Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-04 18:35:13 +00:00
parent ec4b8fd093
commit d654025df5
69 changed files with 1101 additions and 164 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-336f-r8g9-c985",
"modified": "2023-07-17T00:31:54Z",
"modified": "2025-03-04T18:33:18Z",
"published": "2023-07-17T00:31:54Z",
"aliases": [
"CVE-2023-3694"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -30,10 +34,15 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.234245"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.183316"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8crg-9wvr-72vm",
"modified": "2023-12-25T03:30:27Z",
"modified": "2025-03-04T18:33:19Z",
"published": "2023-12-25T03:30:27Z",
"aliases": [
"CVE-2023-7100"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -23,6 +27,10 @@
"type": "WEB",
"url": "https://medium.com/@2839549219ljk/restaurant-table-booking-system-sql-injection-vulnerability-30708cfabe03"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.248952"
@@ -30,10 +38,15 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.248952"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.256861"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjg4-p237-8j88",
"modified": "2024-04-16T00:30:32Z",
"modified": "2025-03-04T18:33:19Z",
"published": "2024-04-16T00:30:32Z",
"aliases": [
"CVE-2024-3493"
],
"details": "\nA specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices. \n\n",
"details": "A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vxw-hpgc-992j",
"modified": "2024-08-14T21:33:12Z",
"modified": "2025-03-04T18:33:22Z",
"published": "2024-08-14T21:33:12Z",
"aliases": [
"CVE-2024-7515"
],
"details": "CVE-2024-7515 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hx72-825v-wv3p",
"modified": "2024-08-14T21:33:12Z",
"modified": "2025-03-04T18:33:21Z",
"published": "2024-08-14T21:33:12Z",
"aliases": [
"CVE-2024-7507"
],
"details": "CVE-2024-7507 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-209",
"CWE-80"
],
"severity": "MODERATE",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"severity": "MODERATE",
File diff suppressed because one or more lines are too long
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h7g-r8hc-vrmp",
"modified": "2025-02-28T18:31:05Z",
"modified": "2025-03-04T18:33:26Z",
"published": "2025-02-28T18:31:05Z",
"aliases": [
"CVE-2025-25431"
],
"details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T18:15:28Z"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhjf-w34g-fcvp",
"modified": "2025-02-27T21:32:16Z",
"modified": "2025-03-04T18:33:26Z",
"published": "2025-02-27T21:32:16Z",
"aliases": [
"CVE-2024-58034"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code()\n\nAs of_find_node_by_name() release the reference of the argument device\nnode, tegra_emc_find_node_by_ram_code() releases some device nodes while\nstill in use, resulting in possible UAFs. According to the bindings and\nthe in-tree DTS files, the \"emc-tables\" node is always device's child\nnode with the property \"nvidia,use-ram-code\", and the \"lpddr2\" node is a\nchild of the \"emc-tables\" node. Thus utilize the\nfor_each_child_of_node() macro and of_get_child_by_name() instead of\nof_find_node_by_name() to simplify the code.\n\nThis bug was found by an experimental verification tool that I am\ndeveloping.\n\n[krzysztof: applied v1, adjust the commit msg to incorporate v2 parts]",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T20:16:02Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2gc-738w-q744",
"modified": "2025-02-27T21:32:17Z",
"modified": "2025-03-04T18:33:26Z",
"published": "2025-02-27T21:32:17Z",
"aliases": [
"CVE-2025-21811"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect access to buffers with no active references\n\nnilfs_lookup_dirty_data_buffers(), which iterates through the buffers\nattached to dirty data folios/pages, accesses the attached buffers without\nlocking the folios/pages.\n\nFor data cache, nilfs_clear_folio_dirty() may be called asynchronously\nwhen the file system degenerates to read only, so\nnilfs_lookup_dirty_data_buffers() still has the potential to cause use\nafter free issues when buffers lose the protection of their dirty state\nmidway due to this asynchronous clearing and are unintentionally freed by\ntry_to_free_buffers().\n\nEliminate this race issue by adjusting the lock section in this function.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T20:16:03Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmf2-mqm7-fcrm",
"modified": "2025-02-28T18:31:05Z",
"modified": "2025-03-04T18:33:26Z",
"published": "2025-02-28T18:31:05Z",
"aliases": [
"CVE-2025-25430"
],
"details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T18:15:28Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whh4-rfqm-vcwg",
"modified": "2025-02-28T21:32:20Z",
"modified": "2025-03-04T18:33:27Z",
"published": "2025-02-28T21:32:20Z",
"aliases": [
"CVE-2025-25428"
],
"details": "TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-259"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-28T19:15:36Z"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59",
"CWE-61"
],
"severity": "MODERATE",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-249w-xh84-97wj",
"modified": "2025-03-04T15:31:50Z",
"modified": "2025-03-04T18:33:42Z",
"published": "2025-03-04T15:31:50Z",
"aliases": [
"CVE-2025-27425"
],
"details": "Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-04T14:15:39Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cxw-wgvv-24jj",
"modified": "2025-03-04T12:30:32Z",
"modified": "2025-03-04T18:33:39Z",
"published": "2025-03-04T12:30:32Z",
"aliases": [
"CVE-2025-22225"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-123"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3297-hxj5-867g",
"modified": "2025-03-04T18:33:43Z",
"published": "2025-03-04T18:33:43Z",
"aliases": [
"CVE-2025-26091"
],
"details": "A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the \"My Passwords\" page.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26091"
},
{
"type": "WEB",
"url": "https://brunocaseiro.github.io/CVE-2025-26091"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-04T17:15:18Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35g5-m5m3-r8mx",
"modified": "2025-03-03T18:31:28Z",
"modified": "2025-03-04T18:33:29Z",
"published": "2025-03-03T18:31:28Z",
"aliases": [
"CVE-2024-53387"
],
"details": "A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-03T17:15:13Z"

Some files were not shown because too many files have changed in this diff Show More