From e828a043c0986863f9bc03e495fb078fcedfe55e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 18 Feb 2025 15:32:17 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xjgh-8jrf-3xgw.json | 9 +++- .../GHSA-vp7q-rg64-pxr9.json | 4 +- .../GHSA-5j89-9926-36q5.json | 2 +- .../GHSA-f9v3-rvrm-52r5.json | 3 +- .../GHSA-pvmm-fgf7-r833.json | 2 +- .../GHSA-7fg2-xxpc-hg8m.json | 6 ++- .../GHSA-rfh2-62gc-x7hw.json | 4 +- .../GHSA-rgjq-f6gr-756j.json | 10 ++++- .../GHSA-4ph3-7qqh-5h7g.json | 15 +++++-- .../GHSA-4xff-6v5v-4gj4.json | 15 +++++-- .../GHSA-64pw-78r7-788g.json | 15 +++++-- .../GHSA-cqwq-wj9g-qgrx.json | 15 +++++-- .../GHSA-f43r-5jhm-fh67.json | 15 +++++-- .../GHSA-fqh8-982r-rggm.json | 15 +++++-- .../GHSA-v85c-wg53-qgrm.json | 15 +++++-- .../GHSA-37pg-r5mj-5q6w.json | 15 +++++-- .../GHSA-52cr-8q5h-6fpf.json | 15 +++++-- .../GHSA-6hmf-56g8-p898.json | 15 +++++-- .../GHSA-cm46-j2rc-99mf.json | 15 +++++-- .../GHSA-f5j6-wv5v-rgw9.json | 15 +++++-- .../GHSA-f5w3-q6fx-5p9r.json | 15 +++++-- .../GHSA-hgm9-g82q-236j.json | 11 +++-- .../GHSA-v5jf-jh4j-87cv.json | 15 +++++-- .../GHSA-2hqc-v3c9-r36r.json | 15 +++++-- .../GHSA-2m52-fc9q-48mj.json | 11 +++-- .../GHSA-3947-v5cg-rpwj.json | 40 ++++++++++++++++++ .../GHSA-749g-9h7c-6xjr.json | 3 +- .../GHSA-c5g7-7w25-772m.json | 29 +++++++++++++ .../GHSA-c82f-pmfx-x3vv.json | 37 +++++++++++++++++ .../GHSA-cg2m-239p-9xhp.json | 33 +++++++++++++++ .../GHSA-cg86-m5xc-jqrm.json | 41 +++++++++++++++++++ .../GHSA-ffvr-gmp3-xx43.json | 11 +++-- .../GHSA-fg38-pgj3-5w5f.json | 11 +++-- .../GHSA-jhqw-cq3q-2p2g.json | 40 ++++++++++++++++++ .../GHSA-p5jc-239c-pvvf.json | 33 +++++++++++++++ .../GHSA-qhjq-4w73-8cmv.json | 15 +++++-- .../GHSA-qr32-fcm4-m5h9.json | 29 +++++++++++++ .../GHSA-wc7r-hp6q-64m9.json | 33 +++++++++++++++ 38 files changed, 556 insertions(+), 86 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-3947-v5cg-rpwj/GHSA-3947-v5cg-rpwj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c5g7-7w25-772m/GHSA-c5g7-7w25-772m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cg2m-239p-9xhp/GHSA-cg2m-239p-9xhp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jhqw-cq3q-2p2g/GHSA-jhqw-cq3q-2p2g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qr32-fcm4-m5h9/GHSA-qr32-fcm4-m5h9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wc7r-hp6q-64m9/GHSA-wc7r-hp6q-64m9.json diff --git a/advisories/unreviewed/2022/05/GHSA-xjgh-8jrf-3xgw/GHSA-xjgh-8jrf-3xgw.json b/advisories/unreviewed/2022/05/GHSA-xjgh-8jrf-3xgw/GHSA-xjgh-8jrf-3xgw.json index aa08c935632..49650566499 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjgh-8jrf-3xgw/GHSA-xjgh-8jrf-3xgw.json +++ b/advisories/unreviewed/2022/05/GHSA-xjgh-8jrf-3xgw/GHSA-xjgh-8jrf-3xgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjgh-8jrf-3xgw", - "modified": "2022-05-24T19:01:48Z", + "modified": "2025-02-18T15:31:02Z", "published": "2022-05-24T19:01:48Z", "aliases": [ "CVE-2021-1906" ], "details": "Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/09/GHSA-vp7q-rg64-pxr9/GHSA-vp7q-rg64-pxr9.json b/advisories/unreviewed/2022/09/GHSA-vp7q-rg64-pxr9/GHSA-vp7q-rg64-pxr9.json index 54958b8a8df..141ee7c71e6 100644 --- a/advisories/unreviewed/2022/09/GHSA-vp7q-rg64-pxr9/GHSA-vp7q-rg64-pxr9.json +++ b/advisories/unreviewed/2022/09/GHSA-vp7q-rg64-pxr9/GHSA-vp7q-rg64-pxr9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-5j89-9926-36q5/GHSA-5j89-9926-36q5.json