From e18a71ed362f5e1f420e30a75aab01140a57b2fd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Apr 2025 18:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2449-qmg7-pw4p.json | 9 ++- .../GHSA-2742-gccf-cjgj.json | 13 ++++- .../GHSA-2jg2-7q2w-m8v7.json | 9 ++- .../GHSA-3xr4-xhxj-vcwg.json | 13 ++++- .../GHSA-578v-gp2f-f247.json | 13 ++++- .../GHSA-57qp-9wm8-fgr9.json | 13 ++++- .../GHSA-6589-x6h4-26gm.json | 13 ++++- .../GHSA-6v67-8hw7-636g.json | 9 ++- .../GHSA-c335-grgp-6vgc.json | 13 ++++- .../GHSA-c542-5hmc-h473.json | 13 ++++- .../GHSA-ccxg-86pq-6mj7.json | 13 ++++- .../GHSA-cj38-v6qv-2jpj.json | 13 ++++- .../GHSA-jm3m-g3qw-qr2v.json | 13 ++++- .../GHSA-m2q9-qc9x-rvvm.json | 13 ++++- .../GHSA-p3fq-9wj3-h9c3.json | 13 ++++- .../GHSA-qww3-wjff-2gj7.json | 13 ++++- .../GHSA-r65h-347c-jjp4.json | 13 ++++- .../GHSA-4j99-9c7q-m4qw.json | 18 +++++- .../GHSA-5jpw-hxh6-542f.json | 10 +++- .../GHSA-5jq2-gw2c-fg5h.json | 1 + .../GHSA-75rq-26mw-g7fp.json | 3 +- .../GHSA-jm5w-p8rr-g6mm.json | 2 +- .../GHSA-mcr4-p4r2-fwpq.json | 3 +- .../GHSA-p3gh-ph86-vc5x.json | 3 +- .../GHSA-rphr-gf93-vggr.json | 3 +- .../GHSA-x6hj-8gmr-q6jx.json | 3 +- .../GHSA-cpxg-8g4c-4mhp.json | 4 +- .../GHSA-34q4-4758-m3xv.json | 3 +- .../GHSA-whc6-7v67-764g.json | 6 +- .../GHSA-24v2-mrj2-4wpc.json | 4 +- .../GHSA-85qx-mfpj-cvj4.json | 6 +- .../GHSA-928f-3rxq-5jvp.json | 4 +- .../GHSA-37r4-ppph-4wwq.json | 3 +- .../GHSA-7wj9-f5xc-vmq2.json | 6 +- .../GHSA-mwjq-q4w6-76fx.json | 3 +- .../GHSA-v35v-mpjj-v438.json | 3 +- .../GHSA-w523-c69w-6x53.json | 4 +- .../GHSA-2cp9-r2rg-qvgg.json | 4 +- .../GHSA-2rrx-pphc-qfv9.json | 6 +- .../GHSA-39p5-3m6f-c8xp.json | 15 +++-- .../GHSA-4v4v-wmpc-5vh5.json | 56 +++++++++++++++++++ .../GHSA-5gr5-vwj6-rq22.json | 36 ++++++++++++ .../GHSA-5prh-r43c-x8ww.json | 15 +++-- .../GHSA-c26r-vw7p-2m7h.json | 35 ++++++++++++ .../GHSA-cr5x-x94v-gf96.json | 15 +++-- .../GHSA-f2ff-9j2m-p32f.json | 56 +++++++++++++++++++ .../GHSA-fmvx-5hvp-q7fh.json | 15 +++-- .../GHSA-g73c-fw68-pwx3.json | 6 +- .../GHSA-h223-9f6r-286q.json | 56 +++++++++++++++++++ .../GHSA-hc79-964w-vvqg.json | 4 +- .../GHSA-hhp2-jg36-4h6q.json | 36 ++++++++++++ .../GHSA-j2pg-qhxw-x7gx.json | 52 +++++++++++++++++ .../GHSA-jfvg-qm4p-473x.json | 56 +++++++++++++++++++ .../GHSA-jjr5-fpcg-gc53.json | 36 ++++++++++++ .../GHSA-mgrm-96cw-6vxv.json | 15 +++-- .../GHSA-mrfj-vv5j-9gw5.json | 15 +++-- .../GHSA-p7wf-qqfr-f6xp.json | 15 +++-- .../GHSA-pxcm-3fhq-q738.json | 56 +++++++++++++++++++ .../GHSA-rpvv-rj3m-qqgx.json | 15 +++-- .../GHSA-vmv5-h8c6-426p.json | 15 +++-- .../GHSA-w73q-37g7-jp37.json | 15 +++-- .../GHSA-wgx6-p2v7-c87g.json | 56 +++++++++++++++++++ .../GHSA-ww4p-f4jp-c2xm.json | 12 +++- 63 files changed, 897 insertions(+), 117 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5gr5-vwj6-rq22/GHSA-5gr5-vwj6-rq22.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h223-9f6r-286q/GHSA-h223-9f6r-286q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hhp2-jg36-4h6q/GHSA-hhp2-jg36-4h6q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j2pg-qhxw-x7gx/GHSA-j2pg-qhxw-x7gx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pxcm-3fhq-q738/GHSA-pxcm-3fhq-q738.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wgx6-p2v7-c87g/GHSA-wgx6-p2v7-c87g.json diff --git a/advisories/unreviewed/2022/05/GHSA-2449-qmg7-pw4p/GHSA-2449-qmg7-pw4p.json b/advisories/unreviewed/2022/05/GHSA-2449-qmg7-pw4p/GHSA-2449-qmg7-pw4p.json index 47c94f7be1b..25bf6df759e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2449-qmg7-pw4p/GHSA-2449-qmg7-pw4p.json +++ b/advisories/unreviewed/2022/05/GHSA-2449-qmg7-pw4p/GHSA-2449-qmg7-pw4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2449-qmg7-pw4p", - "modified": "2022-05-01T07:24:11Z", + "modified": "2025-04-03T18:30:25Z", "published": "2022-05-01T07:24:11Z", "aliases": [ "CVE-2006-5024" ], "details": "Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-2742-gccf-cjgj/GHSA-2742-gccf-cjgj.json b/advisories/unreviewed/2022/05/GHSA-2742-gccf-cjgj/GHSA-2742-gccf-cjgj.json index 399ee08f105..6346af7fd98 100644 --- a/advisories/unreviewed/2022/05/GHSA-2742-gccf-cjgj/GHSA-2742-gccf-cjgj.json +++ b/advisories/unreviewed/2022/05/GHSA-2742-gccf-cjgj/GHSA-2742-gccf-cjgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2742-gccf-cjgj", - "modified": "2022-05-01T07:30:59Z", + "modified": "2025-04-03T18:30:26Z", "published": "2022-05-01T07:30:59Z", "aliases": [ "CVE-2006-5708" ], "details": "Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json b/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json index 2822b674a13..5f1145dee78 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json +++ b/advisories/unreviewed/2022/05/GHSA-2jg2-7q2w-m8v7/GHSA-2jg2-7q2w-m8v7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2jg2-7q2w-m8v7", - "modified": "2022-05-02T00:05:06Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-02T00:05:06Z", "aliases": [ "CVE-2008-3937" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-3xr4-xhxj-vcwg/GHSA-3xr4-xhxj-vcwg.json b/advisories/unreviewed/2022/05/GHSA-3xr4-xhxj-vcwg/GHSA-3xr4-xhxj-vcwg.json index