diff --git a/advisories/unreviewed/2022/02/GHSA-498m-2jp9-66x5/GHSA-498m-2jp9-66x5.json b/advisories/unreviewed/2022/02/GHSA-498m-2jp9-66x5/GHSA-498m-2jp9-66x5.json index 91f326da09a..3cc2b4323c5 100644 --- a/advisories/unreviewed/2022/02/GHSA-498m-2jp9-66x5/GHSA-498m-2jp9-66x5.json +++ b/advisories/unreviewed/2022/02/GHSA-498m-2jp9-66x5/GHSA-498m-2jp9-66x5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-498m-2jp9-66x5", - "modified": "2022-02-11T00:01:10Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-02-08T00:00:31Z", "aliases": [ "CVE-2021-43926" ], "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-fgfm-hjh9-vxjr/GHSA-fgfm-hjh9-vxjr.json b/advisories/unreviewed/2022/02/GHSA-fgfm-hjh9-vxjr/GHSA-fgfm-hjh9-vxjr.json index d2ab299b9b8..806992cb4b6 100644 --- a/advisories/unreviewed/2022/02/GHSA-fgfm-hjh9-vxjr/GHSA-fgfm-hjh9-vxjr.json +++ b/advisories/unreviewed/2022/02/GHSA-fgfm-hjh9-vxjr/GHSA-fgfm-hjh9-vxjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fgfm-hjh9-vxjr", - "modified": "2022-02-11T00:01:09Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-02-08T00:00:30Z", "aliases": [ "CVE-2022-22679" ], "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-fhcm-g3vr-2xmr/GHSA-fhcm-g3vr-2xmr.json b/advisories/unreviewed/2022/02/GHSA-fhcm-g3vr-2xmr/GHSA-fhcm-g3vr-2xmr.json index b09c6120943..6c7f79261dd 100644 --- a/advisories/unreviewed/2022/02/GHSA-fhcm-g3vr-2xmr/GHSA-fhcm-g3vr-2xmr.json +++ b/advisories/unreviewed/2022/02/GHSA-fhcm-g3vr-2xmr/GHSA-fhcm-g3vr-2xmr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fhcm-g3vr-2xmr", - "modified": "2022-02-11T00:01:11Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-02-08T00:00:31Z", "aliases": [ "CVE-2022-22680" ], "details": "Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-vcp7-93pm-gh73/GHSA-vcp7-93pm-gh73.json b/advisories/unreviewed/2022/02/GHSA-vcp7-93pm-gh73/GHSA-vcp7-93pm-gh73.json index b535bbe02f2..403663e20d4 100644 --- a/advisories/unreviewed/2022/02/GHSA-vcp7-93pm-gh73/GHSA-vcp7-93pm-gh73.json +++ b/advisories/unreviewed/2022/02/GHSA-vcp7-93pm-gh73/GHSA-vcp7-93pm-gh73.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcp7-93pm-gh73", - "modified": "2022-02-11T00:01:10Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-02-08T00:00:30Z", "aliases": [ "CVE-2021-43927" ], "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/02/GHSA-vm8g-vm3g-c3rm/GHSA-vm8g-vm3g-c3rm.json b/advisories/unreviewed/2022/02/GHSA-vm8g-vm3g-c3rm/GHSA-vm8g-vm3g-c3rm.json index a754a48958d..b564d25d4bf 100644 --- a/advisories/unreviewed/2022/02/GHSA-vm8g-vm3g-c3rm/GHSA-vm8g-vm3g-c3rm.json +++ b/advisories/unreviewed/2022/02/GHSA-vm8g-vm3g-c3rm/GHSA-vm8g-vm3g-c3rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vm8g-vm3g-c3rm", - "modified": "2022-02-11T00:01:10Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-02-08T00:00:31Z", "aliases": [ "CVE-2021-43925" ], "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json b/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json index afe5cfe31af..28e9ae96d48 100644 --- a/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json +++ b/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4px-ph3f-7964", - "modified": "2022-04-30T00:02:19Z", + "modified": "2025-01-14T21:31:36Z", "published": "2022-04-30T00:02:19Z", "aliases": [ "CVE-2017-14491" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://www.mail-archive.com/dnsmasq-discuss@lists.thekelleys.org.uk/msg11664.html" }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html" + }, + { + "type": "WEB", + "url": "https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html" + }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/973527" @@ -71,6 +79,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXRZ2W6TV6NLUJC5NOFBSG6PZSMDTYPV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MMPCJOYPPL4B5RBY4U425PWG7EETDTD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf" @@ -135,6 +155,10 @@ "type": "WEB", "url": "http://thekelleys.org.uk/dnsmasq/CHANGELOG" }, + { + "type": "WEB", + "url": "http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=0549c73b7ea6b22a3c49beb4d432f185a81efcbc" + }, { "type": "WEB", "url": "http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=0549c73b7ea6b22a3c49beb4d432f185a81efcbc" diff --git a/advisories/unreviewed/2022/05/GHSA-3p35-64mh-v96v/GHSA-3p35-64mh-v96v.json b/advisories/unreviewed/2022/05/GHSA-3p35-64mh-v96v/GHSA-3p35-64mh-v96v.json index 270abefeaac..b8e9a3101e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p35-64mh-v96v/GHSA-3p35-64mh-v96v.json +++ b/advisories/unreviewed/2022/05/GHSA-3p35-64mh-v96v/GHSA-3p35-64mh-v96v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3p35-64mh-v96v", - "modified": "2022-08-13T00:00:31Z", + "modified": "2025-01-14T21:31:39Z", "published": "2022-05-24T16:53:18Z", "aliases": [ "CVE-2019-9513" @@ -21,7 +21,15 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2692" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" }, { "type": "WEB", @@ -59,6 +67,10 @@ "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS" + }, { "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&utm_medium=RSS" @@ -91,6 +103,10 @@ "type": "WEB", "url": "https://www.synology.com/security/advisory/Synology_SA_19_33" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2692" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:2745" @@ -157,11 +173,23 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD" }, { "type": "WEB", @@ -189,7 +217,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-487r-hmj9-h7h2/GHSA-487r-hmj9-h7h2.json b/advisories/unreviewed/2022/05/GHSA-487r-hmj9-h7h2/GHSA-487r-hmj9-h7h2.json index 1933b9f3bb4..5c7c1128d61 100644 --- a/advisories/unreviewed/2022/05/GHSA-487r-hmj9-h7h2/GHSA-487r-hmj9-h7h2.json +++ b/advisories/unreviewed/2022/05/GHSA-487r-hmj9-h7h2/GHSA-487r-hmj9-h7h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-487r-hmj9-h7h2", - "modified": "2022-05-24T19:05:59Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:05:59Z", "aliases": [ "CVE-2021-29084" ], "details": "Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-4pfw-794r-7wqp/GHSA-4pfw-794r-7wqp.json b/advisories/unreviewed/2022/05/GHSA-4pfw-794r-7wqp/GHSA-4pfw-794r-7wqp.json index 1f836efbfbf..432a0f9ed41 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pfw-794r-7wqp/GHSA-4pfw-794r-7wqp.json +++ b/advisories/unreviewed/2022/05/GHSA-4pfw-794r-7wqp/GHSA-4pfw-794r-7wqp.