From d98c5de5cd58bf2a31f9f72066f4f0a33964e9a4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 22 Jan 2025 21:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jvxp-2488-w24g.json | 2 +- .../GHSA-pqg2-q88q-5h4p.json | 2 +- .../GHSA-52hx-8455-4qwv.json | 5 +-- .../GHSA-56qq-x77r-g35x.json | 2 +- .../GHSA-6cqf-r56h-g5xf.json | 2 +- .../GHSA-9ppr-hv62-39w2.json | 2 +- .../GHSA-fww7-75jj-wj62.json | 2 +- .../GHSA-g384-79gw-fwh4.json | 2 +- .../GHSA-79pv-m8fc-mhfj.json | 6 +++- .../GHSA-7w82-f7rp-xf5c.json | 2 +- .../GHSA-m9vf-24g9-vj7g.json | 2 +- .../GHSA-6rc2-8j39-34cx.json | 6 ++-- .../GHSA-9493-w23w-4fq3.json | 4 ++- .../GHSA-99x8-5v72-mr3c.json | 4 ++- .../GHSA-cmmg-m2p2-79qp.json | 4 ++- .../GHSA-ggf4-7mhm-hwf4.json | 2 +- .../GHSA-j26c-55qg-84f2.json | 4 ++- .../GHSA-qm6j-rjvg-wxgx.json | 6 ++-- .../GHSA-r37j-ggrp-xm9j.json | 4 ++- .../GHSA-rqgj-xp64-4fxp.json | 4 ++- .../GHSA-jw3q-qghm-x757.json | 6 ++-- .../GHSA-rwc7-c97h-vxjm.json | 6 ++-- .../GHSA-2rgw-wmwq-m2w3.json | 4 ++- .../GHSA-329p-rhmw-5hxx.json | 4 ++- .../GHSA-394g-2wxx-rv2j.json | 4 ++- .../GHSA-3g8x-9wgw-w22x.json | 29 +++++++++++++++ .../GHSA-485c-prhh-35p4.json | 15 +++++--- .../GHSA-5j8q-6rjv-j6pr.json | 4 ++- .../GHSA-5rgx-hgv8-m99f.json | 15 +++++--- .../GHSA-6jx2-3qqx-x2m4.json | 4 ++- .../GHSA-788m-27g4-cf86.json | 29 +++++++++++++++ .../GHSA-7cjw-wfv9-8h8f.json | 15 +++++--- .../GHSA-7f5p-94w7-8f4w.json | 4 ++- .../GHSA-7j86-mfh6-h4g2.json | 4 ++- .../GHSA-7jqc-2xm3-38rq.json | 4 ++- .../GHSA-7wv2-2269-6gj4.json | 36 +++++++++++++++++++ .../GHSA-83vc-v46q-mv3w.json | 33 +++++++++++++++++ .../GHSA-89gv-ggj8-gg3q.json | 4 ++- .../GHSA-945p-45hq-35x9.json | 4 ++- .../GHSA-c6xg-jh94-mf2w.json | 33 +++++++++++++++++ .../GHSA-cqm6-6j54-g524.json | 15 +++++--- .../GHSA-cxgv-fj39-2f6g.json | 4 ++- .../GHSA-f3r5-c2rg-q6mc.json | 4 ++- .../GHSA-fwfm-v4vv-wgj6.json | 36 +++++++++++++++++++ .../GHSA-gg68-xh96-g8xv.json | 4 ++- .../GHSA-gmx3-jm7j-288w.json | 4 ++- .../GHSA-gpx9-7g7w-37gv.json | 4 ++- .../GHSA-hfv2-jjc2-3875.json | 15 +++++--- .../GHSA-jqx9-x6x8-85cw.json | 4 ++- .../GHSA-mj35-5954-95cc.json | 4 ++- .../GHSA-mmr8-fpcp-hg5w.json | 4 ++- .../GHSA-q45j-3mcp-r4j4.json | 4 ++- .../GHSA-q45q-cm8g-fhw5.json | 4 ++- .../GHSA-r5hv-f8cp-qm5f.json | 4 ++- .../GHSA-rj2q-jjmp-m73j.json | 29 +++++++++++++++ .../GHSA-vr47-q82p-p8ph.json | 4 ++- .../GHSA-vrx2-mgr9-v67h.json | 11 ++++-- .../GHSA-x8pw-mh46-hjmh.json | 4 ++- 58 files changed, 409 insertions(+), 73 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-3g8x-9wgw-w22x/GHSA-3g8x-9wgw-w22x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-788m-27g4-cf86/GHSA-788m-27g4-cf86.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7wv2-2269-6gj4/GHSA-7wv2-2269-6gj4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-83vc-v46q-mv3w/GHSA-83vc-v46q-mv3w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c6xg-jh94-mf2w/GHSA-c6xg-jh94-mf2w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fwfm-v4vv-wgj6/GHSA-fwfm-v4vv-wgj6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rj2q-jjmp-m73j/GHSA-rj2q-jjmp-m73j.json diff --git a/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json b/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json index 0ae17665580..ada592d5732 100644 --- a/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json +++ b/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvxp-2488-w24g", - "modified": "2022-04-30T00:02:23Z", + "modified": "2025-01-22T21:30:52Z", "published": "2022-04-30T00:02:23Z", "aliases": [ "CVE-2016-3976" diff --git a/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json b/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json index fa660888408..c19bd4d0c01 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json +++ b/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqg2-q88q-5h4p", - "modified": "2022-04-30T00:02:23Z", + "modified": "2025-01-22T21:30:52Z", "published": "2022-04-30T00:02:23Z", "aliases": [ "CVE-2016-9563" diff --git a/advisories/unreviewed/2022/05/GHSA-52hx-8455-4qwv/GHSA-52hx-8455-4qwv.json b/advisories/unreviewed/2022/05/GHSA-52hx-8455-4qwv/GHSA-52hx-8455-4qwv.json index f809f59c35c..ef7f9e02d30 100644 --- a/advisories/unreviewed/2022/05/GHSA-52hx-8455-4qwv/GHSA-52hx-8455-4qwv.json +++ b/advisories/unreviewed/2022/05/GHSA-52hx-8455-4qwv/GHSA-52hx-8455-4qwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-52hx-8455-4qwv", - "modified": "2022-05-14T03:48:15Z", + "modified": "2025-01-22T21:30:53Z", "published": "2022-05-14T03:48:15Z", "aliases": [ "CVE-2017-11357" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-434" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-56qq-x77r-g35x/GHSA-56qq-x77r-g35x.json b/advisories/unreviewed/2022/05/GHSA-56qq-x77r-g35x/GHSA-56qq-x77r-g35x.json index 26736ad1ef7..c53724ffbee 100644 --- a/advisories/unreviewed/2022/05/GHSA-56qq-x77r-g35x/GHSA-56qq-x77r-g35x.json +++ b/advisories/unreviewed/2022/05/GHSA-56qq-x77r-g35x/GHSA-56qq-x77r-g35x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-56qq-x77r-g35x", - "modified": "2022-05-13T01:10:21Z", + "modified": "2025-01-22T21:30:52Z", "published": "2022-05-13T01:10:21Z", "aliases": [ "CVE-2016-2388" diff --git a/advisories/unreviewed/2022/05/GHSA-6cqf-r56h-g5xf/GHSA-6cqf-r56h-g5xf.json b/advisories/unreviewed/2022/05/GHSA-6cqf-r56h-g5xf/GHSA-6cqf-r56h-g5xf.json index 062694b962b..abc431c0337 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cqf-r56h-g5xf/GHSA-6cqf-r56h-g5xf.json +++ b/advisories/unreviewed/2022/05/GHSA-6cqf-r56h-g5xf/GHSA-6cqf-r56h-g5xf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cqf-r56h-g5xf", - "modified": "2022-05-17T01:19:01Z", + "modified": "2025-01-22T21:30:53Z", "published": "2022-05-17T01:19:01Z", "aliases": [ "CVE-2017-5521" diff --git a/advisories/unreviewed/2022/05/GHSA-9ppr-hv62-39w2/GHSA-9ppr-hv62-39w2.json b/advisories/unreviewed/2022/05/GHSA-9ppr-hv62-39w2/GHSA-9ppr-hv62-39w2.json index 40b44661252..44e2463e77c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ppr-hv62-39w2/GHSA-9ppr-hv62-39w2.json +++ b/advisories/unreviewed/2022/05/GHSA-9ppr-hv62-39w2/GHSA-9ppr-hv62-39w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ppr-hv62-39w2", - "modified": "2022-05-13T01:28:23Z", + "modified": "2025-01-22T21:30:53Z", "published": "2022-05-13T01:28:23Z", "aliases": [ "CVE-2017-15944" diff --git a/advisories/unreviewed/2022/05/GHSA-fww7-75jj-wj62/GHSA-fww7-75jj-wj62.json b/advisories/unreviewed/2022/05/GHSA-fww7-75jj-wj62/GHSA-fww7-75jj-wj62.json index e2c61bb9381..962ea35b8b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fww7-75jj-wj62/GHSA-fww7-75jj-wj62.json +++ b/advisories/unreviewed/2022/05/GHSA-fww7-75jj-wj62/GHSA-fww7-75jj-wj62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fww7-75jj-wj62", - "modified": "2022-05-17T03:28:58Z", + "modified": "2025-01-22T21:30:52Z", "published": "2022-05-17T03:28:58Z", "aliases": [ "CVE-2016-3643" diff --git a/advisories/unreviewed/2022/05/GHSA-g384-79gw-fwh4/GHSA-g384-79gw-fwh4.json b/advisories/unreviewed/2022/05/GHSA-g384-79gw-fwh4/GHSA-g384-79gw-fwh4.json index b6fb73b4edd..e5c58856b46 100644 --- a/advisories/unreviewed/2022/05/GHSA-g384-79gw-fwh4/GHSA-g384-79gw-fwh4.json +++ b/advisories/unreviewed/2022/05/GHSA-g384-79gw-fwh4/GHSA-g384-79gw-fwh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g384-79gw-fwh4", - "modified": "2022-05-13T01:10:44Z", + "modified": "2025-01-22T21:30:52Z", "published": "2022-05-13T01:10:44Z", "aliases": [ "CVE-2016-2386" diff --git a/advisories/unreviewed/2023/05/GHSA-79pv-m8fc-mhfj/GHSA-79pv-m8fc-mhfj.json b/advisories/unreviewed/2023/05/GHSA-79pv-m8fc-mhfj/GHSA-79pv-m8fc-mhfj.json index a141f3df1fd..26561cce637 100644 --- a/advisories/unreviewed/2023/05/GHSA-79pv-m8fc-mhfj/GHSA-79pv-m8fc-mhfj.json +++ b/advisories/unreviewed/2023/05/GHSA-79pv-m8fc-mhfj/GHSA-79pv-m8fc-mhfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79pv-m8fc-mhfj", - "modified": "2024-04-04T04:12:47Z", + "modified": "2025-01-22T21:30:54Z", "published": "2023-05-17T03:30:16Z", "aliases": [ "CVE-2022-42336" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://xenbits.xenproject.org/xsa/advisory-431.txt" + }, + { + "type": "WEB", + "url": "http://xenbits.xen.org/xsa/advisory-431.