c1a51e3b1d3..a3523a33635 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xr4-xhxj-vcwg/GHSA-3xr4-xhxj-vcwg.json +++ b/advisories/unreviewed/2022/05/GHSA-3xr4-xhxj-vcwg/GHSA-3xr4-xhxj-vcwg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3xr4-xhxj-vcwg", - "modified": "2022-05-01T07:30:29Z", + "modified": "2025-04-03T18:30:26Z", "published": "2022-05-01T07:30:29Z", "aliases": [ "CVE-2006-5632" ], "details": "Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-578v-gp2f-f247/GHSA-578v-gp2f-f247.json b/advisories/unreviewed/2022/05/GHSA-578v-gp2f-f247/GHSA-578v-gp2f-f247.json index 74f32738f18..f8e3d6df3f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-578v-gp2f-f247/GHSA-578v-gp2f-f247.json +++ b/advisories/unreviewed/2022/05/GHSA-578v-gp2f-f247/GHSA-578v-gp2f-f247.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-578v-gp2f-f247", - "modified": "2022-05-01T07:34:00Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:34:00Z", "aliases": [ "CVE-2006-6024" ], "details": "Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) \"Eudora WorldMail stack overflow\" and (2) \"Eudora WorldMail heap overflow\" modules in VulnDisco Pack. NOTE: Some of these details are obtained from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57qp-9wm8-fgr9/GHSA-57qp-9wm8-fgr9.json b/advisories/unreviewed/2022/05/GHSA-57qp-9wm8-fgr9/GHSA-57qp-9wm8-fgr9.json index ecb16c1a788..fbf9b2965a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-57qp-9wm8-fgr9/GHSA-57qp-9wm8-fgr9.json +++ b/advisories/unreviewed/2022/05/GHSA-57qp-9wm8-fgr9/GHSA-57qp-9wm8-fgr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57qp-9wm8-fgr9", - "modified": "2022-05-01T07:33:51Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:33:51Z", "aliases": [ "CVE-2006-6017" ], "details": "WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6589-x6h4-26gm/GHSA-6589-x6h4-26gm.json b/advisories/unreviewed/2022/05/GHSA-6589-x6h4-26gm/GHSA-6589-x6h4-26gm.json index c69ad60e651..bd12ed53611 100644 --- a/advisories/unreviewed/2022/05/GHSA-6589-x6h4-26gm/GHSA-6589-x6h4-26gm.json +++ b/advisories/unreviewed/2022/05/GHSA-6589-x6h4-26gm/GHSA-6589-x6h4-26gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6589-x6h4-26gm", - "modified": "2022-05-01T07:24:07Z", + "modified": "2025-04-03T18:30:25Z", "published": "2022-05-01T07:24:07Z", "aliases": [ "CVE-2006-5021" ], "details": "Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json b/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json index 6cd265b895f..4cceb303830 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json +++ b/advisories/unreviewed/2022/05/GHSA-6v67-8hw7-636g/GHSA-6v67-8hw7-636g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v67-8hw7-636g", - "modified": "2022-05-02T00:05:05Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-02T00:05:05Z", "aliases": [ "CVE-2008-3935" ], "details": "Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-c335-grgp-6vgc/GHSA-c335-grgp-6vgc.json b/advisories/unreviewed/2022/05/GHSA-c335-grgp-6vgc/GHSA-c335-grgp-6vgc.json index c03fdfb2d56..a11b5845d11 100644 --- a/advisories/unreviewed/2022/05/GHSA-c335-grgp-6vgc/GHSA-c335-grgp-6vgc.json +++ b/advisories/unreviewed/2022/05/GHSA-c335-grgp-6vgc/GHSA-c335-grgp-6vgc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c335-grgp-6vgc", - "modified": "2022-05-01T07:30:33Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:30:33Z", "aliases": [ "CVE-2006-5648" ], "details": "Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list and (2) sys_set_robust_list functions to create processes that cannot be killed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c542-5hmc-h473/GHSA-c542-5hmc-h473.json b/advisories/unreviewed/2022/05/GHSA-c542-5hmc-h473/GHSA-c542-5hmc-h473.json index 36aa2175ec7..33e9794b321 100644 --- a/advisories/unreviewed/2022/05/GHSA-c542-5hmc-h473/GHSA-c542-5hmc-h473.json +++ b/advisories/unreviewed/2022/05/GHSA-c542-5hmc-h473/GHSA-c542-5hmc-h473.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c542-5hmc-h473", - "modified": "2022-05-01T07:27:59Z", + "modified": "2025-04-03T18:30:26Z", "published": "2022-05-01T07:27:59Z", "aliases": [ "CVE-2006-5393" ], "details": "Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccxg-86pq-6mj7/GHSA-ccxg-86pq-6mj7.json b/advisories/unreviewed/2022/05/GHSA-ccxg-86pq-6mj7/GHSA-ccxg-86pq-6mj7.json index 56762262463..4458a5a918e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccxg-86pq-6mj7/GHSA-ccxg-86pq-6mj7.json +++ b/advisories/unreviewed/2022/05/GHSA-ccxg-86pq-6mj7/GHSA-ccxg-86pq-6mj7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ccxg-86pq-6mj7", - "modified": "2022-05-01T07:31:17Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:31:17Z", "aliases": [ "CVE-2006-5738" ], "details": "Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cj38-v6qv-2jpj/GHSA-cj38-v6qv-2jpj.json b/advisories/unreviewed/2022/05/GHSA-cj38-v6qv-2jpj/GHSA-cj38-v6qv-2jpj.json index 27e4d079f32..f21c0ce12ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj38-v6qv-2jpj/GHSA-cj38-v6qv-2jpj.json +++ b/advisories/unreviewed/2022/05/GHSA-cj38-v6qv-2jpj/GHSA-cj38-v6qv-2jpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj38-v6qv-2jpj", - "modified": "2022-05-01T07:24:06Z", + "modified": "2025-04-03T18:30:25Z", "published": "2022-05-01T07:24:06Z", "aliases": [ "CVE-2006-5014" ], "details": "Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm3m-g3qw-qr2v/GHSA-jm3m-g3qw-qr2v.json b/advisories/unreviewed/2022/05/GHSA-jm3m-g3qw-qr2v/GHSA-jm3m-g3qw-qr2v.json index b7f047c5d0e..07efdcfda27 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm3m-g3qw-qr2v/GHSA-jm3m-g3qw-qr2v.json +++ b/advisories/unreviewed/2022/05/GHSA-jm3m-g3qw-qr2v/GHSA-jm3m-g3qw-qr2v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jm3m-g3qw-qr2v", - "modified": "2022-05-01T07:30:07Z", + "modified": "2025-04-03T18:30:26Z", "published": "2022-05-01T07:30:07Z", "aliases": [ "CVE-2006-5610" ], "details": "PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2q9-qc9x-rvvm/GHSA-m2q9-qc9x-rvvm.json b/advisories/unreviewed/2022/05/GHSA-m2q9-qc9x-rvvm/GHSA-m2q9-qc9x-rvvm.json index 8cb87090270..9a846ca9170 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2q9-qc9x-rvvm/GHSA-m2q9-qc9x-rvvm.json +++ b/advisories/unreviewed/2022/05/GHSA-m2q9-qc9x-rvvm/GHSA-m2q9-qc9x-rvvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2q9-qc9x-rvvm", - "modified": "2022-05-01T07:30:04Z", + "modified": "2025-04-03T18:30:26Z", "published": "2022-05-01T07:30:04Z", "aliases": [ "CVE-2006-5603" ], "details": "SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3fq-9wj3-h9c3/GHSA-p3fq-9wj3-h9c3.json b/advisories/unreviewed/2022/05/GHSA-p3fq-9wj3-h9c3/GHSA-p3fq-9wj3-h9c3.json index fdf4bfb06f0..030c080660e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3fq-9wj3-h9c3/GHSA-p3fq-9wj3-h9c3.json +++ b/advisories/unreviewed/2022/05/GHSA-p3fq-9wj3-h9c3/GHSA-p3fq-9wj3-h9c3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p3fq-9wj3-h9c3", - "modified": "2022-05-01T07:33:52Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:33:52Z", "aliases": [ "CVE-2006-6016" ], "details": "wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qww3-wjff-2gj7/GHSA-qww3-wjff-2gj7.json b/advisories/unreviewed/2022/05/GHSA-qww3-wjff-2gj7/GHSA-qww3-wjff-2gj7.json index 188c8240911..bebe17e6988 100644 --- a/advisories/unreviewed/2022/05/GHSA-qww3-wjff-2gj7/GHSA-qww3-wjff-2gj7.json +++ b/advisories/unreviewed/2022/05/GHSA-qww3-wjff-2gj7/GHSA-qww3-wjff-2gj7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qww3-wjff-2gj7", - "modified": "2022-05-01T07:30:35Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:30:35Z", "aliases": [ "CVE-2006-5649" ], "details": "Unspecified vulnerability in the \"alignment check exception handling\" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (kernel panic) via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r65h-347c-jjp4/GHSA-r65h-347c-jjp4.json b/advisories/unreviewed/2022/05/GHSA-r65h-347c-jjp4/GHSA-r65h-347c-jjp4.json index 9dad5b41d58..de57a106af8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r65h-347c-jjp4/GHSA-r65h-347c-jjp4.json +++ b/advisories/unreviewed/2022/05/GHSA-r65h-347c-jjp4/GHSA-r65h-347c-jjp4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r65h-347c-jjp4", - "modified": "2022-05-01T07:34:00Z", + "modified": "2025-04-03T18:30:27Z", "published": "2022-05-01T07:34:00Z", "aliases": [ "CVE-2006-6025" ], "details": "QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-4j99-9c7q-m4qw/GHSA-4j99-9c7q-m4qw.json b/advisories/unreviewed/2023/01/GHSA-4j99-9c7q-m4qw/GHSA-4j99-9c7q-m4qw.json index 6c913e73086..cc9720264b1 100644 --- a/advisories/unreviewed/2023/01/GHSA-4j99-9c7q-m4qw/GHSA-4j99-9c7q-m4qw.json +++ b/advisories/unreviewed/2023/01/GHSA-4j99-9c7q-m4qw/GHSA-4j99-9c7q-m4qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j99-9c7q-m4qw", - "modified": "2023-01-27T15:30:32Z", + "modified": "2025-04-03T18:30:36Z", "published": "2023-01-20T21:30:30Z", "aliases": [ "CVE-2022-47021" @@ -27,6 +27,22 @@ "type": "WEB", "url": "https://github.com/xiph/opusfile/commit/0a4cd796df5b030cb866f3f4a5e41a4b92caddf5" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ODIA6QRIRBNF2HRXOE5VCZ2AFP4ZB4R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4LIKBLOE433RA44YTYUZLED4IOWJG5DV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ED4CWLBR2WQ2IXXTHZ24UYZBRNCLMJXH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYPAQANM2ZNPXRBFOS5NFXNJ7O4Q3OBD" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ODIA6QRIRBNF2HRXOE5VCZ2AFP4ZB4R" diff --git a/advisories/unreviewed/2023/01/GHSA-5jpw-hxh6-542f/GHSA-5jpw-hxh6-542f.json b/advisories/unreviewed/2023/01/GHSA-5jpw-hxh6-542f/GHSA-5jpw-hxh6-542f.json index 15d3605812d..3eb91ace5ab 100644 --- a/advisories/unreviewed/2023/01/GHSA-5jpw-hxh6-542f/GHSA-5jpw-hxh6-542f.json +++ b/advisories/unreviewed/2023/01/GHSA-5jpw-hxh6-542f/GHSA-5jpw-hxh6-542f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5jpw-hxh6-542f", - "modified": "2023-01-27T15:30:32Z", + "modified": "2025-04-03T18:30:36Z", "published": "2023-01-20T21:30:30Z", "aliases": [ "CVE-2022-47024" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/vim/vim/commit/a63ad78ed31e36dbdf3a9cd28071dcdbefce7d19" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWIJBSQX53P7DHV77KRXJIXA4GH7XHC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EX6N2DB75A73MQGVW3CS4VTNPAYVM2M" diff --git a/advisories/unreviewed/2023/01/GHSA-5jq2-gw2c-fg5h/GHSA-5jq2-gw2c-fg5h.json b/advisories/unreviewed/2023/01/GHSA-5jq2-gw2c-fg5h/GHSA-5jq2-gw2c-fg5h.json index eddf7da72b3..a864fd48f69 100644 --- a/advisories/unreviewed/2023/01/GHSA-5jq2-gw2c-fg5h/GHSA-5jq2-gw2c-fg5h.json +++ b/advisories/unreviewed/2023/01/GHSA-5jq2-gw2c-fg5h/GHSA-5jq2-gw2c-fg5h.