Publish Advisories

GHSA-gpcj-wh2f-rr23
GHSA-882h-ff2x-f86q
GHSA-377p-4737-hx6m
GHSA-4v9x-qxmv-4h58
GHSA-5c3h-62vh-c2xw
GHSA-jxfh-r792-52qr
GHSA-w46v-c4p8-v28f
GHSA-wrgh-9j55-488p
This commit is contained in:
advisory-database[bot]
2025-02-15 03:32:30 +00:00
parent 1eb208ac21
commit dade0c7835
8 changed files with 200 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpcj-wh2f-rr23",
"modified": "2024-05-22T18:30:38Z",
"modified": "2025-02-15T03:31:24Z",
"published": "2023-12-19T00:30:21Z",
"aliases": [
"CVE-2023-6918"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250214-0009"
},
{
"type": "WEB",
"url": "https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-882h-ff2x-f86q",
"modified": "2024-11-22T21:32:17Z",
"modified": "2025-02-15T03:31:24Z",
"published": "2024-11-22T21:32:17Z",
"aliases": [
"CVE-2024-11477"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11477"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250214-0007"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1532"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-377p-4737-hx6m",
"modified": "2025-02-15T03:31:24Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2025-0995"
],
"details": "Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0995"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/391907159"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T02:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v9x-qxmv-4h58",
"modified": "2025-02-15T03:31:25Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2025-0998"
],
"details": "Out of bounds memory access in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0998"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/386857213"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T02:15:09Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5c3h-62vh-c2xw",
"modified": "2025-02-15T03:31:24Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2024-37374"
],
"details": "Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37374"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T01:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxfh-r792-52qr",
"modified": "2025-02-15T03:31:24Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2025-0997"
],
"details": "Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0997"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/391666328"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T02:15:09Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w46v-c4p8-v28f",
"modified": "2025-02-15T03:31:24Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2024-37375"
],
"details": "Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37375"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T01:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrgh-9j55-488p",
"modified": "2025-02-15T03:31:24Z",
"published": "2025-02-15T03:31:24Z",
"aliases": [
"CVE-2025-0996"
],
"details": "Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0996"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/391788835"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1007"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-15T02:15:09Z"
}
}