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4xw8-rvqf-qchf/GHSA-4xw8-rvqf-qchf.json b/advisories/unreviewed/2022/05/GHSA-4xw8-rvqf-qchf/GHSA-4xw8-rvqf-qchf.json index 0b5374677ff..0756e17df36 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xw8-rvqf-qchf/GHSA-4xw8-rvqf-qchf.json +++ b/advisories/unreviewed/2022/05/GHSA-4xw8-rvqf-qchf/GHSA-4xw8-rvqf-qchf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-620", "CWE-640" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-59pm-73xx-3pvc/GHSA-59pm-73xx-3pvc.json b/advisories/unreviewed/2022/05/GHSA-59pm-73xx-3pvc/GHSA-59pm-73xx-3pvc.json index e57c001e2c8..3c631d48c85 100644 --- a/advisories/unreviewed/2022/05/GHSA-59pm-73xx-3pvc/GHSA-59pm-73xx-3pvc.json +++ b/advisories/unreviewed/2022/05/GHSA-59pm-73xx-3pvc/GHSA-59pm-73xx-3pvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59pm-73xx-3pvc", - "modified": "2022-05-24T19:06:01Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:06:01Z", "aliases": [ "CVE-2021-27649" ], "details": "Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-59q4-wg74-fxmm/GHSA-59q4-wg74-fxmm.json b/advisories/unreviewed/2022/05/GHSA-59q4-wg74-fxmm/GHSA-59q4-wg74-fxmm.json index 42a7d8b4d55..6fc518291ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-59q4-wg74-fxmm/GHSA-59q4-wg74-fxmm.json +++ b/advisories/unreviewed/2022/05/GHSA-59q4-wg74-fxmm/GHSA-59q4-wg74-fxmm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-74" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-6gw7-c226-vg73/GHSA-6gw7-c226-vg73.json b/advisories/unreviewed/2022/05/GHSA-6gw7-c226-vg73/GHSA-6gw7-c226-vg73.json index 18c4f92a33e..70456164e50 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gw7-c226-vg73/GHSA-6gw7-c226-vg73.json +++ b/advisories/unreviewed/2022/05/GHSA-6gw7-c226-vg73/GHSA-6gw7-c226-vg73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gw7-c226-vg73", - "modified": "2022-08-06T00:00:49Z", + "modified": "2025-01-14T21:31:40Z", "published": "2022-05-24T16:53:19Z", "aliases": [ "CVE-2019-9516" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:2745" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" @@ -67,6 +79,10 @@ "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS" + }, { "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&utm_medium=RSS" @@ -145,7 +161,23 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H472D5HPXN6RRXCNFML3BK5OYC52CXF2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD" }, { "type": "WEB", @@ -170,6 +202,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-8292-4xc6-r7cv/GHSA-8292-4xc6-r7cv.json b/advisories/unreviewed/2022/05/GHSA-8292-4xc6-r7cv/GHSA-8292-4xc6-r7cv.json index 81e80a3234b..c2f8e68ccc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8292-4xc6-r7cv/GHSA-8292-4xc6-r7cv.json +++ b/advisories/unreviewed/2022/05/GHSA-8292-4xc6-r7cv/GHSA-8292-4xc6-r7cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8292-4xc6-r7cv", - "modified": "2023-05-17T03:30:15Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:02:57Z", "aliases": [ "CVE-2021-31439" diff --git a/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json b/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json index f27391b1480..e2c7326b218 100644 --- a/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json +++ b/advisories/unreviewed/2022/05/GHSA-88jq-fmhx-7gr3/GHSA-88jq-fmhx-7gr3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88jq-fmhx-7gr3", - "modified": "2022-05-24T19:03:45Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:03:45Z", "aliases": [ "CVE-2021-29088" ], "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-89fc-749h-w2fj/GHSA-89fc-749h-w2fj.json b/advisories/unreviewed/2022/05/GHSA-89fc-749h-w2fj/GHSA-89fc-749h-w2fj.json index 4de1e14cbc8..56f91274bbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-89fc-749h-w2fj/GHSA-89fc-749h-w2fj.json +++ b/advisories/unreviewed/2022/05/GHSA-89fc-749h-w2fj/GHSA-89fc-749h-w2fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89fc-749h-w2fj", - "modified": "2022-08-13T00:00:31Z", + "modified": "2025-01-14T21:31:39Z", "published": "2022-05-24T16:53:17Z", "aliases": [ "CVE-2019-9511" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9511" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2692" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAZZEVTCN2B4WT6AIBJ7XGYJMBTORJU5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" @@ -63,6 +75,10 @@ "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS" + }, { "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&utm_medium=RSS" @@ -99,10 +115,6 @@ "type": "WEB", "url": "https://www.synology.com/security/advisory/Synology_SA_19_33" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2692" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:2745" @@ -183,6 +195,22 @@ "type": "WEB", "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUBYAF6ED3O4XCHQ5C2HYENJLXYXZC4M" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZLUYPYY3RX4ZJDWZRJIKSULYRJ4PXW7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POPAEC4FWL4UU4LDEGPY5NPALU24FFQD" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html" @@ -210,6 +238,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-8mf3-6333-x5rm/GHSA-8mf3-6333-x5rm.json b/advisories/unreviewed/2022/05/GHSA-8mf3-6333-x5rm/GHSA-8mf3-6333-x5rm.json index f1505945637..b41bb17acf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mf3-6333-x5rm/GHSA-8mf3-6333-x5rm.json +++ b/advisories/unreviewed/2022/05/GHSA-8mf3-6333-x5rm/GHSA-8mf3-6333-x5rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8mf3-6333-x5rm", - "modified": "2022-05-24T17:32:36Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:32:36Z", "aliases": [ "CVE-2020-27656" ], "details": "Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-8rp4-gqh3-jpxm/GHSA-8rp4-gqh3-jpxm.json b/advisories/unreviewed/2022/05/GHSA-8rp4-gqh3-jpxm/GHSA-8rp4-gqh3-jpxm.json index 1e95c32acf2..0229d3dbee8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rp4-gqh3-jpxm/GHSA-8rp4-gqh3-jpxm.json +++ b/advisories/unreviewed/2022/05/GHSA-8rp4-gqh3-jpxm/GHSA-8rp4-gqh3-jpxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8rp4-gqh3-jpxm", - "modified": "2022-05-24T17:43:19Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:43:19Z", "aliases": [ "CVE-2021-26565" ], "details": "Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-9259-5376-vjcj/GHSA-9259-5376-vjcj.json b/advisories/unreviewed/2022/05/GHSA-9259-5376-vjcj/GHSA-9259-5376-vjcj.json index a32a701835c..4fd0d71675e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9259-5376-vjcj/GHSA-9259-5376-vjcj.json +++ b/advisories/unreviewed/2022/05/GHSA-9259-5376-vjcj/GHSA-9259-5376-vjcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9259-5376-vjcj", - "modified": "2022-08-13T00:00:31Z", + "modified": "2025-01-14T21:31:39Z", "published": "2022-05-24T16:53:20Z", "aliases": [ "CVE-2019-9515" @@ -19,26 +19,34 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9515" }, - { - "type": "WEB", - "url": "https://kb.cert.org/vuls/id/605641" - }, - { - "type": "WEB", - "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" - }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04@%3Cusers.trafficserver.