From d654025df510b656faa7153bc30c8d41a4c7e480 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 4 Mar 2025 18:35:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-336f-r8g9-c985.json | 11 ++- .../GHSA-8crg-9wvr-72vm.json | 15 +++- .../GHSA-mjg4-p237-8j88.json | 4 +- .../GHSA-5vxw-hpgc-992j.json | 6 +- .../GHSA-hx72-825v-wv3p.json | 6 +- .../GHSA-2cwp-85p5-6fwc.json | 1 + .../GHSA-466p-j3vq-mwq3.json | 1 + .../GHSA-5qmp-w6rv-24wf.json | 15 ++-- .../GHSA-7qjx-378m-p8hm.json | 1 + .../GHSA-9h7g-r8hc-vrmp.json | 15 ++-- .../GHSA-c52f-45m8-h2r6.json | 3 +- .../GHSA-fhjf-w34g-fcvp.json | 15 ++-- .../GHSA-j2gc-738w-q744.json | 15 ++-- .../GHSA-vmf2-mqm7-fcrm.json | 15 ++-- .../GHSA-whh4-rfqm-vcwg.json | 15 ++-- .../GHSA-xjc3-vjh6-m283.json | 1 + .../GHSA-249w-xh84-97wj.json | 15 ++-- .../GHSA-2cxw-wgvv-24jj.json | 6 +- .../GHSA-3297-hxj5-867g.json | 29 ++++++++ .../GHSA-35g5-m5m3-r8mx.json | 15 ++-- .../GHSA-37f6-vjg7-8c6c.json | 6 +- .../GHSA-3j27-47wq-ghmh.json | 11 ++- .../GHSA-3jxr-23ph-c89g.json | 40 +++++++++++ .../GHSA-3vcg-jhjm-5ffm.json | 40 +++++++++++ .../GHSA-3wj6-xwvq-325w.json | 11 ++- .../GHSA-3xm4-5347-4q37.json | 11 ++- .../GHSA-472p-7734-hxc8.json | 11 ++- .../GHSA-57gw-hcmr-f4g2.json | 15 ++-- .../GHSA-5f86-34xg-qr85.json | 15 ++-- .../GHSA-6f5q-x637-6prf.json | 68 +++++++++++++++++++ .../GHSA-6pcr-45mv-9gp3.json | 15 ++-- .../GHSA-6pg6-qhjj-4wcm.json | 15 ++-- .../GHSA-73jf-w7j4-5h24.json | 15 ++-- .../GHSA-7mf9-x65f-jwgf.json | 15 ++-- .../GHSA-8454-mw8r-4mjq.json | 15 ++-- .../GHSA-8f76-x9r8-c3c2.json | 15 ++-- .../GHSA-8j8g-6gw9-rjrf.json | 6 +- .../GHSA-9926-q228-4mpp.json | 11 ++- .../GHSA-9xc8-27jp-6jj2.json | 15 ++-- .../GHSA-c22c-4xww-2fqr.json | 15 ++-- .../GHSA-c3p2-xw2j-qrf4.json | 11 ++- .../GHSA-c6wg-m9gg-2cg8.json | 68 +++++++++++++++++++ .../GHSA-cchf-xm65-f24c.json | 36 ++++++++++ .../GHSA-cx28-78m7-h38f.json | 15 ++-- .../GHSA-f7qf-3422-vc6q.json | 15 ++-- .../GHSA-fj56-7h2j-m3p3.json | 29 ++++++++ .../GHSA-g468-6jvw-w4j4.json | 15 ++-- .../GHSA-g93r-3jrg-24gc.json | 15 ++-- .../GHSA-gqx4-7r84-32m6.json | 15 ++-- .../GHSA-h267-996p-9gjc.json | 15 ++-- .../GHSA-j652-46fv-w96g.json | 6 +- .../GHSA-jxrq-h53g-x3qx.json | 36 ++++++++++ .../GHSA-m2rp-964h-h237.json | 15 ++-- .../GHSA-m3r4-hpjv-ph84.json | 48 +++++++++++++ .../GHSA-m5wp-346p-h7x3.json | 36 ++++++++++ .../GHSA-m793-xp46-r76w.json | 15 ++-- .../GHSA-m8x3-4xx7-hm4v.json | 15 ++-- .../GHSA-pf5c-w647-wm56.json | 48 +++++++++++++ .../GHSA-q9q9-pv7p-h33j.json | 37 ++++++++++ .../GHSA-qqm4-w34f-whgp.json | 15 ++-- .../GHSA-r7pc-h4wr-xggx.json | 15 ++-- .../GHSA-r83v-rmq7-r5m4.json | 15 ++-- .../GHSA-r84f-4wj3-r6vx.json | 15 ++-- .../GHSA-r9qc-pq8g-x74p.json | 40 +++++++++++ .../GHSA-rvh7-h8xh-g43v.json | 4 +- .../GHSA-rwg9-3gf9-vx76.json | 40 +++++++++++ .../GHSA-vqx8-mvcx-mx39.json | 15 ++-- .../GHSA-wm67-cvpp-xg5f.json | 36 ++++++++++ .../GHSA-xx4g-62m6-v2w7.json | 11 ++- 69 files changed, 1101 insertions(+), 164 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-3297-hxj5-867g/GHSA-3297-hxj5-867g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3jxr-23ph-c89g/GHSA-3jxr-23ph-c89g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3vcg-jhjm-5ffm/GHSA-3vcg-jhjm-5ffm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6f5q-x637-6prf/GHSA-6f5q-x637-6prf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c6wg-m9gg-2cg8/GHSA-c6wg-m9gg-2cg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jxrq-h53g-x3qx/GHSA-jxrq-h53g-x3qx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m3r4-hpjv-ph84/GHSA-m3r4-hpjv-ph84.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m5wp-346p-h7x3/GHSA-m5wp-346p-h7x3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pf5c-w647-wm56/GHSA-pf5c-w647-wm56.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r9qc-pq8g-x74p/GHSA-r9qc-pq8g-x74p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rwg9-3gf9-vx76/GHSA-rwg9-3gf9-vx76.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wm67-cvpp-xg5f/GHSA-wm67-cvpp-xg5f.json diff --git a/advisories/unreviewed/2023/07/GHSA-336f-r8g9-c985/GHSA-336f-r8g9-c985.json b/advisories/unreviewed/2023/07/GHSA-336f-r8g9-c985/GHSA-336f-r8g9-c985.json index 9c78f6b21a0..4f09cf46389 100644 --- a/advisories/unreviewed/2023/07/GHSA-336f-r8g9-c985/GHSA-336f-r8g9-c985.json +++ b/advisories/unreviewed/2023/07/GHSA-336f-r8g9-c985/GHSA-336f-r8g9-c985.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-336f-r8g9-c985", - "modified": "2023-07-17T00:31:54Z", + "modified": "2025-03-04T18:33:18Z", "published": "2023-07-17T00:31:54Z", "aliases": [ "CVE-2023-3694" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -30,10 +34,15 @@ { "type": "WEB", "url": "https://vuldb.com/?id.234245" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.183316" } ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/12/GHSA-8crg-9wvr-72vm/GHSA-8crg-9wvr-72vm.json b/advisories/unreviewed/2023/12/GHSA-8crg-9wvr-72vm/GHSA-8crg-9wvr-72vm.json index 141d33d39e3..38b193de7b6 100644 --- a/advisories/unreviewed/2023/12/GHSA-8crg-9wvr-72vm/GHSA-8crg-9wvr-72vm.json +++ b/advisories/unreviewed/2023/12/GHSA-8crg-9wvr-72vm/GHSA-8crg-9wvr-72vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8crg-9wvr-72vm", - "modified": "2023-12-25T03:30:27Z", + "modified": "2025-03-04T18:33:19Z", "published": "2023-12-25T03:30:27Z", "aliases": [ "CVE-2023-7100" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -23,6 +27,10 @@ "type": "WEB", "url": "https://medium.com/@2839549219ljk/restaurant-table-booking-system-sql-injection-vulnerability-30708cfabe03" }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.248952" @@ -30,10 +38,15 @@ { "type": "WEB", "url": "https://vuldb.com/?id.248952" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.256861" } ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-mjg4-p237-8j88/GHSA-mjg4-p237-8j88.json b/advisories/unreviewed/2024/04/GHSA-mjg4-p237-8j88/GHSA-mjg4-p237-8j88.json index 4cd5ca30f30..29719c24ec5 100644 --- a/advisories/unreviewed/2024/04/GHSA-mjg4-p237-8j88/GHSA-mjg4-p237-8j88.json +++ b/advisories/unreviewed/2024/04/GHSA-mjg4-p237-8j88/GHSA-mjg4-p237-8j88.