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-7w82-f7rp-xf5c/GHSA-7w82-f7rp-xf5c.json b/advisories/unreviewed/2023/07/GHSA-7w82-f7rp-xf5c/GHSA-7w82-f7rp-xf5c.json index c2895b93d78..17a2c9955ba 100644 --- a/advisories/unreviewed/2023/07/GHSA-7w82-f7rp-xf5c/GHSA-7w82-f7rp-xf5c.json +++ b/advisories/unreviewed/2023/07/GHSA-7w82-f7rp-xf5c/GHSA-7w82-f7rp-xf5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w82-f7rp-xf5c", - "modified": "2024-04-04T05:43:49Z", + "modified": "2025-01-22T21:30:54Z", "published": "2023-07-06T21:14:58Z", "aliases": [ "CVE-2023-30509" diff --git a/advisories/unreviewed/2023/07/GHSA-m9vf-24g9-vj7g/GHSA-m9vf-24g9-vj7g.json b/advisories/unreviewed/2023/07/GHSA-m9vf-24g9-vj7g/GHSA-m9vf-24g9-vj7g.json index e0f2e181662..2a90822a084 100644 --- a/advisories/unreviewed/2023/07/GHSA-m9vf-24g9-vj7g/GHSA-m9vf-24g9-vj7g.json +++ b/advisories/unreviewed/2023/07/GHSA-m9vf-24g9-vj7g/GHSA-m9vf-24g9-vj7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9vf-24g9-vj7g", - "modified": "2024-04-04T05:43:45Z", + "modified": "2025-01-22T21:30:54Z", "published": "2023-07-06T21:14:58Z", "aliases": [ "CVE-2023-30508" diff --git a/advisories/unreviewed/2024/03/GHSA-6rc2-8j39-34cx/GHSA-6rc2-8j39-34cx.json b/advisories/unreviewed/2024/03/GHSA-6rc2-8j39-34cx/GHSA-6rc2-8j39-34cx.json index e82206fc568..28c8d493f4f 100644 --- a/advisories/unreviewed/2024/03/GHSA-6rc2-8j39-34cx/GHSA-6rc2-8j39-34cx.json +++ b/advisories/unreviewed/2024/03/GHSA-6rc2-8j39-34cx/GHSA-6rc2-8j39-34cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rc2-8j39-34cx", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-22T21:30:55Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1854" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9493-w23w-4fq3/GHSA-9493-w23w-4fq3.json b/advisories/unreviewed/2024/03/GHSA-9493-w23w-4fq3/GHSA-9493-w23w-4fq3.json index 7df1cfb3e5e..296cd18a319 100644 --- a/advisories/unreviewed/2024/03/GHSA-9493-w23w-4fq3/GHSA-9493-w23w-4fq3.json +++ b/advisories/unreviewed/2024/03/GHSA-9493-w23w-4fq3/GHSA-9493-w23w-4fq3.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-99x8-5v72-mr3c/GHSA-99x8-5v72-mr3c.json b/advisories/unreviewed/2024/03/GHSA-99x8-5v72-mr3c/GHSA-99x8-5v72-mr3c.json index 0b0eda8914c..368e59b099f 100644 --- a/advisories/unreviewed/2024/03/GHSA-99x8-5v72-mr3c/GHSA-99x8-5v72-mr3c.json +++ b/advisories/unreviewed/2024/03/GHSA-99x8-5v72-mr3c/GHSA-99x8-5v72-mr3c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cmmg-m2p2-79qp/GHSA-cmmg-m2p2-79qp.json b/advisories/unreviewed/2024/03/GHSA-cmmg-m2p2-79qp/GHSA-cmmg-m2p2-79qp.json index 870a4f4d36d..0cae3959955 100644 --- a/advisories/unreviewed/2024/03/GHSA-cmmg-m2p2-79qp/GHSA-cmmg-m2p2-79qp.json +++ b/advisories/unreviewed/2024/03/GHSA-cmmg-m2p2-79qp/GHSA-cmmg-m2p2-79qp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ggf4-7mhm-hwf4/GHSA-ggf4-7mhm-hwf4.json b/advisories/unreviewed/2024/03/GHSA-ggf4-7mhm-hwf4/GHSA-ggf4-7mhm-hwf4.json index 58fe2bffc2d..302ab1b280c 100644 --- a/advisories/unreviewed/2024/03/GHSA-ggf4-7mhm-hwf4/GHSA-ggf4-7mhm-hwf4.json +++ b/advisories/unreviewed/2024/03/GHSA-ggf4-7mhm-hwf4/GHSA-ggf4-7mhm-hwf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggf4-7mhm-hwf4", - "modified": "2024-03-13T18:31:35Z", + "modified": "2025-01-22T21:30:55Z", "published": "2024-03-13T18:31:35Z", "aliases": [ "CVE-2024-2106" diff --git a/advisories/unreviewed/2024/03/GHSA-j26c-55qg-84f2/GHSA-j26c-55qg-84f2.json b/advisories/unreviewed/2024/03/GHSA-j26c-55qg-84f2/GHSA-j26c-55qg-84f2.json index aea6d30c948..313abc7bdef 100644 --- a/advisories/unreviewed/2024/03/GHSA-j26c-55qg-84f2/GHSA-j26c-55qg-84f2.json +++ b/advisories/unreviewed/2024/03/GHSA-j26c-55qg-84f2/GHSA-j26c-55qg-84f2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qm6j-rjvg-wxgx/GHSA-qm6j-rjvg-wxgx.json b/advisories/unreviewed/2024/03/GHSA-qm6j-rjvg-wxgx/GHSA-qm6j-rjvg-wxgx.json index c1daf5b4515..65fd6cfa96b 100644 --- a/advisories/unreviewed/2024/03/GHSA-qm6j-rjvg-wxgx/GHSA-qm6j-rjvg-wxgx.json +++ b/advisories/unreviewed/2024/03/GHSA-qm6j-rjvg-wxgx/GHSA-qm6j-rjvg-wxgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm6j-rjvg-wxgx", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-22T21:30:55Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1535" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r37j-ggrp-xm9j/GHSA-r37j-ggrp-xm9j.json b/advisories/unreviewed/2024/03/GHSA-r37j-ggrp-xm9j/GHSA-r37j-ggrp-xm9j.json index cf528b67f6d..7c3e1c71402 100644 --- a/advisories/unreviewed/2024/03/GHSA-r37j-ggrp-xm9j/GHSA-r37j-ggrp-xm9j.json +++ b/advisories/unreviewed/2024/03/GHSA-r37j-ggrp-xm9j/GHSA-r37j-ggrp-xm9j.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rqgj-xp64-4fxp/GHSA-rqgj-xp64-4fxp.json b/advisories/unreviewed/2024/03/GHSA-rqgj-xp64-4fxp/GHSA-rqgj-xp64-4fxp.json index 52df57bf882..30adc1419b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-rqgj-xp64-4fxp/GHSA-rqgj-xp64-4fxp.json +++ b/advisories/unreviewed/2024/03/GHSA-rqgj-xp64-4fxp/GHSA-rqgj-xp64-4fxp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json b/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json index 4a02be1854a..71fb2d390f1 100644 --- a/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json +++ b/advisories/unreviewed/2024/04/GHSA-jw3q-qghm-x757/GHSA-jw3q-qghm-x757.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw3q-qghm-x757", - "modified": "2024-04-11T12:30:28Z", + "modified": "2025-01-22T21:30:55Z", "published": "2024-04-11T12:30:28Z", "aliases": [ "CVE-2024-3344" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json b/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json index 43ef24c8a5c..7f78a24d5cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json +++ b/advisories/unreviewed/2024/04/GHSA-rwc7-c97h-vxjm/GHSA-rwc7-c97h-vxjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwc7-c97h-vxjm", - "modified": "2024-04-11T12:30:28Z", + "modified": "2025-01-22T21:30:55Z", "published": "2024-04-11T12:30:28Z", "aliases": [ "CVE-2024-3343" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2rgw-wmwq-m2w3/GHSA-2rgw-wmwq-m2w3.json b/advisories/unreviewed/2025/01/GHSA-2rgw-wmwq-m2w3/GHSA-2rgw-wmwq-m2w3.json index 9913f0c8e84..a69c805d4ae 100644 --- a/advisories/unreviewed/2025/01/GHSA-2rgw-wmwq-m2w3/GHSA-2rgw-wmwq-m2w3.json +++ b/advisories/unreviewed/2025/01/GHSA-2rgw-wmwq-m2w3/GHSA-2rgw-wmwq-m2w3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-329p-rhmw-5hxx/GHSA-329p-rhmw-5hxx.json b/advisories/unreviewed/2025/01/GHSA-329p-rhmw-5hxx/GHSA-329p-rhmw-5hxx.json index 8a4f436efcc..17cb1f92790 100644 --- a/advisories/unreviewed/2025/01/GHSA-329p-rhmw-5hxx/GHSA-329p-rhmw-5hxx.json +++ b/advisories/unreviewed/2025/01/GHSA-329p-rhmw-5hxx/GHSA-329p-rhmw-5hxx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-394g-2wxx-rv2j/GHSA-394g-2wxx-rv2j.json b/advisories/unreviewed/2025/01/GHSA-394g-2wxx-rv2j/GHSA-394g-2wxx-rv2j.json index 15f39e3434f..ef1d4f778a7 100644 --- a/advisories/unreviewed/2025/01/GHSA-394g-2wxx-rv2j/GHSA-394g-2wxx-rv2j.json +++ b/advisories/unreviewed/2025/01/GHSA-394g-2wxx-rv2j/GHSA-394g-2wxx-rv2j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3g8x-9wgw-w22x/GHSA-3g8x-9wgw-w22x.json