b/advisories/unreviewed/2023/03/GHSA-5j89-9926-36q5/GHSA-5j89-9926-36q5.json index a5b54451f4b..3236fc91297 100644 --- a/advisories/unreviewed/2023/03/GHSA-5j89-9926-36q5/GHSA-5j89-9926-36q5.json +++ b/advisories/unreviewed/2023/03/GHSA-5j89-9926-36q5/GHSA-5j89-9926-36q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5j89-9926-36q5", - "modified": "2023-04-07T18:30:50Z", + "modified": "2025-02-18T15:31:04Z", "published": "2023-03-31T18:30:22Z", "aliases": [ "CVE-2023-26830" diff --git a/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json b/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json index 6f614dafb8b..c414a812b43 100644 --- a/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json +++ b/advisories/unreviewed/2023/03/GHSA-f9v3-rvrm-52r5/GHSA-f9v3-rvrm-52r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9v3-rvrm-52r5", - "modified": "2023-04-06T18:30:19Z", + "modified": "2025-02-18T15:31:04Z", "published": "2023-03-29T21:30:15Z", "aliases": [ "CVE-2023-28508" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json b/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json index 638933e2826..d73399287eb 100644 --- a/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json +++ b/advisories/unreviewed/2023/03/GHSA-pvmm-fgf7-r833/GHSA-pvmm-fgf7-r833.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pvmm-fgf7-r833", - "modified": "2023-04-06T18:30:19Z", + "modified": "2025-02-18T15:31:04Z", "published": "2023-03-29T21:30:15Z", "aliases": [ "CVE-2023-28507" diff --git a/advisories/unreviewed/2023/04/GHSA-7fg2-xxpc-hg8m/GHSA-7fg2-xxpc-hg8m.json b/advisories/unreviewed/2023/04/GHSA-7fg2-xxpc-hg8m/GHSA-7fg2-xxpc-hg8m.json index 4f21ccbdaa8..1504346c16d 100644 --- a/advisories/unreviewed/2023/04/GHSA-7fg2-xxpc-hg8m/GHSA-7fg2-xxpc-hg8m.json +++ b/advisories/unreviewed/2023/04/GHSA-7fg2-xxpc-hg8m/GHSA-7fg2-xxpc-hg8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fg2-xxpc-hg8m", - "modified": "2023-04-11T18:30:30Z", + "modified": "2025-02-18T15:31:05Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-24724" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24724" }, + { + "type": "WEB", + "url": "https://medium.com/%40williamamorim256/stored-xss-vulnerability-discovered-in-sas-9-4-admin-console-5680e9e4062c" + }, { "type": "WEB", "url": "https://medium.com/@williamamorim256/stored-xss-vulnerability-discovered-in-sas-9-4-admin-console-5680e9e4062c" diff --git a/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json index 2d00b22c3fe..28b1b065362 100644 --- a/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json +++ b/advisories/unreviewed/2023/04/GHSA-rfh2-62gc-x7hw/GHSA-rfh2-62gc-x7hw.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json b/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json index 1529c2c1027..1e457d9a40d 100644 --- a/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json +++ b/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgjq-f6gr-756j", - "modified": "2023-04-09T03:30:18Z", + "modified": "2025-02-18T15:31:05Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-26916" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/CESNET/libyang/issues/1979" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6NQZHCJG3SBMFOQNIPRZGKDK3ARHLTTB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2VWGCMYKQH4BTFEHX5VYEXXOPIKKFHS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6NQZHCJG3SBMFOQNIPRZGKDK3ARHLTTB" diff --git a/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json