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mjg4-p237-8j88", - "modified": "2024-04-16T00:30:32Z", + "modified": "2025-03-04T18:33:19Z", "published": "2024-04-16T00:30:32Z", "aliases": [ "CVE-2024-3493" ], - "details": "\nA specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices. \n\n", + "details": "A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json b/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json index 79162c8bf86..1b5db856353 100644 --- a/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json +++ b/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vxw-hpgc-992j", - "modified": "2024-08-14T21:33:12Z", + "modified": "2025-03-04T18:33:22Z", "published": "2024-08-14T21:33:12Z", "aliases": [ "CVE-2024-7515" ], "details": "CVE-2024-7515 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json b/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json index c09ba16c3d1..b319cac9676 100644 --- a/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json +++ b/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx72-825v-wv3p", - "modified": "2024-08-14T21:33:12Z", + "modified": "2025-03-04T18:33:21Z", "published": "2024-08-14T21:33:12Z", "aliases": [ "CVE-2024-7507" ], "details": "CVE-2024-7507 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-2cwp-85p5-6fwc/GHSA-2cwp-85p5-6fwc.json b/advisories/unreviewed/2025/01/GHSA-2cwp-85p5-6fwc/GHSA-2cwp-85p5-6fwc.json index a040b1243f7..61ec26c288b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2cwp-85p5-6fwc/GHSA-2cwp-85p5-6fwc.json +++ b/advisories/unreviewed/2025/01/GHSA-2cwp-85p5-6fwc/GHSA-2cwp-85p5-6fwc.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-209", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-466p-j3vq-mwq3/GHSA-466p-j3vq-mwq3.json b/advisories/unreviewed/2025/01/GHSA-466p-j3vq-mwq3/GHSA-466p-j3vq-mwq3.json index 603d2370a02..b169f2a862b 100644 --- a/advisories/unreviewed/2025/01/GHSA-466p-j3vq-mwq3/GHSA-466p-j3vq-mwq3.json +++ b/advisories/unreviewed/2025/01/GHSA-466p-j3vq-mwq3/GHSA-466p-j3vq-mwq3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json b/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json index 0669bf00c46..a5f20d6698f 100644 --- a/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json +++ b/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qmp-w6rv-24wf", - "modified": "2025-02-27T21:32:17Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-02-27T21:32:17Z", "aliases": [ "CVE-2025-21812" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: rcu protect dev->ax25_ptr\n\nsyzbot found a lockdep issue [1].\n\nWe should remove ax25 RTNL dependency in ax25_setsockopt()\n\nThis should also fix a variety of possible UAF in ax25.\n\n[1]\n\nWARNING: possible circular locking dependency detected\n6.13.0-rc3-syzkaller-00762-g9268abe611b0 #0 Not tainted\n------------------------------------------------------\nsyz.5.1818/12806 is trying to acquire lock:\n ffffffff8fcb3988 (rtnl_mutex){+.+.}-{4:4}, at: ax25_setsockopt+0xa55/0xe90 net/ax25/af_ax25.c:680\n\nbut task is already holding lock:\n ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1618 [inline]\n ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: ax25_setsockopt+0x209/0xe90 net/ax25/af_ax25.c:574\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #1 (sk_lock-AF_AX25){+.+.}-{0:0}:\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849\n lock_sock_nested+0x48/0x100 net/core/sock.c:3642\n lock_sock include/net/sock.h:1618 [inline]\n ax25_kill_by_device net/ax25/af_ax25.c:101 [inline]\n ax25_device_event+0x24d/0x580 net/ax25/af_ax25.c:146\n notifier_call_chain+0x1a5/0x3f0 kernel/notifier.c:85\n __dev_notify_flags+0x207/0x400\n dev_change_flags+0xf0/0x1a0 net/core/dev.c:9026\n dev_ifsioc+0x7c8/0xe70 net/core/dev_ioctl.c:563\n dev_ioctl+0x719/0x1340 net/core/dev_ioctl.c:820\n sock_do_ioctl+0x240/0x460 net/socket.c:1234\n sock_ioctl+0x626/0x8e0 net/socket.c:1339\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf5/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n-> #0 (rtnl_mutex){+.+.}-{4:4}:\n check_prev_add kernel/locking/lockdep.c:3161 [inline]\n check_prevs_add kernel/locking/lockdep.c:3280 [inline]\n validate_chain+0x18ef/0x5920 kernel/locking/lockdep.c:3904\n __lock_acquire+0x1397/0x2100 kernel/locking/lockdep.c:5226\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849\n __mutex_lock_common kernel/locking/mutex.c:585 [inline]\n __mutex_lock+0x1ac/0xee0 kernel/locking/mutex.c:735\n ax25_setsockopt+0xa55/0xe90 net/ax25/af_ax25.c:680\n do_sock_setsockopt+0x3af/0x720 net/socket.c:2324\n __sys_setsockopt net/socket.c:2349 [inline]\n __do_sys_setsockopt net/socket.c:2355 [inline]\n __se_sys_setsockopt net/socket.c:2352 [inline]\n __x64_sys_setsockopt+0x1ee/0x280 net/socket.c:2352\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nother info that might help us debug this:\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(sk_lock-AF_AX25);\n lock(rtnl_mutex);\n lock(sk_lock-AF_AX25);\n lock(rtnl_mutex);\n\n *** DEADLOCK ***\n\n1 lock held by syz.5.1818/12806:\n #0: ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1618 [inline]\n #0: ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: ax25_setsockopt+0x209/0xe90 net/ax25/af_ax25.c:574\n\nstack backtrace:\nCPU: 1 UID: 0 PID: 12806 Comm: syz.5.1818 Not tainted 6.13.0-rc3-syzkaller-00762-g9268abe611b0 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_circular_bug+0x13a/0x1b0 kernel/locking/lockdep.c:2074\n check_noncircular+0x36a/0x4a0 kernel/locking/lockdep.c:2206\n check_prev_add kernel/locking/lockdep.c:3161 [inline]\n check_prevs_add kernel/lockin\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T20:16:03Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json index 592d78970ed..99473542908 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json +++ b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json b/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json index fcd2df38b7f..0a02cdfd589 100644 --- a/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json +++ b/advisories/unreviewed/2025/02/GHSA-9h7g-r8hc-vrmp/GHSA-9h7g-r8hc-vrmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7g-r8hc-vrmp", - "modified": "2025-02-28T18:31:05Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-02-28T18:31:05Z", "aliases": [ "CVE-2025-25431" ], "details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T18:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json index dca44159c4b..a0352337d6a 100644 --- a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json +++ b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json b/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json index 42a2b023b58..55784f5474b 100644 --- a/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json +++ b/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fhjf-w34g-fcvp", - "modified": "2025-02-27T21:32:16Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-02-27T21:32:16Z", "aliases": [ "CVE-2024-58034" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code()\n\nAs of_find_node_by_name() release the reference of the argument device\nnode, tegra_emc_find_node_by_ram_code() releases some device nodes while\nstill in use, resulting in possible UAFs. According to the bindings and\nthe in-tree DTS files, the \"emc-tables\" node is always device's child\nnode with the property \"nvidia,use-ram-code\", and the \"lpddr2\" node is a\nchild of the \"emc-tables\" node. Thus utilize the\nfor_each_child_of_node() macro and of_get_child_by_name() instead of\nof_find_node_by_name() to simplify the code.