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19@%3Cannounce.trafficserver.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7@%3Cdev.trafficserver.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" @@ -67,6 +75,10 @@ "type": "WEB", "url": "https://support.f5.com/csp/article/K50233772" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K50233772?utm_source=f5support&%3Butm_medium=RSS" + }, { "type": "WEB", "url": "https://support.f5.com/csp/article/K50233772?utm_source=f5support&utm_medium=RSS" @@ -159,6 +171,18 @@ "type": "WEB", "url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md" }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/605641" + }, + { + "type": "WEB", + "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3E" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html" @@ -174,6 +198,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-932g-58jj-wp5q/GHSA-932g-58jj-wp5q.json b/advisories/unreviewed/2022/05/GHSA-932g-58jj-wp5q/GHSA-932g-58jj-wp5q.json index 89210d8ec9e..14d6141ff5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-932g-58jj-wp5q/GHSA-932g-58jj-wp5q.json +++ b/advisories/unreviewed/2022/05/GHSA-932g-58jj-wp5q/GHSA-932g-58jj-wp5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-932g-58jj-wp5q", - "modified": "2023-09-14T18:32:37Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:07:01Z", "aliases": [ "CVE-2019-19344" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY" diff --git a/advisories/unreviewed/2022/05/GHSA-93p3-5r25-4p75/GHSA-93p3-5r25-4p75.json b/advisories/unreviewed/2022/05/GHSA-93p3-5r25-4p75/GHSA-93p3-5r25-4p75.json index 5ecb8915402..c53fd43eca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-93p3-5r25-4p75/GHSA-93p3-5r25-4p75.json +++ b/advisories/unreviewed/2022/05/GHSA-93p3-5r25-4p75/GHSA-93p3-5r25-4p75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93p3-5r25-4p75", - "modified": "2022-08-13T00:00:31Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T16:53:20Z", "aliases": [ "CVE-2019-9518" @@ -21,43 +21,7 @@ }, { "type": "WEB", - "url": "https://www.synology.com/security/advisory/Synology_SA_19_33" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2019/dsa-4520" - }, - { - "type": "WEB", - "url": "https://support.f5.com/csp/article/K46011592?utm_source=f5support&utm_medium=RSS" - }, - { - "type": "WEB", - "url": "https://support.f5.com/csp/article/K46011592" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20190823-0005" - }, - { - "type": "WEB", - "url": "https://seclists.org/bugtraq/2019/Sep/18" - }, - { - "type": "WEB", - "url": "https://seclists.org/bugtraq/2019/Aug/24" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rd31230d01fa6aad18bdadc0720acd1747e53690bd35f73a48e7a9b75@%3Ccommits.cassandra.apache.org%3E" + "url": "https://lists.apache.org/thread.html/r99a625fb17032646d96cd23dec49603ff630e9318e44a686d63046bc%40%3Ccommits.cassandra.apache.org%3E" }, { "type": "WEB", @@ -65,47 +29,63 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/ff5b0821a6985159a832ff6d1a4bd311ac07ecc7db1e2d8bab619107@%3Cdev.trafficserver.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rd31230d01fa6aad18bdadc0720acd1747e53690bd35f73a48e7a9b75%40%3Ccommits.cassandra.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rd31230d01fa6aad18bdadc0720acd1747e53690bd35f73a48e7a9b75@%3Ccommits.cassandra.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/2653c56545573b528f3f6352a29eccaf498bd6fb2a6a59568d81a61d@%3Cannounce.trafficserver.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/091b518265bce56a16af87b77c8cfacda902a02079e866f9fdf13b61@%3Cusers.trafficserver.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" }, { "type": "WEB", - "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" }, { "type": "WEB", - "url": "https://kb.cert.org/vuls/id/605641" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" }, { "type": "WEB", - "url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md" + "url": "https://seclists.org/bugtraq/2019/Aug/24" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2020:0727" + "url": "https://seclists.org/bugtraq/2019/Sep/18" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:4352" + "url": "https://security.netapp.com/advisory/ntap-20190823-0005" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:3892" + "url": "https://support.f5.com/csp/article/K46011592" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2955" + "url": "https://support.f5.com/csp/article/K46011592?utm_source=f5support&%3Butm_medium=RSS" + }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K46011592?utm_source=f5support&utm_medium=RSS" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2019/dsa-4520" + }, + { + "type": "WEB", + "url": "https://www.synology.com/security/advisory/Synology_SA_19_33" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2925" }, { "type": "WEB", @@ -113,7 +93,63 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2925" + "url": "https://access.redhat.com/errata/RHSA-2019:2955" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3892" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:4352" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2020:0727" + }, + { + "type": "WEB", + "url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/605641" + }, + { + "type": "WEB", + "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/091b518265bce56a16af87b77c8cfacda902a02079e866f9fdf13b61%40%3Cusers.trafficserver.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/091b518265bce56a16af87b77c8cfacda902a02079e866f9fdf13b61@%3Cusers.trafficserver.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/2653c56545573b528f3f6352a29eccaf498bd6fb2a6a59568d81a61d%40%3Cannounce.trafficserver.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/2653c56545573b528f3f6352a29eccaf498bd6fb2a6a59568d81a61d@%3Cannounce.trafficserver.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ff5b0821a6985159a832ff6d1a4bd311ac07ecc7db1e2d8bab619107%40%3Cdev.trafficserver.