b/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json index 0c2f1d59724..628c3c10668 100644 --- a/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json +++ b/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4ph3-7qqh-5h7g", - "modified": "2024-03-11T21:31:27Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-11T21:31:27Z", "aliases": [ "CVE-2024-27229" ], "details": "In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4xff-6v5v-4gj4/GHSA-4xff-6v5v-4gj4.json b/advisories/unreviewed/2024/03/GHSA-4xff-6v5v-4gj4/GHSA-4xff-6v5v-4gj4.json index 45bb069b40e..b94025e016b 100644 --- a/advisories/unreviewed/2024/03/GHSA-4xff-6v5v-4gj4/GHSA-4xff-6v5v-4gj4.json +++ b/advisories/unreviewed/2024/03/GHSA-4xff-6v5v-4gj4/GHSA-4xff-6v5v-4gj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4xff-6v5v-4gj4", - "modified": "2024-03-06T00:31:26Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-24276" ], "details": "Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json b/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json index b19193bfc4c..ec93118f8b8 100644 --- a/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json +++ b/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-64pw-78r7-788g", - "modified": "2024-03-11T21:31:25Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-11T21:31:25Z", "aliases": [ "CVE-2024-22011" ], "details": "In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cqwq-wj9g-qgrx/GHSA-cqwq-wj9g-qgrx.json b/advisories/unreviewed/2024/03/GHSA-cqwq-wj9g-qgrx/GHSA-cqwq-wj9g-qgrx.json index 91a9634cee2..74f0578a8af 100644 --- a/advisories/unreviewed/2024/03/GHSA-cqwq-wj9g-qgrx/GHSA-cqwq-wj9g-qgrx.json +++ b/advisories/unreviewed/2024/03/GHSA-cqwq-wj9g-qgrx/GHSA-cqwq-wj9g-qgrx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqwq-wj9g-qgrx", - "modified": "2024-03-11T21:31:27Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27227" ], "details": "Android kernel allows Remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f43r-5jhm-fh67/GHSA-f43r-5jhm-fh67.json b/advisories/unreviewed/2024/03/GHSA-f43r-5jhm-fh67/GHSA-f43r-5jhm-fh67.json index 92ce44435ab..7395242e787 100644 --- a/advisories/unreviewed/2024/03/GHSA-f43r-5jhm-fh67/GHSA-f43r-5jhm-fh67.json +++ b/advisories/unreviewed/2024/03/GHSA-f43r-5jhm-fh67/GHSA-f43r-5jhm-fh67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f43r-5jhm-fh67", - "modified": "2024-03-06T00:31:26Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-24275" ], "details": "Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json b/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json index 1ea752b4a22..2c0ff74fdbb 100644 --- a/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json +++ b/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqh8-982r-rggm", - "modified": "2024-03-11T21:31:27Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-11T21:31:27Z", "aliases": [ "CVE-2024-27237" ], "details": "In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-131" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v85c-wg53-qgrm/GHSA-v85c-wg53-qgrm.json b/advisories/unreviewed/2024/03/GHSA-v85c-wg53-qgrm/GHSA-v85c-wg53-qgrm.json index 57470641fe6..a7e8bce1680 100644 --- a/advisories/unreviewed/2024/03/GHSA-v85c-wg53-qgrm/GHSA-v85c-wg53-qgrm.json +++ b/advisories/unreviewed/2024/03/GHSA-v85c-wg53-qgrm/GHSA-v85c-wg53-qgrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v85c-wg53-qgrm", - "modified": "2024-03-11T21:31:26Z", + "modified": "2025-02-18T15:31:05Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27218" ], "details": "In update_freq_data of TBD, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2025/01/GHSA-37pg-r5mj-5q6w/GHSA-37pg-r5mj-5q6w.json b/advisories/unreviewed/2025/01/GHSA-37pg-r5mj-5q6w/GHSA-37pg-r5mj-5q6w.json index 89b099af825..dcb0ea4f9a3 100644 --- a/advisories/unreviewed/2025/01/GHSA-37pg-r5mj-5q6w/GHSA-37pg-r5mj-5q6w.json +++ b/advisories/unreviewed/2025/01/GHSA-37pg-r5mj-5q6w/GHSA-37pg-r5mj-5q6w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37pg-r5mj-5q6w", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57912" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: zpa2326: fix information leak in triggered buffer\n\nThe 'sample' local struct is used to push data to user space from a\ntriggered buffer, but it has a hole between the temperature and the\ntimestamp (u32 pressure, u16 temperature, GAP, u64 timestamp).\nThis hole is never initialized.\n\nInitialize the struct to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-52cr-8q5h-6fpf/GHSA-52cr-8q5h-6fpf.json b/advisories/unreviewed/2025/01/GHSA-52cr-8q5h-6fpf/GHSA-52cr-8q5h-6fpf.json index 0df9961668b..f20a2c9db7f 100644 --- a/advisories/unreviewed/2025/01/GHSA-52cr-8q5h-6fpf/GHSA-52cr-8q5h-6fpf.json +++ b/advisories/unreviewed/2025/01/GHSA-52cr-8q5h-6fpf/GHSA-52cr-8q5h-6fpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52cr-8q5h-6fpf", - "modified": "2025-01-19T12:31:26Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57909" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: bh1745: fix information leak in triggered buffer\n\nThe 'scan' local struct is used to push data to user space from a\ntriggered buffer, but it does not set values for inactive channels, as\nit only uses iio_for_each_active_channel() to assign new values.\n\nInitialize the struct to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6hmf-56g8-p898/GHSA-6hmf-56g8-p898.json b/advisories/unreviewed/2025/01/GHSA-6hmf-56g8-p898/GHSA-6hmf-56g8-p898.json index 16746588b09..f1942407842 100644 --- a/advisories/unreviewed/2025/01/GHSA-6hmf-56g8-p898/GHSA-6hmf-56g8-p898.json +++ b/advisories/unreviewed/2025/01/GHSA-6hmf-56g8-p898/GHSA-6hmf-56g8-p898.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hmf-56g8-p898", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57907" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: rockchip_saradc: fix information leak in triggered buffer\n\nThe 'data' local struct is used to push data to user space from a\ntriggered buffer, but it does not set values for inactive channels, as\nit only uses iio_for_each_active_channel() to assign new values.\n\nInitialize the struct to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cm46-j2rc-99mf/GHSA-cm46-j2rc-99mf.json b/advisories/unreviewed/2025/01/GHSA-cm46-j2rc-99mf/GHSA-cm46-j2rc-99mf.json index 97b6fffdf62..2a8b24c4ba1 100644 --- a/advisories/unreviewed/2025/01/GHSA-cm46-j2rc-99mf/GHSA-cm46-j2rc-99mf.json +++ b/advisories/unreviewed/2025/01/GHSA-cm46-j2rc-99mf/GHSA-cm46-j2rc-99mf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cm46-j2rc-99mf", - "modified": "2025-01-19T12:31:26Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57905" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix information leak in triggered buffer\n\nThe 'scan' local struct is used to push data to user space from a\ntriggered buffer, but it has a hole between the sample (unsigned int)\nand the timestamp. This hole is never initialized.