\n\nThis bug was found by an experimental verification tool that I am\ndeveloping.\n\n[krzysztof: applied v1, adjust the commit msg to incorporate v2 parts]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T20:16:02Z" diff --git a/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json b/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json index 2ba5814d2be..9f53db222d1 100644 --- a/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json +++ b/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2gc-738w-q744", - "modified": "2025-02-27T21:32:17Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-02-27T21:32:17Z", "aliases": [ "CVE-2025-21811" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect access to buffers with no active references\n\nnilfs_lookup_dirty_data_buffers(), which iterates through the buffers\nattached to dirty data folios/pages, accesses the attached buffers without\nlocking the folios/pages.\n\nFor data cache, nilfs_clear_folio_dirty() may be called asynchronously\nwhen the file system degenerates to read only, so\nnilfs_lookup_dirty_data_buffers() still has the potential to cause use\nafter free issues when buffers lose the protection of their dirty state\nmidway due to this asynchronous clearing and are unintentionally freed by\ntry_to_free_buffers().\n\nEliminate this race issue by adjusting the lock section in this function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T20:16:03Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json b/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json index 30a424591bd..eb642efa72b 100644 --- a/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json +++ b/advisories/unreviewed/2025/02/GHSA-vmf2-mqm7-fcrm/GHSA-vmf2-mqm7-fcrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmf2-mqm7-fcrm", - "modified": "2025-02-28T18:31:05Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-02-28T18:31:05Z", "aliases": [ "CVE-2025-25430" ], "details": "Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T18:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-whh4-rfqm-vcwg/GHSA-whh4-rfqm-vcwg.json b/advisories/unreviewed/2025/02/GHSA-whh4-rfqm-vcwg/GHSA-whh4-rfqm-vcwg.json index fd39d15a3ec..47e62471d24 100644 --- a/advisories/unreviewed/2025/02/GHSA-whh4-rfqm-vcwg/GHSA-whh4-rfqm-vcwg.json +++ b/advisories/unreviewed/2025/02/GHSA-whh4-rfqm-vcwg/GHSA-whh4-rfqm-vcwg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-whh4-rfqm-vcwg", - "modified": "2025-02-28T21:32:20Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-02-28T21:32:20Z", "aliases": [ "CVE-2025-25428" ], "details": "TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-259" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T19:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json b/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json index a62ef374902..4a7b49de30d 100644 --- a/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json +++ b/advisories/unreviewed/2025/02/GHSA-xjc3-vjh6-m283/GHSA-xjc3-vjh6-m283.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json b/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json index c1e4946258c..685b959a0df 100644 --- a/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json +++ b/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-249w-xh84-97wj", - "modified": "2025-03-04T15:31:50Z", + "modified": "2025-03-04T18:33:42Z", "published": "2025-03-04T15:31:50Z", "aliases": [ "CVE-2025-27425" ], "details": "Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json b/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json index 6a95f7c5f94..c0f529e85a9 100644 --- a/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json +++ b/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cxw-wgvv-24jj", - "modified": "2025-03-04T12:30:32Z", + "modified": "2025-03-04T18:33:39Z", "published": "2025-03-04T12:30:32Z", "aliases": [ "CVE-2025-22225" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-123" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3297-hxj5-867g/GHSA-3297-hxj5-867g.json b/advisories/unreviewed/2025/03/GHSA-3297-hxj5-867g/GHSA-3297-hxj5-867g.json new file mode 100644 index 00000000000..36933417de0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3297-hxj5-867g/GHSA-3297-hxj5-867g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3297-hxj5-867g", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2025-26091" + ], + "details": "A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the \"My Passwords\" page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26091" + }, + { + "type": "WEB", + "url": "https://brunocaseiro.github.io/CVE-2025-26091" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35g5-m5m3-r8mx/GHSA-35g5-m5m3-r8mx.json b/advisories/unreviewed/2025/03/GHSA-35g5-m5m3-r8mx/GHSA-35g5-m5m3-r8mx.json index f0694cd6685..3873b7f8763 100644 --- a/advisories/unreviewed/2025/03/GHSA-35g5-m5m3-r8mx/GHSA-35g5-m5m3-r8mx.json +++ b/advisories/unreviewed/2025/03/GHSA-35g5-m5m3-r8mx/GHSA-35g5-m5m3-r8mx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-35g5-m5m3-r8mx", - "modified": "2025-03-03T18:31:28Z", + "modified": "2025-03-04T18:33:29Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2024-53387" ], "details": "A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-37f6-vjg7-8c6c/GHSA-37f6-vjg7-8c6c.json b/advisories/unreviewed/2025/03/GHSA-37f6-vjg7-8c6c/GHSA-37f6-vjg7-8c6c.json index a542d7b9453..e4a8e2d0fba 100644 --- a/advisories/unreviewed/2025/03/GHSA-37f6-vjg7-8c6c/GHSA-37f6-vjg7-8c6c.json +++ b/advisories/unreviewed/2025/03/GHSA-37f6-vjg7-8c6c/GHSA-37f6-vjg7-8c6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37f6-vjg7-8c6c", - "modified": "2025-03-04T12:30:32Z", + "modified": "2025-03-04T18:33:39Z", "published": "2025-03-04T12:30:32Z", "aliases": [ "CVE-2025-22226" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json b/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json index 8d6b7939805..83f8c80f5c4 100644 --- a/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json +++ b/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3j27-47wq-ghmh", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:28Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20646" ], "details": "In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3jxr-23ph-c89g/GHSA-3jxr-23ph-c89g.json b/advisories/unreviewed/2025/03/GHSA-3jxr-23ph-c89g/GHSA-3jxr-23ph-c89g.json new file mode 100644 index 00000000000..1408a39c864 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3jxr-23ph-c89g/GHSA-3jxr-23ph-c89g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jxr-23ph-c89g", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2025-23368" + ], + "details": "A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23368" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-23368" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337621" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3vcg-jhjm-5ffm/GHSA-3vcg-jhjm-5ffm.json b/advisories/unreviewed/2025/03/GHSA-3vcg-jhjm-5ffm/GHSA-3vcg-jhjm-5ffm.json new file mode 100644 index 00000000000..a6bbc0add64 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3vcg-jhjm-5ffm/GHSA-3vcg-jhjm-5ffm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vcg-jhjm-5ffm", + "modified": "2025-03-04T18:33:44Z", + "published": "2025-03-04T18:33:44Z", + "aliases": [ + "CVE-2024-10930" + ], + "details": "An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10930" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-01" + }, + { + "type": "WEB", + "url": "https://www.corporate.carrier.com/product-security/advisories-resources" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json b/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json index 1f13672a23b..42410d013d8 100644 --- a/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json +++ b/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3wj6-xwvq-325w", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:28Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20645" ], "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json b/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json index bfcce945f5a..38d8fc7f252 100644 --- a/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json +++ b/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3xm4-5347-4q37", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:28Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20649" ], "details": "In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-280" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json b/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json index 15ef3ff3da7..573e9a4e80b 100644 --- a/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json +++ b/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-472p-7734-hxc8", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:28Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20648" ], "details": "In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json b/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json index 568a6f82e1b..3cefd7a913a 100644 --- a/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json +++ b/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57gw-hcmr-f4g2", - "modified": "2025-03-04T15:31:50Z", + "modified": "2025-03-04T18:33:42Z", "published": "2025-03-04T15:31:50Z", "aliases": [ "CVE-2025-27426" ], "details": "Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5f86-34xg-qr85/GHSA-5f86-34xg-qr85.json b/advisories/unreviewed/2025/03/GHSA-5f86-34xg-qr85/GHSA-5f86-34xg-qr85.json index e2a6cf20206..28d76edb4be 100644 --- a/advisories/unreviewed/2025/03/GHSA-5f86-34xg-qr85/GHSA-5f86-34xg-qr85.json +++ b/advisories/unreviewed/2025/03/GHSA-5f86-34xg-qr85/GHSA-5f86-34xg-qr85.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f86-34xg-qr85", - "modified": "2025-03-04T00:30:54Z", + "modified": "2025-03-04T18:33:32Z", "published": "2025-03-04T00:30:54Z", "aliases": [ "CVE-2024-55064" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T22:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6f5q-x637-6prf/GHSA-6f5q-x637-6prf.json b/advisories/unreviewed/2025/03/GHSA-6f5q-x637-6prf/GHSA-6f5q-x637-6prf.json new file mode 100644 index 00000000000..cb465dd923a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6f5q-x637-6prf/GHSA-6f5q-x637-6prf.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f5q-x637-6prf", + "modified": "2025-03-04T18:33:25Z", + "published": "2025-03-04T18:33:25Z", + "aliases": [ + "CVE-2022-49114" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libfc: Fix use after free in fc_exch_abts_resp()\n\nfc_exch_release(ep) will decrease the ep's reference count. When the\nreference count reaches zero, it is freed. But ep is still used in the\nfollowing code, which will lead to a use after free.\n\nReturn after the fc_exch_release() call to avoid use after free.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d7effe5fff9d28e45e18ac3a564067c7ddfe898" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/271add11994ba1a334859069367e04d2be2ebdd4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/412dd8299b02e4410fe77b8396953c1a8dde183a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/499d198494e77b6533251b9b909baf5c101129cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a131d4ea8b581ac9b01d3a72754db4848be3232" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cf2ce8967b0d98c8cfa4dc42ef4fcf080f5c836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6044ad64f41c87382cfeeca281573d1886d80cbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87909291762d08fdb60d19069d7a89b5b308d0ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f581df412bc45c95176e3c808ee2839c05b2ab0c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json b/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json index c7349ca54b0..1d80a258358 100644 --- a/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json +++ b/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pcr-45mv-9gp3", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-04T18:33:30Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2025-0286" ], "details": "Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json b/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json index 13fcea34c47..65a0067763b 100644 --- a/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json +++ b/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pg6-qhjj-4wcm", - "modified": "2025-03-03T21:30:59Z", + "modified": "2025-03-04T18:33:32Z", "published": "2025-03-03T21:30:59Z", "aliases": [ "CVE-2025-25967" ], "details": "Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T19:15:35Z" diff --git a/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json b/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json index 2303f8c6345..6270d864641 100644 --- a/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json +++ b/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73jf-w7j4-5h24", - "modified": "2025-03-03T03:31:18Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-27584" ], "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name parameter at /rest/staffResource/update.