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/01/GHSA-75rq-26mw-g7fp/GHSA-75rq-26mw-g7fp.json b/advisories/unreviewed/2023/01/GHSA-75rq-26mw-g7fp/GHSA-75rq-26mw-g7fp.json index 8bcb5717636..efae55c669a 100644 --- a/advisories/unreviewed/2023/01/GHSA-75rq-26mw-g7fp/GHSA-75rq-26mw-g7fp.json +++ b/advisories/unreviewed/2023/01/GHSA-75rq-26mw-g7fp/GHSA-75rq-26mw-g7fp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jm5w-p8rr-g6mm/GHSA-jm5w-p8rr-g6mm.json b/advisories/unreviewed/2023/01/GHSA-jm5w-p8rr-g6mm/GHSA-jm5w-p8rr-g6mm.json index 9cfede63795..b47efb3329a 100644 --- a/advisories/unreviewed/2023/01/GHSA-jm5w-p8rr-g6mm/GHSA-jm5w-p8rr-g6mm.json +++ b/advisories/unreviewed/2023/01/GHSA-jm5w-p8rr-g6mm/GHSA-jm5w-p8rr-g6mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm5w-p8rr-g6mm", - "modified": "2023-02-06T21:30:34Z", + "modified": "2025-04-03T18:30:33Z", "published": "2023-01-20T18:30:22Z", "aliases": [ "CVE-2022-47732" diff --git a/advisories/unreviewed/2023/01/GHSA-mcr4-p4r2-fwpq/GHSA-mcr4-p4r2-fwpq.json b/advisories/unreviewed/2023/01/GHSA-mcr4-p4r2-fwpq/GHSA-mcr4-p4r2-fwpq.json index 63aca275715..04f9ab0217e 100644 --- a/advisories/unreviewed/2023/01/GHSA-mcr4-p4r2-fwpq/GHSA-mcr4-p4r2-fwpq.json +++ b/advisories/unreviewed/2023/01/GHSA-mcr4-p4r2-fwpq/GHSA-mcr4-p4r2-fwpq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-p3gh-ph86-vc5x/GHSA-p3gh-ph86-vc5x.json b/advisories/unreviewed/2023/01/GHSA-p3gh-ph86-vc5x/GHSA-p3gh-ph86-vc5x.json index 4e23730d603..76ab3d1b0d0 100644 --- a/advisories/unreviewed/2023/01/GHSA-p3gh-ph86-vc5x/GHSA-p3gh-ph86-vc5x.json +++ b/advisories/unreviewed/2023/01/GHSA-p3gh-ph86-vc5x/GHSA-p3gh-ph86-vc5x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-rphr-gf93-vggr/GHSA-rphr-gf93-vggr.json b/advisories/unreviewed/2023/01/GHSA-rphr-gf93-vggr/GHSA-rphr-gf93-vggr.json index 1555f757d63..3fc469b7121 100644 --- a/advisories/unreviewed/2023/01/GHSA-rphr-gf93-vggr/GHSA-rphr-gf93-vggr.json +++ b/advisories/unreviewed/2023/01/GHSA-rphr-gf93-vggr/GHSA-rphr-gf93-vggr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-x6hj-8gmr-q6jx/GHSA-x6hj-8gmr-q6jx.json b/advisories/unreviewed/2023/01/GHSA-x6hj-8gmr-q6jx/GHSA-x6hj-8gmr-q6jx.json index 3e7bc7d5a75..5511b5c37a5 100644 --- a/advisories/unreviewed/2023/01/GHSA-x6hj-8gmr-q6jx/GHSA-x6hj-8gmr-q6jx.json +++ b/advisories/unreviewed/2023/01/GHSA-x6hj-8gmr-q6jx/GHSA-x6hj-8gmr-q6jx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json b/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json index c1316c15887..d7743384028 100644 --- a/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json +++ b/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-34q4-4758-m3xv/GHSA-34q4-4758-m3xv.json b/advisories/unreviewed/2024/12/GHSA-34q4-4758-m3xv/GHSA-34q4-4758-m3xv.json index 1d7b324177f..2c0ce76f3df 100644 --- a/advisories/unreviewed/2024/12/GHSA-34q4-4758-m3xv/GHSA-34q4-4758-m3xv.json +++ b/advisories/unreviewed/2024/12/GHSA-34q4-4758-m3xv/GHSA-34q4-4758-m3xv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-whc6-7v67-764g/GHSA-whc6-7v67-764g.json b/advisories/unreviewed/2024/12/GHSA-whc6-7v67-764g/GHSA-whc6-7v67-764g.json index 3e9b9daec1b..3ea0f2241e9 100644 --- a/advisories/unreviewed/2024/12/GHSA-whc6-7v67-764g/GHSA-whc6-7v67-764g.json +++ b/advisories/unreviewed/2024/12/GHSA-whc6-7v67-764g/GHSA-whc6-7v67-764g.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whc6-7v67-764g", - "modified": "2024-12-20T18:31:31Z", + "modified": "2025-04-03T18:30:47Z", "published": "2024-12-19T21:31:11Z", "aliases": [ "CVE-2024-12672" ], "details": "A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json index 96b990bbd69..7dd29d8c97c 100644 --- a/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json +++ b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json b/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json index b8859a04285..5e9624a0748 100644 --- a/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json +++ b/advisories/unreviewed/2025/01/GHSA-85qx-mfpj-cvj4/GHSA-85qx-mfpj-cvj4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85qx-mfpj-cvj4", - "modified": "2025-01-26T06:30:48Z", + "modified": "2025-04-03T18:30:53Z", "published": "2025-01-26T06:30:48Z", "aliases": [ "CVE-2024-10628" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10628" }, + { + "type": "WEB", + "url": "https://abrahack.com/posts/quiz-maker-sqli" + }, { "type": "WEB", "url": "https://ays-pro.com/changelog-for-quiz-maker-pro" diff --git a/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json index 2433810c1f0..f6e899929de 