\n\nInitialize the struct to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f5j6-wv5v-rgw9/GHSA-f5j6-wv5v-rgw9.json b/advisories/unreviewed/2025/01/GHSA-f5j6-wv5v-rgw9/GHSA-f5j6-wv5v-rgw9.json index e5dba0d00e6..11e49452a16 100644 --- a/advisories/unreviewed/2025/01/GHSA-f5j6-wv5v-rgw9/GHSA-f5j6-wv5v-rgw9.json +++ b/advisories/unreviewed/2025/01/GHSA-f5j6-wv5v-rgw9/GHSA-f5j6-wv5v-rgw9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5j6-wv5v-rgw9", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57908" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: imu: kmx61: fix information leak in triggered buffer\n\nThe 'buffer' local array is used to push data to user space from a\ntriggered buffer, but it does not set values for inactive channels, as\nit only uses iio_for_each_active_channel() to assign new values.\n\nInitialize the array to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f5w3-q6fx-5p9r/GHSA-f5w3-q6fx-5p9r.json b/advisories/unreviewed/2025/01/GHSA-f5w3-q6fx-5p9r/GHSA-f5w3-q6fx-5p9r.json index 7c41bd1a14f..1875c23778a 100644 --- a/advisories/unreviewed/2025/01/GHSA-f5w3-q6fx-5p9r/GHSA-f5w3-q6fx-5p9r.json +++ b/advisories/unreviewed/2025/01/GHSA-f5w3-q6fx-5p9r/GHSA-f5w3-q6fx-5p9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5w3-q6fx-5p9r", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57906" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads8688: fix information leak in triggered buffer\n\nThe 'buffer' local array is used to push data to user space from a\ntriggered buffer, but it does not set values for inactive channels, as\nit only uses iio_for_each_active_channel() to assign new values.\n\nInitialize the array to zero before using it to avoid pushing\nuninitialized information to userspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hgm9-g82q-236j/GHSA-hgm9-g82q-236j.json b/advisories/unreviewed/2025/01/GHSA-hgm9-g82q-236j/GHSA-hgm9-g82q-236j.json index 9a5145586d1..a248a6f36a7 100644 --- a/advisories/unreviewed/2025/01/GHSA-hgm9-g82q-236j/GHSA-hgm9-g82q-236j.json +++ b/advisories/unreviewed/2025/01/GHSA-hgm9-g82q-236j/GHSA-hgm9-g82q-236j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hgm9-g82q-236j", - "modified": "2025-01-19T12:31:26Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57916" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Resolve kernel panic during GPIO IRQ handling\n\nResolve kernel panic caused by improper handling of IRQs while\naccessing GPIO values. This is done by replacing generic_handle_irq with\nhandle_nested_irq.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v5jf-jh4j-87cv/GHSA-v5jf-jh4j-87cv.json b/advisories/unreviewed/2025/01/GHSA-v5jf-jh4j-87cv/GHSA-v5jf-jh4j-87cv.json index e1fcf45552d..d6186874a30 100644 --- a/advisories/unreviewed/2025/01/GHSA-v5jf-jh4j-87cv/GHSA-v5jf-jh4j-87cv.json +++ b/advisories/unreviewed/2025/01/GHSA-v5jf-jh4j-87cv/GHSA-v5jf-jh4j-87cv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v5jf-jh4j-87cv", - "modified": "2025-01-19T12:31:26Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-01-19T12:31:26Z", "aliases": [ "CVE-2024-57919" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix divide error in DM plane scale calcs\n\ndm_get_plane_scale doesn't take into account plane scaled size equal to\nzero, leading to a kernel oops due to division by zero. Fix by setting\nout-scale size as zero when the dst size is zero, similar to what is\ndone by drm_calc_scale(). This issue started with the introduction of\ncursor ovelay mode that uses this function to assess cursor mode changes\nvia dm_crtc_get_cursor_mode() before checking plane state.