b/advisories/unreviewed/2025/01/GHSA-3g8x-9wgw-w22x/GHSA-3g8x-9wgw-w22x.json new file mode 100644 index 00000000000..1b8b35ebf79 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3g8x-9wgw-w22x/GHSA-3g8x-9wgw-w22x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g8x-9wgw-w22x", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2024-56914" + ], + "details": "D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56914" + }, + { + "type": "WEB", + "url": "https://github.com/2664521593/mycve/blob/main/BOF_in_D-Link_DSL-3782_1.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-485c-prhh-35p4/GHSA-485c-prhh-35p4.json b/advisories/unreviewed/2025/01/GHSA-485c-prhh-35p4/GHSA-485c-prhh-35p4.json index 8dc754495f3..ab59ec01b40 100644 --- a/advisories/unreviewed/2025/01/GHSA-485c-prhh-35p4/GHSA-485c-prhh-35p4.json +++ b/advisories/unreviewed/2025/01/GHSA-485c-prhh-35p4/GHSA-485c-prhh-35p4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-485c-prhh-35p4", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-01-22T21:30:55Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57536" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5j8q-6rjv-j6pr/GHSA-5j8q-6rjv-j6pr.json b/advisories/unreviewed/2025/01/GHSA-5j8q-6rjv-j6pr/GHSA-5j8q-6rjv-j6pr.json index ebb2396e200..c03be924838 100644 --- a/advisories/unreviewed/2025/01/GHSA-5j8q-6rjv-j6pr/GHSA-5j8q-6rjv-j6pr.json +++ b/advisories/unreviewed/2025/01/GHSA-5j8q-6rjv-j6pr/GHSA-5j8q-6rjv-j6pr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5rgx-hgv8-m99f/GHSA-5rgx-hgv8-m99f.json b/advisories/unreviewed/2025/01/GHSA-5rgx-hgv8-m99f/GHSA-5rgx-hgv8-m99f.json index 313090caee4..b4f8de8a97b 100644 --- a/advisories/unreviewed/2025/01/GHSA-5rgx-hgv8-m99f/GHSA-5rgx-hgv8-m99f.json +++ b/advisories/unreviewed/2025/01/GHSA-5rgx-hgv8-m99f/GHSA-5rgx-hgv8-m99f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rgx-hgv8-m99f", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-01-22T21:30:56Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57541" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6jx2-3qqx-x2m4/GHSA-6jx2-3qqx-x2m4.json b/advisories/unreviewed/2025/01/GHSA-6jx2-3qqx-x2m4/GHSA-6jx2-3qqx-x2m4.json index bce5fbc9fc1..4cc01bb0033 100644 --- a/advisories/unreviewed/2025/01/GHSA-6jx2-3qqx-x2m4/GHSA-6jx2-3qqx-x2m4.json +++ b/advisories/unreviewed/2025/01/GHSA-6jx2-3qqx-x2m4/GHSA-6jx2-3qqx-x2m4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-788m-27g4-cf86/GHSA-788m-27g4-cf86.json b/advisories/unreviewed/2025/01/GHSA-788m-27g4-cf86/GHSA-788m-27g4-cf86.json new file mode 100644 index 00000000000..439bf71dc23 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-788m-27g4-cf86/GHSA-788m-27g4-cf86.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-788m-27g4-cf86", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2024-56923" + ], + "details": "Stored Cross-Site Scripting (XSS) in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56923" + }, + { + "type": "WEB", + "url": "https://github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7cjw-wfv9-8h8f/GHSA-7cjw-wfv9-8h8f.json b/advisories/unreviewed/2025/01/GHSA-7cjw-wfv9-8h8f/GHSA-7cjw-wfv9-8h8f.json index 30fffaf5af3..c6ed8bf1d87 100644 --- a/advisories/unreviewed/2025/01/GHSA-7cjw-wfv9-8h8f/GHSA-7cjw-wfv9-8h8f.json +++ b/advisories/unreviewed/2025/01/GHSA-7cjw-wfv9-8h8f/GHSA-7cjw-wfv9-8h8f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7cjw-wfv9-8h8f", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-01-22T21:30:55Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57542" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7f5p-94w7-8f4w/GHSA-7f5p-94w7-8f4w.json b/advisories/unreviewed/2025/01/GHSA-7f5p-94w7-8f4w/GHSA-7f5p-94w7-8f4w.json index 4cdf1573450..e9d28937627 100644 --- a/advisories/unreviewed/2025/01/GHSA-7f5p-94w7-8f4w/GHSA-7f5p-94w7-8f4w.json +++ b/advisories/unreviewed/2025/01/GHSA-7f5p-94w7-8f4w/GHSA-7f5p-94w7-8f4w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7j86-mfh6-h4g2/GHSA-7j86-mfh6-h4g2.json b/advisories/unreviewed/2025/01/GHSA-7j86-mfh6-h4g2/GHSA-7j86-mfh6-h4g2.json index 042addd3822..43c396d3edb 100644 --- a/advisories/unreviewed/2025/01/GHSA-7j86-mfh6-h4g2/GHSA-7j86-mfh6-h4g2.json +++ b/advisories/unreviewed/2025/01/GHSA-7j86-mfh6-h4g2/GHSA-7j86-mfh6-h4g2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7jqc-2xm3-38rq/GHSA-7jqc-2xm3-38rq.json b/advisories/unreviewed/2025/01/GHSA-7jqc-2xm3-38rq/GHSA-7jqc-2xm3-38rq.json index bfb1878f919..5afc5f3718f 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jqc-2xm3-38rq/GHSA-7jqc-2xm3-38rq.json +++ b/advisories/unreviewed/2025/01/GHSA-7jqc-2xm3-38rq/GHSA-7jqc-2xm3-38rq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7wv2-2269-6gj4/GHSA-7wv2-2269-6gj4.json b/advisories/unreviewed/2025/01/GHSA-7wv2-2269-6gj4/GHSA-7wv2-2269-6gj4.json new file mode 100644 index 00000000000..f7deea76a29 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7wv2-2269-6gj4/GHSA-7wv2-2269-6gj4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wv2-2269-6gj4", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2024-11166" + ], + "details": "For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a ground station and issue a Comm-A Identity Request. This action can set the Sensitivity Level Control (SLC) to the lowest setting and disable the Resolution Advisory (RA), leading to a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11166" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-83vc-v46q-mv3w/GHSA-83vc-v46q-mv3w.json b/advisories/unreviewed/2025/01/GHSA-83vc-v46q-mv3w/GHSA-83vc-v46q-mv3w.json new file mode 100644 index 00000000000..6a306ebafbf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-83vc-v46q-mv3w/GHSA-83vc-v46q-mv3w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83vc-v46q-mv3w", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2025-0611" + ], + "details": "Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0611" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/386143468" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89gv-ggj8-gg3q/GHSA-89gv-ggj8-gg3q.json b/advisories/unreviewed/2025/01/GHSA-89gv-ggj8-gg3q/GHSA-89gv-ggj8-gg3q.json index d13dd6f5df9..a5e4c3297fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-89gv-ggj8-gg3q/GHSA-89gv-ggj8-gg3q.json +++ b/advisories/unreviewed/2025/01/GHSA-89gv-ggj8-gg3q/GHSA-89gv-ggj8-gg3q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-945p-45hq-35x9/GHSA-945p-45hq-35x9.json b/advisories/unreviewed/2025/01/GHSA-945p-45hq-35x9/GHSA-945p-45hq-35x9.json index ead4f8f3749..6d95e2d1df2 100644 --- a/advisories/unreviewed/2025/01/GHSA-945p-45hq-35x9/GHSA-945p-45hq-35x9.json +++ b/advisories/unreviewed/2025/01/GHSA-945p-45hq-35x9/GHSA-945p-45hq-35x9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-c6xg-jh94-mf2w/GHSA-c6xg-jh94-mf2w.json b/advisories/unreviewed/2025/01/GHSA-c6xg-jh94-mf2w/GHSA-c6xg-jh94-mf2w.json new file mode 100644 index 00000000000..cd2261fbc62 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c6xg-jh94-mf2w/GHSA-c6xg-jh94-mf2w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6xg-jh94-mf2w", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2025-0612" + ], + "details": "Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0612" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/385155406" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cqm6-6j54-g524/GHSA-cqm6-6j54-g524.json b/advisories/unreviewed/2025/01/GHSA-cqm6-6j54-g524/GHSA-cqm6-6j54-g524.json index d5ddd6cabc9..74df67aef84 100644 --- a/advisories/unreviewed/2025/01/GHSA-cqm6-6j54-g524/GHSA-cqm6-6j54-g524.json +++ b/advisories/unreviewed/2025/01/GHSA-cqm6-6j54-g524/GHSA-cqm6-6j54-g524.