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T01:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7mf9-x65f-jwgf/GHSA-7mf9-x65f-jwgf.json b/advisories/unreviewed/2025/03/GHSA-7mf9-x65f-jwgf/GHSA-7mf9-x65f-jwgf.json index c64b5e1fda2..b693d90381d 100644 --- a/advisories/unreviewed/2025/03/GHSA-7mf9-x65f-jwgf/GHSA-7mf9-x65f-jwgf.json +++ b/advisories/unreviewed/2025/03/GHSA-7mf9-x65f-jwgf/GHSA-7mf9-x65f-jwgf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mf9-x65f-jwgf", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-04T18:33:30Z", "published": "2025-03-03T18:31:29Z", "aliases": [ "CVE-2025-0289" ], "details": "Paragon Partition Manager version 17, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json b/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json index e67da597b90..9ba573a5457 100644 --- a/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json +++ b/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8454-mw8r-4mjq", - "modified": "2025-03-04T15:31:48Z", + "modified": "2025-03-04T18:33:40Z", "published": "2025-03-04T15:31:48Z", "aliases": [ "CVE-2025-1934" ], "details": "It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-185" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8f76-x9r8-c3c2/GHSA-8f76-x9r8-c3c2.json b/advisories/unreviewed/2025/03/GHSA-8f76-x9r8-c3c2/GHSA-8f76-x9r8-c3c2.json index 400d6b93d2e..135a4973806 100644 --- a/advisories/unreviewed/2025/03/GHSA-8f76-x9r8-c3c2/GHSA-8f76-x9r8-c3c2.json +++ b/advisories/unreviewed/2025/03/GHSA-8f76-x9r8-c3c2/GHSA-8f76-x9r8-c3c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8f76-x9r8-c3c2", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-04T18:33:30Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2025-0285" ], "details": "Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8j8g-6gw9-rjrf/GHSA-8j8g-6gw9-rjrf.json b/advisories/unreviewed/2025/03/GHSA-8j8g-6gw9-rjrf/GHSA-8j8g-6gw9-rjrf.json index bbbc4fbc564..0d1024dd22e 100644 --- a/advisories/unreviewed/2025/03/GHSA-8j8g-6gw9-rjrf/GHSA-8j8g-6gw9-rjrf.json +++ b/advisories/unreviewed/2025/03/GHSA-8j8g-6gw9-rjrf/GHSA-8j8g-6gw9-rjrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8j8g-6gw9-rjrf", - "modified": "2025-03-04T09:30:39Z", + "modified": "2025-03-04T18:33:38Z", "published": "2025-03-04T09:30:39Z", "aliases": [ "CVE-2024-48248" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48248" }, + { + "type": "WEB", + "url": "https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248/?ref=labs.watchtowr.com" + }, { "type": "WEB", "url": "https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm" diff --git a/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json b/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json index 5766e349cf2..f2350cf33e4 100644 --- a/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json +++ b/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9926-q228-4mpp", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:28Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20650" ], "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2061.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json b/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json index e11bff8cb56..336afb9186e 100644 --- a/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json +++ b/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9xc8-27jp-6jj2", - "modified": "2025-03-04T15:31:50Z", + "modified": "2025-03-04T18:33:42Z", "published": "2025-03-04T15:31:50Z", "aliases": [ "CVE-2024-50705" ], "details": "Unauthenticated reflected cross-site scripting (XSS) in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T15:15:19Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json index a1c50bc7579..533519809cd 100644 --- a/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json +++ b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c22c-4xww-2fqr", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-04T18:33:40Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1935" ], "details": "A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json b/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json index a2b9fae154f..1c6e2a5c8e2 100644 --- a/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json +++ b/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c3p2-xw2j-qrf4", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20644" ], "details": "In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01525673; Issue ID: MSV-2747.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1286" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c6wg-m9gg-2cg8/GHSA-c6wg-m9gg-2cg8.json b/advisories/unreviewed/2025/03/GHSA-c6wg-m9gg-2cg8/GHSA-c6wg-m9gg-2cg8.json new file mode 100644 index 00000000000..4f6b3d3690e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c6wg-m9gg-2cg8/GHSA-c6wg-m9gg-2cg8.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6wg-m9gg-2cg8", + "modified": "2025-03-04T18:33:26Z", + "published": "2025-03-04T18:33:26Z", + "aliases": [ + "CVE-2022-49275" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: m_can: m_can_tx_handler(): fix use after free of skb\n\ncan_put_echo_skb() will clone skb then free the skb. Move the\ncan_put_echo_skb() for the m_can version 3.0.x directly before the\nstart of the xmit in hardware, similar to the 3.1.x branch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49275" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08d90846e438ac22dc56fc49ec0b0d195831c5ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e8e79c416aae1de224c0f1860f2e3350fa171f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31417073493f302d26ab66b3abc098d43227b835" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4db7d6f481990dd179a9ee7126dc7aa31ea4fff3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7728d937ec403a1ceff9483023252d2cb8777f81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/869016a2938ac44f7b2fb7fc22c89edad99eb9b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3892a747ab16b1eb6593a19d29f62c3b3f020ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d93ed9aff64968f4cdad690712eb4f48ae537bde" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f43e64076ff1b1dcb893fb77ad1204105f710a29" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json