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ff5b0821a6985159a832ff6d1a4bd311ac07ecc7db1e2d8bab619107@%3Cdev.trafficserver.apache.org%3E" }, { "type": "WEB", @@ -130,6 +166,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-9977-6673-28cw/GHSA-9977-6673-28cw.json b/advisories/unreviewed/2022/05/GHSA-9977-6673-28cw/GHSA-9977-6673-28cw.json index 97bb0375c14..9b356f93907 100644 --- a/advisories/unreviewed/2022/05/GHSA-9977-6673-28cw/GHSA-9977-6673-28cw.json +++ b/advisories/unreviewed/2022/05/GHSA-9977-6673-28cw/GHSA-9977-6673-28cw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9977-6673-28cw", - "modified": "2022-05-24T19:05:59Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:05:59Z", "aliases": [ "CVE-2021-29087" ], "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-999r-3mg2-g4rj/GHSA-999r-3mg2-g4rj.json b/advisories/unreviewed/2022/05/GHSA-999r-3mg2-g4rj/GHSA-999r-3mg2-g4rj.json index 3c762eb93a4..7b2ad89e5f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-999r-3mg2-g4rj/GHSA-999r-3mg2-g4rj.json +++ b/advisories/unreviewed/2022/05/GHSA-999r-3mg2-g4rj/GHSA-999r-3mg2-g4rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-999r-3mg2-g4rj", - "modified": "2022-05-14T03:50:44Z", + "modified": "2025-01-14T21:31:36Z", "published": "2022-05-14T03:50:44Z", "aliases": [ "CVE-2017-9554" diff --git a/advisories/unreviewed/2022/05/GHSA-cjg6-frrp-p7cp/GHSA-cjg6-frrp-p7cp.json b/advisories/unreviewed/2022/05/GHSA-cjg6-frrp-p7cp/GHSA-cjg6-frrp-p7cp.json index e8f580b2fbd..19d8f911e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjg6-frrp-p7cp/GHSA-cjg6-frrp-p7cp.json +++ b/advisories/unreviewed/2022/05/GHSA-cjg6-frrp-p7cp/GHSA-cjg6-frrp-p7cp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjg6-frrp-p7cp", - "modified": "2022-05-24T17:46:06Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:46:06Z", "aliases": [ "CVE-2021-29083" ], "details": "Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-f7vf-74cx-834m/GHSA-f7vf-74cx-834m.json b/advisories/unreviewed/2022/05/GHSA-f7vf-74cx-834m/GHSA-f7vf-74cx-834m.json index 82130d8efeb..5683e5bb369 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7vf-74cx-834m/GHSA-f7vf-74cx-834m.json +++ b/advisories/unreviewed/2022/05/GHSA-f7vf-74cx-834m/GHSA-f7vf-74cx-834m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7vf-74cx-834m", - "modified": "2022-05-24T17:32:35Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:32:35Z", "aliases": [ "CVE-2020-27648" ], "details": "Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-gw65-pmpr-pj76/GHSA-gw65-pmpr-pj76.json b/advisories/unreviewed/2022/05/GHSA-gw65-pmpr-pj76/GHSA-gw65-pmpr-pj76.json index c45e86ccd9b..6a444971c60 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw65-pmpr-pj76/GHSA-gw65-pmpr-pj76.json +++ b/advisories/unreviewed/2022/05/GHSA-gw65-pmpr-pj76/GHSA-gw65-pmpr-pj76.json @@ -24,7 +24,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j675-7hvj-qfw5/GHSA-j675-7hvj-qfw5.json b/advisories/unreviewed/2022/05/GHSA-j675-7hvj-qfw5/GHSA-j675-7hvj-qfw5.json index 07a65e577c0..cceeb6e249e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j675-7hvj-qfw5/GHSA-j675-7hvj-qfw5.json +++ b/advisories/unreviewed/2022/05/GHSA-j675-7hvj-qfw5/GHSA-j675-7hvj-qfw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j675-7hvj-qfw5", - "modified": "2022-05-13T01:33:29Z", + "modified": "2025-01-14T21:31:38Z", "published": "2022-05-13T01:33:29Z", "aliases": [ "CVE-2018-1160" diff --git a/advisories/unreviewed/2022/05/GHSA-m32f-99jg-48x9/GHSA-m32f-99jg-48x9.json b/advisories/unreviewed/2022/05/GHSA-m32f-99jg-48x9/GHSA-m32f-99jg-48x9.json index 18613316236..879f31d38df 100644 --- a/advisories/unreviewed/2022/05/GHSA-m32f-99jg-48x9/GHSA-m32f-99jg-48x9.json +++ b/advisories/unreviewed/2022/05/GHSA-m32f-99jg-48x9/GHSA-m32f-99jg-48x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m32f-99jg-48x9", - "modified": "2022-05-24T19:06:00Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:06:00Z", "aliases": [ "CVE-2021-29085" ], "details": "Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-mjrv-32hr-4pv5/GHSA-mjrv-32hr-4pv5.json b/advisories/unreviewed/2022/05/GHSA-mjrv-32hr-4pv5/GHSA-mjrv-32hr-4pv5.json index 41d9f6c846c..ad388983a1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjrv-32hr-4pv5/GHSA-mjrv-32hr-4pv5.json +++ b/advisories/unreviewed/2022/05/GHSA-mjrv-32hr-4pv5/GHSA-mjrv-32hr-4pv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjrv-32hr-4pv5", - "modified": "2022-05-13T01:48:01Z", + "modified": "2025-01-14T21:31:36Z", "published": "2022-05-13T01:48:01Z", "aliases": [ "CVE-2017-9553" diff --git a/advisories/unreviewed/2022/05/GHSA-pr6j-q8cq-rhhr/GHSA-pr6j-q8cq-rhhr.json b/advisories/unreviewed/2022/05/GHSA-pr6j-q8cq-rhhr/GHSA-pr6j-q8cq-rhhr.json index 376fc9b99be..7830a471de7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr6j-q8cq-rhhr/GHSA-pr6j-q8cq-rhhr.json +++ b/advisories/unreviewed/2022/05/GHSA-pr6j-q8cq-rhhr/GHSA-pr6j-q8cq-rhhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pr6j-q8cq-rhhr", - "modified": "2022-05-24T17:32:35Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:32:35Z", "aliases": [ "CVE-2020-27650" ], "details": "Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-614" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qm39-44mj-vqvq/GHSA-qm39-44mj-vqvq.json b/advisories/unreviewed/2022/05/GHSA-qm39-44mj-vqvq/GHSA-qm39-44mj-vqvq.json index ae8bf02beb0..842da7afd4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm39-44mj-vqvq/GHSA-qm39-44mj-vqvq.json +++ b/advisories/unreviewed/2022/05/GHSA-qm39-44mj-vqvq/GHSA-qm39-44mj-vqvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qm39-44mj-vqvq", - "modified": "2022-05-24T17:44:30Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:44:30Z", "aliases": [ "CVE-2021-27646" ], "details": "Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-qw9p-wf2h-j96q/GHSA-qw9p-wf2h-j96q.json b/advisories/unreviewed/2022/05/GHSA-qw9p-wf2h-j96q/GHSA-qw9p-wf2h-j96q.json index 036220dffba..cf8265a2e15 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw9p-wf2h-j96q/GHSA-qw9p-wf2h-j96q.json +++ b/advisories/unreviewed/2022/05/GHSA-qw9p-wf2h-j96q/GHSA-qw9p-wf2h-j96q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw9p-wf2h-j96q", - "modified": "2022-11-16T12:00:20Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:07:00Z", "aliases": [ "CVE-2019-14907" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQ6U65I2K23YJC4FESW477WL55TU3PPT" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ACZVNMIFQGGXNJPMHAVBN3H2U65FXQY" diff --git a/advisories/unreviewed/2022/05/GHSA-r945-qf65-4pr8/GHSA-r945-qf65-4pr8.json b/advisories/unreviewed/2022/05/GHSA-r945-qf65-4pr8/GHSA-r945-qf65-4pr8.json index 81713774a71..0a77419008a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r945-qf65-4pr8/GHSA-r945-qf65-4pr8.json +++ b/advisories/unreviewed/2022/05/GHSA-r945-qf65-4pr8/GHSA-r945-qf65-4pr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r945-qf65-4pr8", - "modified": "2022-05-24T19:03:43Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:03:43Z", "aliases": [ "CVE-2021-33182" ], "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-rf4v-73h8-p6f7/GHSA-rf4v-73h8-p6f7.json b/advisories/unreviewed/2022/05/GHSA-rf4v-73h8-p6f7/GHSA-rf4v-73h8-p6f7.json index 731d338f669..c854555d2db 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf4v-73h8-p6f7/GHSA-rf4v-73h8-p6f7.json +++ b/advisories/unreviewed/2022/05/GHSA-rf4v-73h8-p6f7/GHSA-rf4v-73h8-p6f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf4v-73h8-p6f7", - "modified": "2022-05-13T01:20:33Z", + "modified": "2025-01-14T21:31:36Z", "published": "2022-05-13T01:20:33Z", "aliases": [ "CVE-2018-7184" diff --git a/advisories/unreviewed/2022/05/GHSA-v5hv-rggx-r8xg/GHSA-v5hv-rggx-r8xg.json b/advisories/unreviewed/2022/05/GHSA-v5hv-rggx-r8xg/GHSA-v5hv-rggx-r8xg.json index 61f916e6256..7d0def017df 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5hv-rggx-r8xg/GHSA-v5hv-rggx-r8xg.json +++ b/advisories/unreviewed/2022/05/GHSA-v5hv-rggx-r8xg/GHSA-v5hv-rggx-r8xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5hv-rggx-r8xg", - "modified": "2022-05-13T01:20:34Z", + "modified": "2025-01-14T21:31:37Z", "published": "2022-05-13T01:20:34Z", "aliases": [ "CVE-2018-7185" diff --git a/advisories/unreviewed/2022/05/GHSA-v9cv-3r4j-cx4j/GHSA-v9cv-3r4j-cx4j.json b/advisories/unreviewed/2022/05/GHSA-v9cv-3r4j-cx4j/GHSA-v9cv-3r4j-cx4j.json index c23040da77c..7242bb791eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9cv-3r4j-cx4j/GHSA-v9cv-3r4j-cx4j.json +++ b/advisories/unreviewed/2022/05/GHSA-v9cv-3r4j-cx4j/GHSA-v9cv-3r4j-cx4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9cv-3r4j-cx4j", - "modified": "2022-05-13T01:25:45Z", + "modified": "2025-01-14T21:31:36Z", "published": "2022-05-13T01:25:45Z", "aliases": [ "CVE-2018-7170" diff --git a/advisories/unreviewed/2022/05/GHSA-vwc7-rhxw-hppq/GHSA-vwc7-rhxw-hppq.json b/advisories/unreviewed/2022/05/GHSA-vwc7-rhxw-hppq/GHSA-vwc7-rhxw-hppq.json index eef6bb909b0..12fa7eb9393 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwc7-rhxw-hppq/GHSA-vwc7-rhxw-hppq.json +++ b/advisories/unreviewed/2022/05/GHSA-vwc7-rhxw-hppq/GHSA-vwc7-rhxw-hppq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vwc7-rhxw-hppq", - "modified": "2022-05-24T17:44:30Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:44:30Z", "aliases": [ "CVE-2021-27647" ], "details": "Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-w6v5-q8c8-52xx/GHSA-w6v5-q8c8-52xx.json b/advisories/unreviewed/2022/05/GHSA-w6v5-q8c8-52xx/GHSA-w6v5-q8c8-52xx.json index 710925d41ed..c348796319c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6v5-q8c8-52xx/GHSA-w6v5-q8c8-52xx.json +++ b/advisories/unreviewed/2022/05/GHSA-w6v5-q8c8-52xx/GHSA-w6v5-q8c8-52xx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6v5-q8c8-52xx", - "modified": "2022-08-13T00:00:31Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T16:53:21Z", "aliases": [ "CVE-2019-9517" @@ -21,23 +21,7 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" }, { "type": "WEB", @@ -45,7 +29,59 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHTKU7YQ5EEP2XNSAV4M4VJ7QCBOJMOD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BP556LEG3WENHZI5TAQ6ZEBFTJB4E2IS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:2893" }, { "type": "WEB", @@ -79,6 +115,10 @@ "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&%3Butm_medium=RSS" + }, { "type": "WEB", "url": "https://support.f5.com/csp/article/K02591030?utm_source=f5support&utm_medium=RSS" @@ -103,10 +143,6 @@ "type": "WEB", "url": "https://www.synology.com/security/advisory/Synology_SA_19_33" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:2893" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:2925" @@ -155,42 +191,82 @@ "type": "WEB", "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10296" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb%40%3Cannounce.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/4610762456644181b267c846423b3a990bd4aaea1886ecc7d51febdb@%3Cannounce.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50%40%3Cdev.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/d89f999e26dfb1d50f247ead1fe8538014eb412b2dbe5be4b1a9ef50@%3Cdev.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c%40%3Cdev.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c@%3Cdev.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.html" @@ -210,6 +286,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-wgmc-67f7-2pmg/GHSA-wgmc-67f7-2pmg.json b/advisories/unreviewed/2022/05/GHSA-wgmc-67f7-2pmg/GHSA-wgmc-67f7-2pmg.json index f810d851a71..4e18f9d9afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgmc-67f7-2pmg/GHSA-wgmc-67f7-2pmg.json +++ b/advisories/unreviewed/2022/05/GHSA-wgmc-67f7-2pmg/GHSA-wgmc-67f7-2pmg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgmc-67f7-2pmg", - "modified": "2022-05-24T19:05:59Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T19:05:59Z", "aliases": [ "CVE-2021-29086" ], "details": "Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-x5fh-xfvr-gg7m/GHSA-x5fh-xfvr-gg7m.json b/advisories/unreviewed/2022/05/GHSA-x5fh-xfvr-gg7m/GHSA-x5fh-xfvr-gg7m.json index 9d9b3875b4a..c7e9c9790c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5fh-xfvr-gg7m/GHSA-x5fh-xfvr-gg7m.json +++ b/advisories/unreviewed/2022/05/GHSA-x5fh-xfvr-gg7m/GHSA-x5fh-xfvr-gg7m.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-201" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xc56-v745-v4g3/GHSA-xc56-v745-v4g3.json b/advisories/unreviewed/2022/05/GHSA-xc56-v745-v4g3/GHSA-xc56-v745-v4g3.json index 3469d34d604..7b9767bdab1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc56-v745-v4g3/GHSA-xc56-v745-v4g3.json +++ b/advisories/unreviewed/2022/05/GHSA-xc56-v745-v4g3/GHSA-xc56-v745-v4g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xc56-v745-v4g3", - "modified": "2022-08-03T00:00:56Z", + "modified": "2025-01-14T21:31:41Z", "published": "2022-05-24T17:44:30Z", "aliases": [ "CVE-2021-26569" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-362" + "CWE-362", + "CWE-366" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xv9q-3jh5-9rrc/GHSA-xv9q-3jh5-9rrc.json b/advisories/unreviewed/2022/05/GHSA-xv9q-3jh5-9rrc/GHSA-xv9q-3jh5-9rrc.json index 2db8d5dc7a0..44499135776 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv9q-3jh5-9rrc/GHSA-xv9q-3jh5-9rrc.json +++ b/advisories/unreviewed/2022/05/GHSA-xv9q-3jh5-9rrc/GHSA-xv9q-3jh5-9rrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv9q-3jh5-9rrc", - "modified": "2022-05-13T01:02:11Z", + "modified": "2025-01-14T21:31:38Z", "published": "2022-05-13T01:02:11Z", "aliases": [ "CVE-2019-3870" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://bugzilla.samba.org/show_bug.cgi?id=13834" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTJVFA3RZ6G2IZDTVKLHRMX6QBYA4GPA" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62" diff --git a/advisories/unreviewed/2023/05/GHSA-966v-xccm-p63c/GHSA-966v-xccm-p63c.json b/advisories/unreviewed/2023/05/GHSA-966v-xccm-p63c/GHSA-966v-xccm-p63c.json index f2084bd784a..bf4172ed979 100644 --- a/advisories/unreviewed/2023/05/GHSA-966v-xccm-p63c/GHSA-966v-xccm-p63c.json +++ b/advisories/unreviewed/2023/05/GHSA-966v-xccm-p63c/GHSA-966v-xccm-p63c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-r56f-m3qp-r2r5/GHSA-r56f-m3qp-r2r5.json b/advisories/unreviewed/2023/05/GHSA-r56f-m3qp-r2r5/GHSA-r56f-m3qp-r2r5.json index 2f0e84b0126..14bd7288b68 100644 --- a/advisories/unreviewed/2023/05/GHSA-r56f-m3qp-r2r5/GHSA-r56f-m3qp-r2r5.json +++ b/advisories/unreviewed/2023/05/GHSA-r56f-m3qp-r2r5/GHSA-r56f-m3qp-r2r5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-wqh8-3grf-j8jp/GHSA-wqh8-3grf-j8jp.json b/advisories/unreviewed/2023/05/GHSA-wqh8-3grf-j8jp/GHSA-wqh8-3grf-j8jp.json index fa08aba5244..f3b0f192d4e 100644 --- a/advisories/unreviewed/2023/05/GHSA-wqh8-3grf-j8jp/GHSA-wqh8-3grf-j8jp.json +++ b/advisories/unreviewed/2023/05/GHSA-wqh8-3grf-j8jp/GHSA-wqh8-3grf-j8jp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-6xg5-vvc4-9mrx/GHSA-6xg5-vvc4-9mrx.json b/advisories/unreviewed/2024/03/GHSA-6xg5-vvc4-9mrx/GHSA-6xg5-vvc4-9mrx.json index ce4fc427983..f5edc8b09a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xg5-vvc4-9mrx/GHSA-6xg5-vvc4-9mrx.json +++ b/advisories/unreviewed/2024/03/GHSA-6xg5-vvc4-9mrx/GHSA-6xg5-vvc4-9mrx.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-644" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json index 52e97cfb866..8709f8600bd 100644 --- a/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json +++ b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xp5-393r-g6q2", - "modified": "2024-04-07T03:30:45Z", + "modified": "2025-01-14T21:31:47Z", "published": "2024-04-07T03:30:45Z", "aliases": [ "CVE-2023-6877" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-x245-wv5c-hr8q/GHSA-x245-wv5c-hr8q.json b/advisories/unreviewed/2024/04/GHSA-x245-wv5c-hr8q/GHSA-x245-wv5c-hr8q.json index f2e3983ca31..10af1af253d 100644 --- a/advisories/unreviewed/2024/04/GHSA-x245-wv5c-hr8q/GHSA-x245-wv5c-hr8q.json +++ b/advisories/unreviewed/2024/04/GHSA-x245-wv5c-hr8q/GHSA-x245-wv5c-hr8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x245-wv5c-hr8q", - "modified": "2024-04-17T15:30:42Z", + "modified": "2025-01-14T21:31:47Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2023-6805" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7p6x-vmqm-g4wc/GHSA-7p6x-vmqm-g4wc.json b/advisories/unreviewed/2024/05/GHSA-7p6x-vmqm-g4wc/GHSA-7p6x-vmqm-g4wc.json index 6dbad4de992..dce70884c02 100644 --- a/advisories/unreviewed/2024/05/GHSA-7p6x-vmqm-g4wc/GHSA-7p6x-vmqm-g4wc.json +++ b/advisories/unreviewed/2024/05/GHSA-7p6x-vmqm-g4wc/GHSA-7p6x-vmqm-g4wc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json b/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json index ca2284902e7..7a54d543004 100644 --- a/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json +++ b/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2423-2c9w-8vgr", - "modified": "2025-01-06T18:31:05Z", + "modified": "2025-01-14T21:31:47Z", "published": "2025-01-06T18:31:05Z", "aliases": [ "CVE-2024-56828" ], "details": "File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is parsed. For example, given a string like: data:image/html;base64,PGh0bWw+PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPjwvaHRtbD4= the content after the comma is extracted and decoded using Base64.getDecoder().decode(). The substring from the 11th character up to the first occurrence of a semicolon (;) is assigned to the suffix variable (representing the file extension). The decoded content is then written to a file. However, the file extension is not validated, and since this functionality is exposed to the frontend, it poses significant security risks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T18:15:23Z" diff --git a/advisories/unreviewed/2025/01/GHSA-243g-fh5x-f6c7/GHSA-243g-fh5x-f6c7.json b/advisories/unreviewed/2025/01/GHSA-243g-fh5x-f6c7/GHSA-243g-fh5x-f6c7.json new file mode 100644 index 00000000000..2c2362439dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-243g-fh5x-f6c7/GHSA-243g-fh5x-f6c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-243g-fh5x-f6c7", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-48855" + ], + "details": "Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48855" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3j6g-xwcr-2hcw/GHSA-3j6g-xwcr-2hcw.json b/advisories/unreviewed/2025/01/GHSA-3j6g-xwcr-2hcw/GHSA-3j6g-xwcr-2hcw.json new file mode 100644 index 00000000000..757f8a66d11 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3j6g-xwcr-2hcw/GHSA-3j6g-xwcr-2hcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j6g-xwcr-2hcw", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-48858" + ], + "details": "Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48858" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3p4f-j34w-3mfc/GHSA-3p4f-j34w-3mfc.json b/advisories/unreviewed/2025/01/GHSA-3p4f-j34w-3mfc/GHSA-3p4f-j34w-3mfc.json new file mode 100644 index 00000000000..3c8d94f8f38 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3p4f-j34w-3mfc/GHSA-3p4f-j34w-3mfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p4f-j34w-3mfc", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21134" + ], + "details": "Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21134" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator-mobile-ios/apsb25-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3xg4-9379-gq7p/GHSA-3xg4-9379-gq7p.json b/advisories/unreviewed/2025/01/GHSA-3xg4-9379-gq7p/GHSA-3xg4-9379-gq7p.json new file mode 100644 index 00000000000..4f0cc872eb8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3xg4-9379-gq7p/GHSA-3xg4-9379-gq7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xg4-9379-gq7p", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-48857" + ], + "details": "NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48857" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json b/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json new file mode 100644 index 00000000000..dd63e359e93 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45wg-59j7-h44g", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-21137" + ], + "details": "Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21137" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46hr-24vx-hm3m/GHSA-46hr-24vx-hm3m.json b/advisories/unreviewed/2025/01/GHSA-46hr-24vx-hm3m/GHSA-46hr-24vx-hm3m.json new file mode 100644 index 00000000000..5030be54d94 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-46hr-24vx-hm3m/GHSA-46hr-24vx-hm3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46hr-24vx-hm3m", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21127" + ], + "details": "Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21127" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4h8j-v9x7-v3wj/GHSA-4h8j-v9x7-v3wj.json