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqm6-6j54-g524", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-01-22T21:30:56Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57537" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cxgv-fj39-2f6g/GHSA-cxgv-fj39-2f6g.json b/advisories/unreviewed/2025/01/GHSA-cxgv-fj39-2f6g/GHSA-cxgv-fj39-2f6g.json index 9faa3381da1..e4b37cfa81c 100644 --- a/advisories/unreviewed/2025/01/GHSA-cxgv-fj39-2f6g/GHSA-cxgv-fj39-2f6g.json +++ b/advisories/unreviewed/2025/01/GHSA-cxgv-fj39-2f6g/GHSA-cxgv-fj39-2f6g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-f3r5-c2rg-q6mc/GHSA-f3r5-c2rg-q6mc.json b/advisories/unreviewed/2025/01/GHSA-f3r5-c2rg-q6mc/GHSA-f3r5-c2rg-q6mc.json index 7e0f2e53bce..61dc6faa596 100644 --- a/advisories/unreviewed/2025/01/GHSA-f3r5-c2rg-q6mc/GHSA-f3r5-c2rg-q6mc.json +++ b/advisories/unreviewed/2025/01/GHSA-f3r5-c2rg-q6mc/GHSA-f3r5-c2rg-q6mc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fwfm-v4vv-wgj6/GHSA-fwfm-v4vv-wgj6.json b/advisories/unreviewed/2025/01/GHSA-fwfm-v4vv-wgj6/GHSA-fwfm-v4vv-wgj6.json new file mode 100644 index 00000000000..25db5c0a69d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fwfm-v4vv-wgj6/GHSA-fwfm-v4vv-wgj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwfm-v4vv-wgj6", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2024-9310" + ], + "details": "By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data can be transmitted to aircraft targets. This can lead to the appearance of fake aircraft on displays and potentially trigger undesired Resolution Advisories (RAs).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9310" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-807" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gg68-xh96-g8xv/GHSA-gg68-xh96-g8xv.json b/advisories/unreviewed/2025/01/GHSA-gg68-xh96-g8xv/GHSA-gg68-xh96-g8xv.json index 35027f5fef7..de7e2f7d0a5 100644 --- a/advisories/unreviewed/2025/01/GHSA-gg68-xh96-g8xv/GHSA-gg68-xh96-g8xv.json +++ b/advisories/unreviewed/2025/01/GHSA-gg68-xh96-g8xv/GHSA-gg68-xh96-g8xv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gmx3-jm7j-288w/GHSA-gmx3-jm7j-288w.json b/advisories/unreviewed/2025/01/GHSA-gmx3-jm7j-288w/GHSA-gmx3-jm7j-288w.json index 977242542c6..848e2002b37 100644 --- a/advisories/unreviewed/2025/01/GHSA-gmx3-jm7j-288w/GHSA-gmx3-jm7j-288w.json +++ b/advisories/unreviewed/2025/01/GHSA-gmx3-jm7j-288w/GHSA-gmx3-jm7j-288w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gpx9-7g7w-37gv/GHSA-gpx9-7g7w-37gv.json b/advisories/unreviewed/2025/01/GHSA-gpx9-7g7w-37gv/GHSA-gpx9-7g7w-37gv.json index ca3190c967b..540b0b7ea65 100644 --- a/advisories/unreviewed/2025/01/GHSA-gpx9-7g7w-37gv/GHSA-gpx9-7g7w-37gv.json +++ b/advisories/unreviewed/2025/01/GHSA-gpx9-7g7w-37gv/GHSA-gpx9-7g7w-37gv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-hfv2-jjc2-3875/GHSA-hfv2-jjc2-3875.json b/advisories/unreviewed/2025/01/GHSA-hfv2-jjc2-3875/GHSA-hfv2-jjc2-3875.json index 32c92acea68..66fe6d28e49 100644 --- a/advisories/unreviewed/2025/01/GHSA-hfv2-jjc2-3875/GHSA-hfv2-jjc2-3875.json +++ b/advisories/unreviewed/2025/01/GHSA-hfv2-jjc2-3875/GHSA-hfv2-jjc2-3875.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfv2-jjc2-3875", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-01-22T21:30:56Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57543" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jqx9-x6x8-85cw/GHSA-jqx9-x6x8-85cw.json b/advisories/unreviewed/2025/01/GHSA-jqx9-x6x8-85cw/GHSA-jqx9-x6x8-85cw.json index 4cef40f7692..3d8f7515bd0 100644 --- a/advisories/unreviewed/2025/01/GHSA-jqx9-x6x8-85cw/GHSA-jqx9-x6x8-85cw.json +++ b/advisories/unreviewed/2025/01/GHSA-jqx9-x6x8-85cw/GHSA-jqx9-x6x8-85cw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-mj35-5954-95cc/GHSA-mj35-5954-95cc.json