b/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json new file mode 100644 index 00000000000..440fb009401 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cchf-xm65-f24c/GHSA-cchf-xm65-f24c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cchf-xm65-f24c", + "modified": "2025-03-04T18:33:44Z", + "published": "2025-03-04T18:33:44Z", + "aliases": [ + "CVE-2024-41147" + ], + "details": "An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41147" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cx28-78m7-h38f/GHSA-cx28-78m7-h38f.json b/advisories/unreviewed/2025/03/GHSA-cx28-78m7-h38f/GHSA-cx28-78m7-h38f.json index 22d71643d7e..4b3bd6b16ab 100644 --- a/advisories/unreviewed/2025/03/GHSA-cx28-78m7-h38f/GHSA-cx28-78m7-h38f.json +++ b/advisories/unreviewed/2025/03/GHSA-cx28-78m7-h38f/GHSA-cx28-78m7-h38f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cx28-78m7-h38f", - "modified": "2025-03-03T18:31:28Z", + "modified": "2025-03-04T18:33:30Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2024-57240" ], "details": "A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f7qf-3422-vc6q/GHSA-f7qf-3422-vc6q.json b/advisories/unreviewed/2025/03/GHSA-f7qf-3422-vc6q/GHSA-f7qf-3422-vc6q.json index 1553bbd2b53..66e78845a34 100644 --- a/advisories/unreviewed/2025/03/GHSA-f7qf-3422-vc6q/GHSA-f7qf-3422-vc6q.json +++ b/advisories/unreviewed/2025/03/GHSA-f7qf-3422-vc6q/GHSA-f7qf-3422-vc6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7qf-3422-vc6q", - "modified": "2025-03-01T00:31:55Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-03-01T00:31:55Z", "aliases": [ "CVE-2025-25476" ], "details": "A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T23:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json b/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json new file mode 100644 index 00000000000..ce582ea4272 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fj56-7h2j-m3p3/GHSA-fj56-7h2j-m3p3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj56-7h2j-m3p3", + "modified": "2025-03-04T18:33:44Z", + "published": "2025-03-04T18:33:44Z", + "aliases": [ + "CVE-2025-26182" + ], + "details": "An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26182" + }, + { + "type": "WEB", + "url": "https://gist.github.com/GSBP0/007355c5f6bd213264ae1c35c347e5cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json b/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json index ccc8cee9fe9..7adf7cae459 100644 --- a/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json +++ b/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g468-6jvw-w4j4", - "modified": "2025-03-03T21:30:59Z", + "modified": "2025-03-04T18:33:31Z", "published": "2025-03-03T21:30:59Z", "aliases": [ "CVE-2025-25939" ], "details": "Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T19:15:35Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json b/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json index 3ce03962d03..814e0522aa6 100644 --- a/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json +++ b/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g93r-3jrg-24gc", - "modified": "2025-03-03T03:31:18Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-03-03T03:31:18Z", "aliases": [ "CVE-2025-27585" ], "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Print Name parameter at /rest/staffResource/update.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T01:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json b/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json index 511aa068d6d..c4d18c4ab61 100644 --- a/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json +++ b/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqx4-7r84-32m6", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-04T18:33:40Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1940" ], "details": "A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. \n*This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1021" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json b/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json index 9354f48f37f..995681effbf 100644 --- a/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json +++ b/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h267-996p-9gjc", - "modified": "2025-03-04T15:31:48Z", + "modified": "2025-03-04T18:33:39Z", "published": "2025-03-04T15:31:48Z", "aliases": [ "CVE-2025-1932" ], "details": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j652-46fv-w96g/GHSA-j652-46fv-w96g.json b/advisories/unreviewed/2025/03/GHSA-j652-46fv-w96g/GHSA-j652-46fv-w96g.json index 3f06bbd34e0..7b88e8414a9 100644 --- a/advisories/unreviewed/2025/03/GHSA-j652-46fv-w96g/GHSA-j652-46fv-w96g.json +++ b/advisories/unreviewed/2025/03/GHSA-j652-46fv-w96g/GHSA-j652-46fv-w96g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j652-46fv-w96g", - "modified": "2025-03-04T12:30:32Z", + "modified": "2025-03-04T18:33:38Z", "published": "2025-03-04T12:30:32Z", "aliases": [ "CVE-2025-22224" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-367" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-jxrq-h53g-x3qx/GHSA-jxrq-h53g-x3qx.json b/advisories/unreviewed/2025/03/GHSA-jxrq-h53g-x3qx/GHSA-jxrq-h53g-x3qx.json new file mode 100644 index 00000000000..68f45510b71 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxrq-h53g-x3qx/GHSA-jxrq-h53g-x3qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxrq-h53g-x3qx", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2024-11957" + ], + "details": "Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276\n\n on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11957" + }, + { + "type": "WEB", + "url": "https://www.welivesecurity.com/en/eset-research/analysis-of-two-arbitrary-code-execution-vulnerabilities-affecting-wps-office" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json b/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json index aea8f62a503..58a60aeb0c3 100644 --- a/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json +++ b/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2rp-964h-h237", - "modified": "2025-03-04T15:31:50Z", + "modified": "2025-03-04T18:33:41Z", "published": "2025-03-04T15:31:50Z", "aliases": [ "CVE-2025-27424" ], "details": "Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-m3r4-hpjv-ph84/GHSA-m3r4-hpjv-ph84.json b/advisories/unreviewed/2025/03/GHSA-m3r4-hpjv-ph84/GHSA-m3r4-hpjv-ph84.json new file mode 100644 index 00000000000..7493b4943c5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m3r4-hpjv-ph84/GHSA-m3r4-hpjv-ph84.