100644 --- a/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json +++ b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-37r4-ppph-4wwq/GHSA-37r4-ppph-4wwq.json b/advisories/unreviewed/2025/03/GHSA-37r4-ppph-4wwq/GHSA-37r4-ppph-4wwq.json index 347faffa584..0e427de6b62 100644 --- a/advisories/unreviewed/2025/03/GHSA-37r4-ppph-4wwq/GHSA-37r4-ppph-4wwq.json +++ b/advisories/unreviewed/2025/03/GHSA-37r4-ppph-4wwq/GHSA-37r4-ppph-4wwq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json b/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json index 1af813f4bfd..5cf5b027396 100644 --- a/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json +++ b/advisories/unreviewed/2025/03/GHSA-7wj9-f5xc-vmq2/GHSA-7wj9-f5xc-vmq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wj9-f5xc-vmq2", - "modified": "2025-03-31T21:32:49Z", + "modified": "2025-04-03T18:30:56Z", "published": "2025-03-31T21:32:49Z", "aliases": [ "CVE-2024-24456" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-mwjq-q4w6-76fx/GHSA-mwjq-q4w6-76fx.json b/advisories/unreviewed/2025/03/GHSA-mwjq-q4w6-76fx/GHSA-mwjq-q4w6-76fx.json index 374e3a1c6fc..d79d56d90b2 100644 --- a/advisories/unreviewed/2025/03/GHSA-mwjq-q4w6-76fx/GHSA-mwjq-q4w6-76fx.json +++ b/advisories/unreviewed/2025/03/GHSA-mwjq-q4w6-76fx/GHSA-mwjq-q4w6-76fx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-v35v-mpjj-v438/GHSA-v35v-mpjj-v438.json b/advisories/unreviewed/2025/03/GHSA-v35v-mpjj-v438/GHSA-v35v-mpjj-v438.json index 98bfa0dd006..3794bae6e54 100644 --- a/advisories/unreviewed/2025/03/GHSA-v35v-mpjj-v438/GHSA-v35v-mpjj-v438.json +++ b/advisories/unreviewed/2025/03/GHSA-v35v-mpjj-v438/GHSA-v35v-mpjj-v438.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json index 6af8b2fd38d..097886c4c70 100644 --- a/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json +++ b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json index dc71660cd76..b4cd5afbe47 100644 --- a/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json +++ b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2rrx-pphc-qfv9/GHSA-2rrx-pphc-qfv9.json b/advisories/unreviewed/2025/04/GHSA-2rrx-pphc-qfv9/GHSA-2rrx-pphc-qfv9.json index 85c6d039d8f..fe90ae5c0f9 100644 --- a/advisories/unreviewed/2025/04/GHSA-2rrx-pphc-qfv9/GHSA-2rrx-pphc-qfv9.json +++ b/advisories/unreviewed/2025/04/GHSA-2rrx-pphc-qfv9/GHSA-2rrx-pphc-qfv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rrx-pphc-qfv9", - "modified": "2025-04-03T15:31:13Z", + "modified": "2025-04-03T18:30:58Z", "published": "2025-04-03T15:31:13Z", "aliases": [ "CVE-2025-2946" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json b/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json index 98ab2fb7e60..c23d0b44f28 100644 --- a/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json +++ b/advisories/unreviewed/2025/04/GHSA-39p5-3m6f-c8xp/GHSA-39p5-3m6f-c8xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-39p5-3m6f-c8xp", - "modified": "2025-04-02T21:30:51Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-02T21:30:51Z", "aliases": [ "CVE-2025-29063" ], "details": "An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T21:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json b/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json new file mode 100644 index 00000000000..c1ff5a28d6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4v4v-wmpc-5vh5/GHSA-4v4v-wmpc-5vh5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v4v-wmpc-5vh5", + "modified": "2025-04-03T18:30:58Z", + "published": "2025-04-03T18:30:58Z", + "aliases": [ + "CVE-2025-3164" + ], + "details": "A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3164" + }, + { + "type": "WEB", + "url": "https://github.com/tencentmusic/supersonic/issues/2193" + }, + { + "type": "WEB", + "url": "https://github.com/tencentmusic/supersonic/issues/2193#issue-2945884387" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.542528" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5gr5-vwj6-rq22/GHSA-5gr5-vwj6-rq22.json b/advisories/unreviewed/2025/04/GHSA-5gr5-vwj6-rq22/GHSA-5gr5-vwj6-rq22.json new file mode 100644 index 00000000000..2cf2d088671 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5gr5-vwj6-rq22/GHSA-5gr5-vwj6-rq22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gr5-vwj6-rq22", + "modified": "2025-04-03T18:30:58Z", + "published": "2025-04-03T18:30:58Z", + "aliases": [ + "CVE-2025-29987" + ], + "details": "Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29987" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300899/dsa-2025-139-dell-technologies-powerprotect-data-domain-security-update-for-a-security-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json b/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json index 3518801e5a9..1bb69427b08 100644 --- a/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json +++ b/advisories/unreviewed/2025/04/GHSA-5prh-r43c-x8ww/GHSA-5prh-r43c-x8ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5prh-r43c-x8ww", - "modified": "2025-04-02T21:30:50Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-02T21:30:50Z", "aliases": [ "CVE-2025-22923" ], "details": "An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T21:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json b/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json new file mode 100644 index 00000000000..8c0f0ab9b0f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c26r-vw7p-2m7h", + "modified": "2025-04-03T18:30:58Z", + "published": "2025-04-03T18:30:58Z", + "aliases": [ + "CVE-2024-4877" + ], + "details": "OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4877" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-4877" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-268" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json b/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json index 25cb531e610..84cc791a47b 100644 --- a/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json +++ b/advisories/unreviewed/2025/04/GHSA-cr5x-x94v-gf96/GHSA-cr5x-x94v-gf96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr5x-x94v-gf96", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30456" ], "details": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json b/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json new file mode 100644 index 00000000000..1939eac6805 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2ff-9j2m-p32f", + "modified": "2025-04-03T18:31:00Z", + "published": "2025-04-03T18:31:00Z", + "aliases": [ + "CVE-2025-3166" + ], + "details": "A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affects the function search_item of the component Search Product Menu. The manipulation of the argument target leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3166" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve_Product-Management-System/blob/main/cve.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303112" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303112" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.542668" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fmvx-5hvp-q7fh/GHSA-fmvx-5hvp-q7fh.json b/advisories/unreviewed/2025/04/GHSA-fmvx-5hvp-q7fh/GHSA-fmvx-5hvp-q7fh.json index 5008c973471..83cdda65372 100644 --- a/advisories/unreviewed/2025/04/GHSA-fmvx-5hvp-q7fh/GHSA-fmvx-5hvp-q7fh.json +++ b/advisories/unreviewed/2025/04/GHSA-fmvx-5hvp-q7fh/GHSA-fmvx-5hvp-q7fh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fmvx-5hvp-q7fh", - "modified": "2025-04-03T09:32:15Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-03T09:32:15Z", "aliases": [ "CVE-2025-22004" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: fix use after free in lec_send()\n\nThe ->send() operation frees skb so save the length before calling\n->send() to avoid a use after free.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T08:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g73c-fw68-pwx3/GHSA-g73c-fw68-pwx3.json b/advisories/unreviewed/2025/04/GHSA-g73c-fw68-pwx3/GHSA-g73c-fw68-pwx3.json index 05739f71140..b0d7b8224e2 100644 --- a/advisories/unreviewed/2025/04/GHSA-g73c-fw68-pwx3/GHSA-g73c-fw68-pwx3.json +++ b/advisories/unreviewed/2025/04/GHSA-g73c-fw68-pwx3/GHSA-g73c-fw68-pwx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g73c-fw68-pwx3", - "modified": "2025-04-03T15:31:13Z", + "modified": "2025-04-03T18:30:58Z", "published": "2025-04-03T15:31:13Z", "aliases": [ "CVE-2025-2945" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h223-9f6r-286q/GHSA-h223-9f6r-286q.json b/advisories/unreviewed/2025/04/GHSA-h223-9f6r-286q/GHSA-h223-9f6r-286q.json new file mode 100644 index 00000000000..dbe2e8cabfe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h223-9f6r-286q/GHSA-h223-9f6r-286q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h223-9f6r-286q", + "modified": "2025-04-03T18:31:00Z", + "published": "2025-04-03T18:31:00Z", + "aliases": [ + "CVE-2025-3168" + ], + "details": "A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3168" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303127" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303127" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json b/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json index c4b18b70d0e..41b7329b9e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json +++ b/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-hhp2-jg36-4h6q/GHSA-hhp2-jg36-4h6q.json b/advisories/unreviewed/2025/04/GHSA-hhp2-jg36-4h6q/GHSA-hhp2-jg36-4h6q.json new file mode 100644 index 00000000000..8b9daf0ea6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hhp2-jg36-4h6q/GHSA-hhp2-jg36-4h6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhp2-jg36-4h6q", + "modified": "2025-04-03T18:30:59Z", + "published": "2025-04-03T18:30:59Z", + "aliases": [ + "CVE-2025-32054" + ], + "details": "In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32054" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2pg-qhxw-x7gx/GHSA-j2pg-qhxw-x7gx.json b/advisories/unreviewed/2025/04/GHSA-j2pg-qhxw-x7gx/GHSA-j2pg-qhxw-x7gx.json new file mode 100644 index 00000000000..14405aab819 