b/advisories/unreviewed/2025/01/GHSA-mj35-5954-95cc/GHSA-mj35-5954-95cc.json index f1cdb0adb27..6972e245bda 100644 --- a/advisories/unreviewed/2025/01/GHSA-mj35-5954-95cc/GHSA-mj35-5954-95cc.json +++ b/advisories/unreviewed/2025/01/GHSA-mj35-5954-95cc/GHSA-mj35-5954-95cc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-mmr8-fpcp-hg5w/GHSA-mmr8-fpcp-hg5w.json b/advisories/unreviewed/2025/01/GHSA-mmr8-fpcp-hg5w/GHSA-mmr8-fpcp-hg5w.json index 370f47c795b..14a5bc94830 100644 --- a/advisories/unreviewed/2025/01/GHSA-mmr8-fpcp-hg5w/GHSA-mmr8-fpcp-hg5w.json +++ b/advisories/unreviewed/2025/01/GHSA-mmr8-fpcp-hg5w/GHSA-mmr8-fpcp-hg5w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-q45j-3mcp-r4j4/GHSA-q45j-3mcp-r4j4.json b/advisories/unreviewed/2025/01/GHSA-q45j-3mcp-r4j4/GHSA-q45j-3mcp-r4j4.json index 65ce8e20385..776151ca6f9 100644 --- a/advisories/unreviewed/2025/01/GHSA-q45j-3mcp-r4j4/GHSA-q45j-3mcp-r4j4.json +++ b/advisories/unreviewed/2025/01/GHSA-q45j-3mcp-r4j4/GHSA-q45j-3mcp-r4j4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-q45q-cm8g-fhw5/GHSA-q45q-cm8g-fhw5.json b/advisories/unreviewed/2025/01/GHSA-q45q-cm8g-fhw5/GHSA-q45q-cm8g-fhw5.json index 4fcc400b70c..512f3fcbdf0 100644 --- a/advisories/unreviewed/2025/01/GHSA-q45q-cm8g-fhw5/GHSA-q45q-cm8g-fhw5.json +++ b/advisories/unreviewed/2025/01/GHSA-q45q-cm8g-fhw5/GHSA-q45q-cm8g-fhw5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-r5hv-f8cp-qm5f/GHSA-r5hv-f8cp-qm5f.json b/advisories/unreviewed/2025/01/GHSA-r5hv-f8cp-qm5f/GHSA-r5hv-f8cp-qm5f.json index 0efd277ed49..03355bf2b08 100644 --- a/advisories/unreviewed/2025/01/GHSA-r5hv-f8cp-qm5f/GHSA-r5hv-f8cp-qm5f.json +++ b/advisories/unreviewed/2025/01/GHSA-r5hv-f8cp-qm5f/GHSA-r5hv-f8cp-qm5f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-rj2q-jjmp-m73j/GHSA-rj2q-jjmp-m73j.json b/advisories/unreviewed/2025/01/GHSA-rj2q-jjmp-m73j/GHSA-rj2q-jjmp-m73j.json new file mode 100644 index 00000000000..1addfe51035 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rj2q-jjmp-m73j/GHSA-rj2q-jjmp-m73j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj2q-jjmp-m73j", + "modified": "2025-01-22T21:30:57Z", + "published": "2025-01-22T21:30:57Z", + "aliases": [ + "CVE-2024-56924" + ], + "details": "A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56924" + }, + { + "type": "WEB", + "url": "https://github.com/ipratheep/CVE-2024-56924" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vr47-q82p-p8ph/GHSA-vr47-q82p-p8ph.json b/advisories/unreviewed/2025/01/GHSA-vr47-q82p-p8ph/GHSA-vr47-q82p-p8ph.json index 52233dc10db..db09791f74e 100644 --- a/advisories/unreviewed/2025/01/GHSA-vr47-q82p-p8ph/GHSA-vr47-q82p-p8ph.json +++ b/advisories/unreviewed/2025/01/GHSA-vr47-q82p-p8ph/GHSA-vr47-q82p-p8ph.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-vrx2-mgr9-v67h/GHSA-vrx2-mgr9-v67h.json b/advisories/unreviewed/2025/01/GHSA-vrx2-mgr9-v67h/GHSA-vrx2-mgr9-v67h.json index 31083ed5240..cde7faa702f 100644 --- a/advisories/unreviewed/2025/01/GHSA-vrx2-mgr9-v67h/GHSA-vrx2-mgr9-v67h.json +++ b/advisories/unreviewed/2025/01/GHSA-vrx2-mgr9-v67h/GHSA-vrx2-mgr9-v67h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrx2-mgr9-v67h", - "modified": "2025-01-22T00:33:35Z", + "modified": "2025-01-22T21:30:57Z", "published": "2025-01-22T00:33:35Z", "aliases": [ "CVE-2024-45478" ], "details": "Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.\nUsers are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x8pw-mh46-hjmh/GHSA-x8pw-mh46-hjmh.json b/advisories/unreviewed/2025/01/GHSA-x8pw-mh46-hjmh/GHSA-x8pw-mh46-hjmh.json index baaf3edcd08..7bc8f575ee6 100644 --- a/advisories/unreviewed/2025/01/GHSA-x8pw-mh46-hjmh/GHSA-x8pw-mh46-hjmh.json +++ b/advisories/unreviewed/2025/01/GHSA-x8pw-mh46-hjmh/GHSA-x8pw-mh46-hjmh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null,