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3r4-hpjv-ph84", + "modified": "2025-03-04T18:33:26Z", + "published": "2025-03-04T18:33:26Z", + "aliases": [ + "CVE-2022-49196" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries: Fix use after free in remove_phb_dynamic()\n\nIn remove_phb_dynamic() we use &phb->io_resource, after we've called\ndevice_unregister(&host_bridge->dev). But the unregister may have freed\nphb, because pcibios_free_controller_deferred() is the release function\nfor the host_bridge.\n\nIf there are no outstanding references when we call device_unregister()\nthen phb will be freed out from under us.\n\nThis has gone mainly unnoticed, but with slub_debug and page_poison\nenabled it can lead to a crash:\n\n PID: 7574 TASK: c0000000d492cb80 CPU: 13 COMMAND: \"drmgr\"\n #0 [c0000000e4f075a0] crash_kexec at c00000000027d7dc\n #1 [c0000000e4f075d0] oops_end at c000000000029608\n #2 [c0000000e4f07650] __bad_page_fault at c0000000000904b4\n #3 [c0000000e4f076c0] do_bad_slb_fault at c00000000009a5a8\n #4 [c0000000e4f076f0] data_access_slb_common_virt at c000000000008b30\n Data SLB Access [380] exception frame:\n R0: c000000000167250 R1: c0000000e4f07a00 R2: c000000002a46100\n R3: c000000002b39ce8 R4: 00000000000000c0 R5: 00000000000000a9\n R6: 3894674d000000c0 R7: 0000000000000000 R8: 00000000000000ff\n R9: 0000000000000100 R10: 6b6b6b6b6b6b6b6b R11: 0000000000008000\n R12: c00000000023da80 R13: c0000009ffd38b00 R14: 0000000000000000\n R15: 000000011c87f0f0 R16: 0000000000000006 R17: 0000000000000003\n R18: 0000000000000002 R19: 0000000000000004 R20: 0000000000000005\n R21: 000000011c87ede8 R22: 000000011c87c5a8 R23: 000000011c87d3a0\n R24: 0000000000000000 R25: 0000000000000001 R26: c0000000e4f07cc8\n R27: c00000004d1cc400 R28: c0080000031d00e8 R29: c00000004d23d800\n R30: c00000004d1d2400 R31: c00000004d1d2540\n NIP: c000000000167258 MSR: 8000000000009033 OR3: c000000000e9f474\n CTR: 0000000000000000 LR: c000000000167250 XER: 0000000020040003\n CCR: 0000000024088420 MQ: 0000000000000000 DAR: 6b6b6b6b6b6b6ba3\n DSISR: c0000000e4f07920 Syscall Result: fffffffffffffff2\n [NIP : release_resource+56]\n [LR : release_resource+48]\n #5 [c0000000e4f07a00] release_resource at c000000000167258 (unreliable)\n #6 [c0000000e4f07a30] remove_phb_dynamic at c000000000105648\n #7 [c0000000e4f07ab0] dlpar_remove_slot at c0080000031a09e8 [rpadlpar_io]\n #8 [c0000000e4f07b50] remove_slot_store at c0080000031a0b9c [rpadlpar_io]\n #9 [c0000000e4f07be0] kobj_attr_store at c000000000817d8c\n #10 [c0000000e4f07c00] sysfs_kf_write at c00000000063e504\n #11 [c0000000e4f07c20] kernfs_fop_write_iter at c00000000063d868\n #12 [c0000000e4f07c70] new_sync_write at c00000000054339c\n #13 [c0000000e4f07d10] vfs_write at c000000000546624\n #14 [c0000000e4f07d60] ksys_write at c0000000005469f4\n #15 [c0000000e4f07db0] system_call_exception at c000000000030840\n #16 [c0000000e4f07e10] system_call_vectored_common at c00000000000c168\n\nTo avoid it, we can take a reference to the host_bridge->dev until we're\ndone using phb. Then when we drop the reference the phb will be freed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49196" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33d39efb61a84e055ca2386157d39ebbdf6b7d31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/403f9e0bc5535a0a5184d1352fa3a70e6ffacb6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/895ca4ae1f72e0a0160ab162723e59c9f265ec93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe2640bd7a62f1f7c3f55fbda31084085075bc30" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m5wp-346p-h7x3/GHSA-m5wp-346p-h7x3.json b/advisories/unreviewed/2025/03/GHSA-m5wp-346p-h7x3/GHSA-m5wp-346p-h7x3.json new file mode 100644 index 00000000000..092ae1cd4f0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m5wp-346p-h7x3/GHSA-m5wp-346p-h7x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5wp-346p-h7x3", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2025-1424" + ], + "details": "A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device.\nThis issue affects InkPad Color 3 in version U743k3.6.8.3671.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1424" + }, + { + "type": "WEB", + "url": "https://www.redguard.ch/blog/2025/03/04/security-advisory-pocketbook-inkpad-color-3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json b/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json index 46e60942b64..8e62d7c304f 100644 --- a/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json +++ b/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m793-xp46-r76w", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-04T18:33:40Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1941" ], "details": "Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json index 565aa42a81e..548299c6cbd 100644 --- a/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json +++ b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8x3-4xx7-hm4v", - "modified": "2025-03-03T03:31:18Z", + "modified": "2025-03-04T18:33:27Z", "published": "2025-03-03T03:31:17Z", "aliases": [ "CVE-2025-25949" ], "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T01:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pf5c-w647-wm56/GHSA-pf5c-w647-wm56.json b/advisories/unreviewed/2025/03/GHSA-pf5c-w647-wm56/GHSA-pf5c-w647-wm56.json new file mode 100644 index 00000000000..90f30f76e12 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pf5c-w647-wm56/GHSA-pf5c-w647-wm56.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5c-w647-wm56", + "modified": "2025-03-04T18:33:25Z", + "published": "2025-03-04T18:33:25Z", + "aliases": [ + "CVE-2022-49182" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: add vlan list lock to protect vlan list\n\nWhen adding port base VLAN, vf VLAN need to remove from HW and modify\nthe vlan state in vf VLAN list as false. If the periodicity task is\nfreeing the same node, it may cause \"use after free\" error.\nThis patch adds a vlan list lock to protect the vlan list.