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2pg-qhxw-x7gx/GHSA-j2pg-qhxw-x7gx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2pg-qhxw-x7gx", + "modified": "2025-04-03T18:30:59Z", + "published": "2025-04-03T18:30:59Z", + "aliases": [ + "CVE-2025-3165" + ], + "details": "A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend.py. The manipulation of the argument ckpt_path/quant_ckpt_dir leads to deserialization. An attack has to be approached locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3165" + }, + { + "type": "WEB", + "url": "https://github.com/thu-pacman/chitu/issues/32" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.542529" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json b/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json new file mode 100644 index 00000000000..cf2860ec889 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfvg-qm4p-473x", + "modified": "2025-04-03T18:30:59Z", + "published": "2025-04-03T18:30:58Z", + "aliases": [ + "CVE-2025-3163" + ], + "details": "A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3163" + }, + { + "type": "WEB", + "url": "https://github.com/InternLM/lmdeploy/issues/3254" + }, + { + "type": "WEB", + "url": "https://github.com/InternLM/lmdeploy/issues/3254#issue-2918865448" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.542527" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json b/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json new file mode 100644 index 00000000000..96cbf748780 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjr5-fpcg-gc53", + "modified": "2025-04-03T18:30:58Z", + "published": "2025-04-03T18:30:58Z", + "aliases": [ + "CVE-2025-22457" + ], + "details": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22457" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json b/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json index f1241825f92..b2f5a3669aa 100644 --- a/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json +++ b/advisories/unreviewed/2025/04/GHSA-mgrm-96cw-6vxv/GHSA-mgrm-96cw-6vxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgrm-96cw-6vxv", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-03T18:30:56Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30449" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json b/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json index 142b04892cd..b2506206f10 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json +++ b/advisories/unreviewed/2025/04/GHSA-mrfj-vv5j-9gw5/GHSA-mrfj-vv5j-9gw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrfj-vv5j-9gw5", - "modified": "2025-04-02T21:30:50Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-02T21:30:50Z", "aliases": [ "CVE-2025-22924" ], "details": "OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T21:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json index 03283661ad0..e20392ddd1d 100644 --- a/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json +++ b/advisories/unreviewed/2025/04/GHSA-p7wf-qqfr-f6xp/GHSA-p7wf-qqfr-f6xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p7wf-qqfr-f6xp", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24213" ], "details": "This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A type confusion issue could lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pxcm-3fhq-q738/GHSA-pxcm-3fhq-q738.json b/advisories/unreviewed/2025/04/GHSA-pxcm-3fhq-q738/GHSA-pxcm-3fhq-q738.json new file mode 100644 index 00000000000..e06cd54f6e2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pxcm-3fhq-q738/GHSA-pxcm-3fhq-q738.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxcm-3fhq-q738", + "modified": "2025-04-03T18:31:00Z", + "published": "2025-04-03T18:31:00Z", + "aliases": [ + "CVE-2025-3169" + ], + "details": "A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tool/saveAttachment.php. The manipulation of the argument attachmentFiles leads to unrestricted upload. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 12.0.3 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains, that \"this vulnerability can be exploited only on not securely installed instances, as it is adviced during product install: attachment directory should be out of web reach, so that even if executable file can be uploaded, it cannot be executed through the web.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3169" + }, + { + "type": "WEB", + "url": "https://github.com/deadmilkman/cve-reports/blob/main/01-projeqtor-rce/readme.md" + }, + { + "type": "WEB", + "url": "https://github.com/deadmilkman/cve-reports/blob/main/01-projeqtor-rce/readme.md#proof-of-concept-poc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303128" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303128" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json b/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json index 5df96cb079a..2f00e71dadd 100644 --- a/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json +++ b/advisories/unreviewed/2025/04/GHSA-rpvv-rj3m-qqgx/GHSA-rpvv-rj3m-qqgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rpvv-rj3m-qqgx", - "modified": "2025-04-02T21:30:51Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-02T21:30:51Z", "aliases": [ "CVE-2025-29062" ], "details": "An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T21:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vmv5-h8c6-426p/GHSA-vmv5-h8c6-426p.json b/advisories/unreviewed/2025/04/GHSA-vmv5-h8c6-426p/GHSA-vmv5-h8c6-426p.json index 17b5131bd02..d1fc074a0af 100644 --- a/advisories/unreviewed/2025/04/GHSA-vmv5-h8c6-426p/GHSA-vmv5-h8c6-426p.json +++ b/advisories/unreviewed/2025/04/GHSA-vmv5-h8c6-426p/GHSA-vmv5-h8c6-426p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmv5-h8c6-426p", - "modified": "2025-04-03T09:32:15Z", + "modified": "2025-04-03T18:30:58Z", "published": "2025-04-03T09:32:15Z", "aliases": [ "CVE-2025-21999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: fix UAF in proc_get_inode()\n\nFix race between rmmod and /proc/XXX's inode instantiation.\n\nThe bug is that pde->proc_ops don't belong to /proc, it belongs to a\nmodule, therefore dereferencing it after /proc entry has been registered\nis a bug unless use_pde/unuse_pde() pair has been used.\n\nuse_pde/unuse_pde can be avoided (2 atomic ops!) because pde->proc_ops\nnever changes so information necessary for inode instantiation can be\nsaved _before_ proc_register() in PDE itself and used later, avoiding\npde->proc_ops->... dereference.\n\n rmmod lookup\nsys_delete_module\n proc_lookup_de\n\t\t\t pde_get(de);\n\t\t\t proc_get_inode(dir->i_sb, de);\n mod->exit()\n proc_remove\n remove_proc_subtree\n proc_entry_rundown(de);\n free_module(mod);\n\n if (S_ISREG(inode->i_mode))\n\t if (de->proc_ops->proc_read_iter)\n --> As module is already freed, will trigger UAF\n\nBUG: unable to handle page fault for address: fffffbfff80a702b\nPGD 817fc4067 P4D 817fc4067 PUD 817fc0067 PMD 102ef4067 PTE 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 26 UID: 0 PID: 2667 Comm: ls Tainted: G\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nRIP: 0010:proc_get_inode+0x302/0x6e0\nRSP: 0018:ffff88811c837998 EFLAGS: 00010a06\nRAX: dffffc0000000000 RBX: ffffffffc0538140 RCX: 0000000000000007\nRDX: 1ffffffff80a702b RSI: 0000000000000001 RDI: ffffffffc0538158\nRBP: ffff8881299a6000 R08: 0000000067bbe1e5 R09: 1ffff11023906f20\nR10: ffffffffb560ca07 R11: ffffffffb2b43a58 R12: ffff888105bb78f0\nR13: ffff888100518048 R14: ffff8881299a6004 R15: 0000000000000001\nFS: 00007f95b9686840(0000) GS:ffff8883af100000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: fffffbfff80a702b CR3: 0000000117dd2000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n proc_lookup_de+0x11f/0x2e0\n __lookup_slow+0x188/0x350\n walk_component+0x2ab/0x4f0\n path_lookupat+0x120/0x660\n filename_lookup+0x1ce/0x560\n vfs_statx+0xac/0x150\n __do_sys_newstat+0x96/0x110\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n[adobriyan@gmail.com: don't do 2 atomic ops on the common path]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T08:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json b/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json index 1c0bbeadaf2..709d82e1b50 100644 --- a/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json +++ b/advisories/unreviewed/2025/04/GHSA-w73q-37g7-jp37/GHSA-w73q-37g7-jp37.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w73q-37g7-jp37", - "modified": "2025-04-02T21:30:49Z", + "modified": "2025-04-03T18:30:57Z", "published": "2025-04-02T21:30:49Z", "aliases": [ "CVE-2024-37917" ], "details": "Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T21:15:30Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wgx6-p2v7-c87g/GHSA-wgx6-p2v7-c87g.json b/advisories/unreviewed/2025/04/GHSA-wgx6-p2v7-c87g/GHSA-wgx6-p2v7-c87g.json new file mode 100644 index 00000000000..f852d57fa88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wgx6-p2v7-c87g/GHSA-wgx6-p2v7-c87g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgx6-p2v7-c87g", + "modified": "2025-04-03T18:31:00Z", + "published": "2025-04-03T18:31:00Z", + "aliases": [ + "CVE-2025-3167" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3167" + }, + { + "type": "WEB", + "url": "https://github.com/LZY0522/CVE/blob/main/CVE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303113" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303113" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543150" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-03T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ww4p-f4jp-c2xm/GHSA-ww4p-f4jp-c2xm.json b/advisories/unreviewed/2025/04/GHSA-ww4p-f4jp-c2xm/GHSA-ww4p-f4jp-c2xm.json index b39e11843d4..0b749398e4e 100644 --- a/advisories/unreviewed/2025/04/GHSA-ww4p-f4jp-c2xm/GHSA-ww4p-f4jp-c2xm.json +++ b/advisories/unreviewed/2025/04/GHSA-ww4p-f4jp-c2xm/GHSA-ww4p-f4jp-c2xm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ww4p-f4jp-c2xm", - "modified": "2025-04-02T03:31:43Z", + "modified": "2025-04-03T18:30:56Z", "published": "2025-04-02T03:31:43Z", "aliases": [ "CVE-2025-3070" ], "details": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,9 +30,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1287", "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T01:15:38Z"