b/advisories/unreviewed/2025/01/GHSA-4h8j-v9x7-v3wj/GHSA-4h8j-v9x7-v3wj.json new file mode 100644 index 00000000000..a952e7fdec4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4h8j-v9x7-v3wj/GHSA-4h8j-v9x7-v3wj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h8j-v9x7-v3wj", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-23072" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - RefreshSpecial Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23072" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ic9547e80a8296d707ad8a157eb8ba7aa26fb08dc" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T378885" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5rcj-5qr3-56qc/GHSA-5rcj-5qr3-56qc.json b/advisories/unreviewed/2025/01/GHSA-5rcj-5qr3-56qc/GHSA-5rcj-5qr3-56qc.json new file mode 100644 index 00000000000..ef7d0221325 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5rcj-5qr3-56qc/GHSA-5rcj-5qr3-56qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcj-5qr3-56qc", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21131" + ], + "details": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21131" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7vr6-q52x-qhhq/GHSA-7vr6-q52x-qhhq.json b/advisories/unreviewed/2025/01/GHSA-7vr6-q52x-qhhq/GHSA-7vr6-q52x-qhhq.json new file mode 100644 index 00000000000..e3124b06a40 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7vr6-q52x-qhhq/GHSA-7vr6-q52x-qhhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vr6-q52x-qhhq", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-21138" + ], + "details": "Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21138" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9wrw-w4gf-8x2q/GHSA-9wrw-w4gf-8x2q.json b/advisories/unreviewed/2025/01/GHSA-9wrw-w4gf-8x2q/GHSA-9wrw-w4gf-8x2q.json new file mode 100644 index 00000000000..22466bf92fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9wrw-w4gf-8x2q/GHSA-9wrw-w4gf-8x2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wrw-w4gf-8x2q", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21133" + ], + "details": "Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21133" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator-mobile-ios/apsb25-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json b/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json new file mode 100644 index 00000000000..a86b3bcecc8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm3m-9484-8h7w", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21128" + ], + "details": "Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21128" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmv6-fx37-6f78/GHSA-fmv6-fx37-6f78.json b/advisories/unreviewed/2025/01/GHSA-fmv6-fx37-6f78/GHSA-fmv6-fx37-6f78.json new file mode 100644 index 00000000000..ff8478e0727 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmv6-fx37-6f78/GHSA-fmv6-fx37-6f78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmv6-fx37-6f78", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21122" + ], + "details": "Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21122" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb25-02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmw8-4xqq-qh9j/GHSA-fmw8-4xqq-qh9j.json b/advisories/unreviewed/2025/01/GHSA-fmw8-4xqq-qh9j/GHSA-fmw8-4xqq-qh9j.json new file mode 100644 index 00000000000..3b99f373a46 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmw8-4xqq-qh9j/GHSA-fmw8-4xqq-qh9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmw8-4xqq-qh9j", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-48856" + ], + "details": "Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48856" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g65w-c34w-fhj5/GHSA-g65w-c34w-fhj5.json b/advisories/unreviewed/2025/01/GHSA-g65w-c34w-fhj5/GHSA-g65w-c34w-fhj5.json new file mode 100644 index 00000000000..cc0b8398af8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g65w-c34w-fhj5/GHSA-g65w-c34w-fhj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g65w-c34w-fhj5", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21130" + ], + "details": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21130" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h327-5h5x-675h/GHSA-h327-5h5x-675h.json b/advisories/unreviewed/2025/01/GHSA-h327-5h5x-675h/GHSA-h327-5h5x-675h.json new file mode 100644 index 00000000000..b3d451beaf7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h327-5h5x-675h/GHSA-h327-5h5x-675h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h327-5h5x-675h", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-23074" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23074" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I4b77ced314bc6cea0ef3657a82e7467d3661fe2a" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T373265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j2m4-4rvg-26j8/GHSA-j2m4-4rvg-26j8.json b/advisories/unreviewed/2025/01/GHSA-j2m4-4rvg-26j8/GHSA-j2m4-4rvg-26j8.json new file mode 100644 index 00000000000..d4be27c6c49 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j2m4-4rvg-26j8/GHSA-j2m4-4rvg-26j8.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2m4-4rvg-26j8", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-0474" + ], + "details": "Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.\nThis issue affects Invoice Ninja: from 5.8.56 through 5.11.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0474" + }, + { + "type": "WEB", + "url": "https://github.com/invoiceninja/invoiceninja/commit/2a9bf353b432d7060e85487b617151ecbc36247d" + }, + { + "type": "WEB", + "url": "https://github.com/invoiceninja/invoiceninja/compare/97ae948618230c1812f3223b80bf22dcb0382dc5..435780932fe19063001d79ba518815df62773d71" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/invoice-ninja-ssrf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mccj-j3pr-x8gh/GHSA-mccj-j3pr-x8gh.json b/advisories/unreviewed/2025/01/GHSA-mccj-j3pr-x8gh/GHSA-mccj-j3pr-x8gh.json new file mode 100644 index 00000000000..2e534da118f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mccj-j3pr-x8gh/GHSA-mccj-j3pr-x8gh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mccj-j3pr-x8gh", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-21136" + ], + "details": "Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21136" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mf23-wm84-g9x3/GHSA-mf23-wm84-g9x3.json b/advisories/unreviewed/2025/01/GHSA-mf23-wm84-g9x3/GHSA-mf23-wm84-g9x3.json new file mode 100644 index 00000000000..8fa1a927f97 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mf23-wm84-g9x3/GHSA-mf23-wm84-g9x3.