From dade0c78352d845879b5c46c770953529a199c3f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 15 Feb 2025 03:32:30 +0000 Subject: [PATCH] Publish Advisories GHSA-gpcj-wh2f-rr23 GHSA-882h-ff2x-f86q GHSA-377p-4737-hx6m GHSA-4v9x-qxmv-4h58 GHSA-5c3h-62vh-c2xw GHSA-jxfh-r792-52qr GHSA-w46v-c4p8-v28f GHSA-wrgh-9j55-488p --- .../GHSA-gpcj-wh2f-rr23.json | 6 +++- .../GHSA-882h-ff2x-f86q.json | 6 +++- .../GHSA-377p-4737-hx6m.json | 35 +++++++++++++++++++ .../GHSA-4v9x-qxmv-4h58.json | 35 +++++++++++++++++++ .../GHSA-5c3h-62vh-c2xw.json | 25 +++++++++++++ .../GHSA-jxfh-r792-52qr.json | 35 +++++++++++++++++++ .../GHSA-w46v-c4p8-v28f.json | 25 +++++++++++++ .../GHSA-wrgh-9j55-488p.json | 35 +++++++++++++++++++ 8 files changed, 200 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-377p-4737-hx6m/GHSA-377p-4737-hx6m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4v9x-qxmv-4h58/GHSA-4v9x-qxmv-4h58.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5c3h-62vh-c2xw/GHSA-5c3h-62vh-c2xw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jxfh-r792-52qr/GHSA-jxfh-r792-52qr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w46v-c4p8-v28f/GHSA-w46v-c4p8-v28f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wrgh-9j55-488p/GHSA-wrgh-9j55-488p.json diff --git a/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json b/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json index 134f16f733f..abd3fd62fe3 100644 --- a/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json +++ b/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gpcj-wh2f-rr23", - "modified": "2024-05-22T18:30:38Z", + "modified": "2025-02-15T03:31:24Z", "published": "2023-12-19T00:30:21Z", "aliases": [ "CVE-2023-6918" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250214-0009" + }, { "type": "WEB", "url": "https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases" diff --git a/advisories/unreviewed/2024/11/GHSA-882h-ff2x-f86q/GHSA-882h-ff2x-f86q.json b/advisories/unreviewed/2024/11/GHSA-882h-ff2x-f86q/GHSA-882h-ff2x-f86q.json index b78aa3902e3..b94c936cea2 100644 --- a/advisories/unreviewed/2024/11/GHSA-882h-ff2x-f86q/GHSA-882h-ff2x-f86q.json +++ b/advisories/unreviewed/2024/11/GHSA-882h-ff2x-f86q/GHSA-882h-ff2x-f86q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-882h-ff2x-f86q", - "modified": "2024-11-22T21:32:17Z", + "modified": "2025-02-15T03:31:24Z", "published": "2024-11-22T21:32:17Z", "aliases": [ "CVE-2024-11477" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11477" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250214-0007" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1532" diff --git a/advisories/unreviewed/2025/02/GHSA-377p-4737-hx6m/GHSA-377p-4737-hx6m.json b/advisories/unreviewed/2025/02/GHSA-377p-4737-hx6m/GHSA-377p-4737-hx6m.json new file mode 100644 index 00000000000..da500ae8678 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-377p-4737-hx6m/GHSA-377p-4737-hx6m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-377p-4737-hx6m", + "modified": "2025-02-15T03:31:24Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2025-0995" + ], + "details": "Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0995" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/391907159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4v9x-qxmv-4h58/GHSA-4v9x-qxmv-4h58.json b/advisories/unreviewed/2025/02/GHSA-4v9x-qxmv-4h58/GHSA-4v9x-qxmv-4h58.json new file mode 100644 index 00000000000..9812a604594 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4v9x-qxmv-4h58/GHSA-4v9x-qxmv-4h58.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9x-qxmv-4h58", + "modified": "2025-02-15T03:31:25Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2025-0998" + ], + "details": "Out of bounds memory access in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0998" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/386857213" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5c3h-62vh-c2xw/GHSA-5c3h-62vh-c2xw.json b/advisories/unreviewed/2025/02/GHSA-5c3h-62vh-c2xw/GHSA-5c3h-62vh-c2xw.json new file mode 100644 index 00000000000..91786a0573f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5c3h-62vh-c2xw/GHSA-5c3h-62vh-c2xw.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c3h-62vh-c2xw", + "modified": "2025-02-15T03:31:24Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2024-37374" + ], + "details": "Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37374" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jxfh-r792-52qr/GHSA-jxfh-r792-52qr.json b/advisories/unreviewed/2025/02/GHSA-jxfh-r792-52qr/GHSA-jxfh-r792-52qr.json new file mode 100644 index 00000000000..b966b211dda --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jxfh-r792-52qr/GHSA-jxfh-r792-52qr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxfh-r792-52qr", + "modified": "2025-02-15T03:31:24Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2025-0997" + ], + "details": "Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0997" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/391666328" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w46v-c4p8-v28f/GHSA-w46v-c4p8-v28f.json b/advisories/unreviewed/2025/02/GHSA-w46v-c4p8-v28f/GHSA-w46v-c4p8-v28f.json new file mode 100644 index 00000000000..302d381bf61 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w46v-c4p8-v28f/GHSA-w46v-c4p8-v28f.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w46v-c4p8-v28f", + "modified": "2025-02-15T03:31:24Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2024-37375" + ], + "details": "Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wrgh-9j55-488p/GHSA-wrgh-9j55-488p.json b/advisories/unreviewed/2025/02/GHSA-wrgh-9j55-488p/GHSA-wrgh-9j55-488p.json new file mode 100644 index 00000000000..49b4f4bcd01 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wrgh-9j55-488p/GHSA-wrgh-9j55-488p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrgh-9j55-488p", + "modified": "2025-02-15T03:31:24Z", + "published": "2025-02-15T03:31:24Z", + "aliases": [ + "CVE-2025-0996" + ], + "details": "Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0996" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/391788835" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1007" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T02:15:09Z" + } +} \ No newline at end of file