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49182" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09e383ca97e798f9954189b741af54b5c51e7a97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1932a624ab88ff407d1a1d567fe581faa15dc725" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30f0ff7176efe8ac6c55f85bce26ed58bb608758" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f58af41deeab0f45c9c80adf5f2de489ebbac3dd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json b/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json new file mode 100644 index 00000000000..ef8bbb0f994 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q9q9-pv7p-h33j/GHSA-q9q9-pv7p-h33j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9q9-pv7p-h33j", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2025-26320" + ], + "details": "t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26320" + }, + { + "type": "WEB", + "url": "https://github.com/BaranTeyin1/vulnerability-research/tree/main/CVE-2025-26320" + }, + { + "type": "WEB", + "url": "https://github.com/t0mer/broadlinkmanager-docker" + }, + { + "type": "WEB", + "url": "https://github.com/t0mer/broadlinkmanager-docker/blob/master/broadlinkmanager/broadlinkmanager.py#L639-L657" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qqm4-w34f-whgp/GHSA-qqm4-w34f-whgp.json b/advisories/unreviewed/2025/03/GHSA-qqm4-w34f-whgp/GHSA-qqm4-w34f-whgp.json index e6d66067ef9..5b783ec06b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-qqm4-w34f-whgp/GHSA-qqm4-w34f-whgp.json +++ b/advisories/unreviewed/2025/03/GHSA-qqm4-w34f-whgp/GHSA-qqm4-w34f-whgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqm4-w34f-whgp", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-04T18:33:30Z", "published": "2025-03-03T18:31:29Z", "aliases": [ "CVE-2025-0288" ], "details": "Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory vulnerability facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-131" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json b/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json index 16d09dca119..dc65ca6ff99 100644 --- a/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json +++ b/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7pc-h4wr-xggx", - "modified": "2025-03-03T21:30:59Z", + "modified": "2025-03-04T18:33:32Z", "published": "2025-03-03T21:30:59Z", "aliases": [ "CVE-2025-26206" ], "details": "Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T19:15:35Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json b/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json index b9b284072ae..5f8345c3ffb 100644 --- a/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json +++ b/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r83v-rmq7-r5m4", - "modified": "2025-03-04T15:31:49Z", + "modified": "2025-03-04T18:33:41Z", "published": "2025-03-04T15:31:49Z", "aliases": [ "CVE-2025-1942" ], "details": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json b/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json index 7deb8e60bf7..f051eb78a61 100644 --- a/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json +++ b/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r84f-4wj3-r6vx", - "modified": "2025-03-04T15:31:48Z", + "modified": "2025-03-04T18:33:39Z", "published": "2025-03-04T15:31:48Z", "aliases": [ "CVE-2025-1933" ], "details": "On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-252" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T14:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r9qc-pq8g-x74p/GHSA-r9qc-pq8g-x74p.json b/advisories/unreviewed/2025/03/GHSA-r9qc-pq8g-x74p/GHSA-r9qc-pq8g-x74p.json new file mode 100644 index 00000000000..5654ef035ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r9qc-pq8g-x74p/GHSA-r9qc-pq8g-x74p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9qc-pq8g-x74p", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2024-50707" + ], + "details": "Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50707" + }, + { + "type": "WEB", + "url": "https://uniguest.com/cve-bulletins" + }, + { + "type": "WEB", + "url": "https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50707-Vulnerability-Summary.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json b/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json index 6eda66e183b..40403feb381 100644 --- a/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json +++ b/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-rwg9-3gf9-vx76/GHSA-rwg9-3gf9-vx76.json b/advisories/unreviewed/2025/03/GHSA-rwg9-3gf9-vx76/GHSA-rwg9-3gf9-vx76.json new file mode 100644 index 00000000000..194f2bbae6e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rwg9-3gf9-vx76/GHSA-rwg9-3gf9-vx76.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwg9-3gf9-vx76", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2024-50704" + ], + "details": "Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50704" + }, + { + "type": "WEB", + "url": "https://uniguest.com/cve-bulletins" + }, + { + "type": "WEB", + "url": "https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50704-Vulnerability-Summary.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vqx8-mvcx-mx39/GHSA-vqx8-mvcx-mx39.json b/advisories/unreviewed/2025/03/GHSA-vqx8-mvcx-mx39/GHSA-vqx8-mvcx-mx39.json index cd29d4f468c..962e8fa75fb 100644 --- a/advisories/unreviewed/2025/03/GHSA-vqx8-mvcx-mx39/GHSA-vqx8-mvcx-mx39.json +++ b/advisories/unreviewed/2025/03/GHSA-vqx8-mvcx-mx39/GHSA-vqx8-mvcx-mx39.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vqx8-mvcx-mx39", - "modified": "2025-03-01T00:31:55Z", + "modified": "2025-03-04T18:33:26Z", "published": "2025-03-01T00:31:55Z", "aliases": [ "CVE-2025-25379" ], "details": "Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T23:15:10Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wm67-cvpp-xg5f/GHSA-wm67-cvpp-xg5f.json b/advisories/unreviewed/2025/03/GHSA-wm67-cvpp-xg5f/GHSA-wm67-cvpp-xg5f.json new file mode 100644 index 00000000000..9e6402712f5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wm67-cvpp-xg5f/GHSA-wm67-cvpp-xg5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm67-cvpp-xg5f", + "modified": "2025-03-04T18:33:43Z", + "published": "2025-03-04T18:33:43Z", + "aliases": [ + "CVE-2025-1425" + ], + "details": "A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1425" + }, + { + "type": "WEB", + "url": "https://www.redguard.ch/blog/2025/03/04/security-advisory-pocketbook-inkpad-color-3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json b/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json index 4913e56ef85..e280c5daa40 100644 --- a/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json +++ b/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xx4g-62m6-v2w7", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-04T18:33:29Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20652" ], "details": "In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:10Z"