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf23-wm84-g9x3", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-23018" + ], + "details": "IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23018" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc2473" + }, + { + "type": "WEB", + "url": "https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf" + }, + { + "type": "WEB", + "url": "https://www.top10vpn.com/research/tunneling-protocol-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-940" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json b/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json index 6fe318debdb..fe3f32489fa 100644 --- a/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json +++ b/advisories/unreviewed/2025/01/GHSA-mvph-h5j7-4h2g/GHSA-mvph-h5j7-4h2g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-379" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json b/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json new file mode 100644 index 00000000000..f5984d2f7df --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prrw-fgg2-wvfg", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21129" + ], + "details": "Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21129" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcgg-j2x8-h9g8/GHSA-qcgg-j2x8-h9g8.json b/advisories/unreviewed/2025/01/GHSA-qcgg-j2x8-h9g8/GHSA-qcgg-j2x8-h9g8.json new file mode 100644 index 00000000000..ef05d5d884d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcgg-j2x8-h9g8/GHSA-qcgg-j2x8-h9g8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcgg-j2x8-h9g8", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-56374" + ], + "details": "An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56374" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/django-announce" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2025/jan/14/security-releases" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/01/14/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qm7w-rp99-m478/GHSA-qm7w-rp99-m478.json b/advisories/unreviewed/2025/01/GHSA-qm7w-rp99-m478/GHSA-qm7w-rp99-m478.json new file mode 100644 index 00000000000..7b672ec6f3d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qm7w-rp99-m478/GHSA-qm7w-rp99-m478.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm7w-rp99-m478", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-21135" + ], + "details": "Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21135" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb25-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qpjx-9hp9-85gm/GHSA-qpjx-9hp9-85gm.json b/advisories/unreviewed/2025/01/GHSA-qpjx-9hp9-85gm/GHSA-qpjx-9hp9-85gm.json new file mode 100644 index 00000000000..55613f9df51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qpjx-9hp9-85gm/GHSA-qpjx-9hp9-85gm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpjx-9hp9-85gm", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-23019" + ], + "details": "IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23019" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc4213" + }, + { + "type": "WEB", + "url": "https://papers.mathyvanhoef.com/usenix2025-tunnels.pdf" + }, + { + "type": "WEB", + "url": "https://www.top10vpn.com/research/tunneling-protocol-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-940" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qvvc-rx46-m5x3/GHSA-qvvc-rx46-m5x3.json b/advisories/unreviewed/2025/01/GHSA-qvvc-rx46-m5x3/GHSA-qvvc-rx46-m5x3.json new file mode 100644 index 00000000000..acb7385d51c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qvvc-rx46-m5x3/GHSA-qvvc-rx46-m5x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvvc-rx46-m5x3", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2024-48854" + ], + "details": "Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48854" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json b/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json new file mode 100644 index 00000000000..54f993ee926 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5c9-3mr5-pgp3", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2025-21139" + ], + "details": "Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21139" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r6p4-6frv-q6pp/GHSA-r6p4-6frv-q6pp.json b/advisories/unreviewed/2025/01/GHSA-r6p4-6frv-q6pp/GHSA-r6p4-6frv-q6pp.json new file mode 100644 index 00000000000..e2ae91e2854 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r6p4-6frv-q6pp/GHSA-r6p4-6frv-q6pp.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6p4-6frv-q6pp", + "modified": "2025-01-14T21:31:48Z", + "published": "2025-01-14T21:31:48Z", + "aliases": [ + "CVE-2024-5175" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5175" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w9r8-xh84-c8wx/GHSA-w9r8-xh84-c8wx.json b/advisories/unreviewed/2025/01/GHSA-w9r8-xh84-c8wx/GHSA-w9r8-xh84-c8wx.json new file mode 100644 index 00000000000..30c121a59f2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w9r8-xh84-c8wx/GHSA-w9r8-xh84-c8wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9r8-xh84-c8wx", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-23073" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data.This issue affects Mediawiki - GlobalBlocking Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23073" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I2a2d32aedf6328be0a9f1b4e04a6567a25f19486" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T377855" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xg62-pxmq-6wgh/GHSA-xg62-pxmq-6wgh.json b/advisories/unreviewed/2025/01/GHSA-xg62-pxmq-6wgh/GHSA-xg62-pxmq-6wgh.json new file mode 100644 index 00000000000..470caa76ce3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xg62-pxmq-6wgh/GHSA-xg62-pxmq-6wgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg62-pxmq-6wgh", + "modified": "2025-01-14T21:31:47Z", + "published": "2025-01-14T21:31:47Z", + "aliases": [ + "CVE-2025-21132" + ], + "details": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21132" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xxjv-9p3v-x2hv/GHSA-xxjv-9p3v-x2hv.json b/advisories/unreviewed/2025/01/GHSA-xxjv-9p3v-x2hv/GHSA-xxjv-9p3v-x2hv.json index 3e3be344d35..c816ec53427 100644 --- a/advisories/unreviewed/2025/01/GHSA-xxjv-9p3v-x2hv/GHSA-xxjv-9p3v-x2hv.json +++ b/advisories/unreviewed/2025/01/GHSA-xxjv-9p3v-x2hv/GHSA-xxjv-9p3v-x2hv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxjv-9p3v-x2hv", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-14T21:31:47Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57623" ], "details": "An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z"