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2830" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1956379" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-26" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h26x-295r-3cj4/GHSA-h26x-295r-3cj4.json b/advisories/unreviewed/2025/04/GHSA-h26x-295r-3cj4/GHSA-h26x-295r-3cj4.json index f48919bcaa9..c9ed898dc52 100644 --- a/advisories/unreviewed/2025/04/GHSA-h26x-295r-3cj4/GHSA-h26x-295r-3cj4.json +++ b/advisories/unreviewed/2025/04/GHSA-h26x-295r-3cj4/GHSA-h26x-295r-3cj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h26x-295r-3cj4", - "modified": "2025-04-02T03:31:43Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-02T03:31:43Z", "aliases": [ "CVE-2025-3074" ], "details": "Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T01:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h44c-2324-c88q/GHSA-h44c-2324-c88q.json b/advisories/unreviewed/2025/04/GHSA-h44c-2324-c88q/GHSA-h44c-2324-c88q.json index 5942b9e1b01..d73888a0078 100644 --- a/advisories/unreviewed/2025/04/GHSA-h44c-2324-c88q/GHSA-h44c-2324-c88q.json +++ b/advisories/unreviewed/2025/04/GHSA-h44c-2324-c88q/GHSA-h44c-2324-c88q.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json b/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json index 0c704f9793b..884e2d50719 100644 --- a/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json +++ b/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json index dad6abb9bba..6b4d0c29194 100644 --- a/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json +++ b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcc3-vmjf-jfhj", - "modified": "2025-04-15T06:30:34Z", + "modified": "2025-04-15T15:30:53Z", "published": "2025-04-15T06:30:34Z", "aliases": [ "CVE-2024-13610" ], "details": "The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T06:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jhgf-xqjm-37vh/GHSA-jhgf-xqjm-37vh.json b/advisories/unreviewed/2025/04/GHSA-jhgf-xqjm-37vh/GHSA-jhgf-xqjm-37vh.json new file mode 100644 index 00000000000..e4d2bf4fd6d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhgf-xqjm-37vh/GHSA-jhgf-xqjm-37vh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhgf-xqjm-37vh", + "modified": "2025-04-15T15:30:54Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-32948" + ], + "details": "The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's \"inbox\" endpoint. By abusing the \"Create Activity\" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32948" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-activitypub-playlist-creation-blind-ssrf-dos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mpvr-j99q-8c2v/GHSA-mpvr-j99q-8c2v.json b/advisories/unreviewed/2025/04/GHSA-mpvr-j99q-8c2v/GHSA-mpvr-j99q-8c2v.json new file mode 100644 index 00000000000..0c0f3d62d97 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mpvr-j99q-8c2v/GHSA-mpvr-j99q-8c2v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpvr-j99q-8c2v", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-27980" + ], + "details": "cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27980" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/qq_52469895/article/details/145496958?sharetype=blogdetail&sharerId=145496958&sharerefer=PC&sharesource=qq_52469895&spm=1011.2480.3001.8118" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pxfj-34h8-mjfc/GHSA-pxfj-34h8-mjfc.json b/advisories/unreviewed/2025/04/GHSA-pxfj-34h8-mjfc/GHSA-pxfj-34h8-mjfc.json new file mode 100644 index 00000000000..ebf5bf0d014 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pxfj-34h8-mjfc/GHSA-pxfj-34h8-mjfc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxfj-34h8-mjfc", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28143" + ], + "details": "Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28143" + }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/885505cda80f81069ba39b11f2f996fc" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json b/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json index a78454719c4..d6b88f649bb 100644 --- a/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json +++ b/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7wx-4c6m-pm7w", - "modified": "2025-04-07T15:31:01Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-04T15:31:17Z", "aliases": [ "CVE-2025-28146" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28146" }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/469a6f2b694a76c3b58249b27fdd0881" + }, { "type": "WEB", "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/3" diff --git a/advisories/unreviewed/2025/04/GHSA-qc9g-vf45-fwfp/GHSA-qc9g-vf45-fwfp.json b/advisories/unreviewed/2025/04/GHSA-qc9g-vf45-fwfp/GHSA-qc9g-vf45-fwfp.json new file mode 100644 index 00000000000..b45ffcec62f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qc9g-vf45-fwfp/GHSA-qc9g-vf45-fwfp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc9g-vf45-fwfp", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28136" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28136" + }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28136.md" + }, + { + "type": "WEB", + "url": "https://sudsy-eyeliner-a59.notion.site/BufferOverflow-V4-1-2cu-5137_B20200730-19872b8cd95f80cf8df9f3abcb912554" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjhj-f8wp-4w4x/GHSA-vjhj-f8wp-4w4x.json b/advisories/unreviewed/2025/04/GHSA-vjhj-f8wp-4w4x/GHSA-vjhj-f8wp-4w4x.json index fcf81cd80c8..0b380c00b45 100644 --- a/advisories/unreviewed/2025/04/GHSA-vjhj-f8wp-4w4x/GHSA-vjhj-f8wp-4w4x.json +++ b/advisories/unreviewed/2025/04/GHSA-vjhj-f8wp-4w4x/GHSA-vjhj-f8wp-4w4x.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-wghf-qmx9-35pp/GHSA-wghf-qmx9-35pp.json b/advisories/unreviewed/2025/04/GHSA-wghf-qmx9-35pp/GHSA-wghf-qmx9-35pp.json index 82ac37a6cbe..c125b17718b 100644 --- a/advisories/unreviewed/2025/04/GHSA-wghf-qmx9-35pp/GHSA-wghf-qmx9-35pp.json +++ b/advisories/unreviewed/2025/04/GHSA-wghf-qmx9-35pp/GHSA-wghf-qmx9-35pp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wghf-qmx9-35pp", - "modified": "2025-04-02T03:31:43Z", + "modified": "2025-04-15T15:30:52Z", "published": "2025-04-02T03:31:43Z", "aliases": [ "CVE-2025-3072" ], "details": "Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T01:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wpg4-89x4-3hj9/GHSA-wpg4-89x4-3hj9.json b/advisories/unreviewed/2025/04/GHSA-wpg4-89x4-3hj9/GHSA-wpg4-89x4-3hj9.json new file mode 100644 index 00000000000..6263a33cbfc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wpg4-89x4-3hj9/GHSA-wpg4-89x4-3hj9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpg4-89x4-3hj9", + "modified": "2025-04-15T15:30:53Z", + "published": "2025-04-15T15:30:53Z", + "aliases": [ + "CVE-2025-28144" + ], + "details": "Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28144" + }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/31a4df78e523635085908ddd4b68d91f" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/edimax_br-6847_v3-%20peerpin_stack_overflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T15:16:08Z" + } +} \ No newline at end of file