\n\n[Dec17 17:14] Oops: divide error: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000018] CPU: 5 PID: 1660 Comm: surface-DP-1 Not tainted 6.10.0+ #231\n[ +0.000007] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024\n[ +0.000004] RIP: 0010:dm_get_plane_scale+0x3f/0x60 [amdgpu]\n[ +0.000553] Code: 44 0f b7 41 3a 44 0f b7 49 3e 83 e0 0f 48 0f a3 c2 73 21 69 41 28 e8 03 00 00 31 d2 41 f7 f1 31 d2 89 06 69 41 2c e8 03 00 00 <41> f7 f0 89 07 e9 d7 d8 7e e9 44 89 c8 45 89 c1 41 89 c0 eb d4 66\n[ +0.000005] RSP: 0018:ffffa8df0de6b8a0 EFLAGS: 00010246\n[ +0.000006] RAX: 00000000000003e8 RBX: ffff9ac65c1f6e00 RCX: ffff9ac65d055500\n[ +0.000003] RDX: 0000000000000000 RSI: ffffa8df0de6b8b0 RDI: ffffa8df0de6b8b4\n[ +0.000004] RBP: ffff9ac64e7a5800 R08: 0000000000000000 R09: 0000000000000a00\n[ +0.000003] R10: 00000000000000ff R11: 0000000000000054 R12: ffff9ac6d0700010\n[ +0.000003] R13: ffff9ac65d054f00 R14: ffff9ac65d055500 R15: ffff9ac64e7a60a0\n[ +0.000004] FS: 00007f869ea00640(0000) GS:ffff9ac970080000(0000) knlGS:0000000000000000\n[ +0.000004] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.000003] CR2: 000055ca701becd0 CR3: 000000010e7f2000 CR4: 0000000000350ef0\n[ +0.000004] Call Trace:\n[ +0.000007] \n[ +0.000006] ? __die_body.cold+0x19/0x27\n[ +0.000009] ? die+0x2e/0x50\n[ +0.000007] ? do_trap+0xca/0x110\n[ +0.000007] ? do_error_trap+0x6a/0x90\n[ +0.000006] ? dm_get_plane_scale+0x3f/0x60 [amdgpu]\n[ +0.000504] ? exc_divide_error+0x38/0x50\n[ +0.000005] ? dm_get_plane_scale+0x3f/0x60 [amdgpu]\n[ +0.000488] ? asm_exc_divide_error+0x1a/0x20\n[ +0.000011] ? dm_get_plane_scale+0x3f/0x60 [amdgpu]\n[ +0.000593] dm_crtc_get_cursor_mode+0x33f/0x430 [amdgpu]\n[ +0.000562] amdgpu_dm_atomic_check+0x2ef/0x1770 [amdgpu]\n[ +0.000501] drm_atomic_check_only+0x5e1/0xa30 [drm]\n[ +0.000047] drm_mode_atomic_ioctl+0x832/0xcb0 [drm]\n[ +0.000050] ? __pfx_drm_mode_atomic_ioctl+0x10/0x10 [drm]\n[ +0.000047] drm_ioctl_kernel+0xb3/0x100 [drm]\n[ +0.000062] drm_ioctl+0x27a/0x4f0 [drm]\n[ +0.000049] ? __pfx_drm_mode_atomic_ioctl+0x10/0x10 [drm]\n[ +0.000055] amdgpu_drm_ioctl+0x4e/0x90 [amdgpu]\n[ +0.000360] __x64_sys_ioctl+0x97/0xd0\n[ +0.000010] do_syscall_64+0x82/0x190\n[ +0.000008] ? __pfx_drm_mode_createblob_ioctl+0x10/0x10 [drm]\n[ +0.000044] ? srso_return_thunk+0x5/0x5f\n[ +0.000006] ? drm_ioctl_kernel+0xb3/0x100 [drm]\n[ +0.000040] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? __check_object_size+0x50/0x220\n[ +0.000007] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? drm_ioctl+0x2a4/0x4f0 [drm]\n[ +0.000039] ? __pfx_drm_mode_createblob_ioctl+0x10/0x10 [drm]\n[ +0.000043] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? __pm_runtime_suspend+0x69/0xc0\n[ +0.000006] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? amdgpu_drm_ioctl+0x71/0x90 [amdgpu]\n[ +0.000366] ? srso_return_thunk+0x5/0x5f\n[ +0.000006] ? syscall_exit_to_user_mode+0x77/0x210\n[ +0.000007] ? srso_return_thunk+0x5/0x5f\n[ +0.000005] ? do_syscall_64+0x8e/0x190\n[ +0.000006] ? srso_return_thunk+0x5/0x5f\n[ +0.000006] ? do_syscall_64+0x8e/0x190\n[ +0.000006] ? srso_return_thunk+0x5/0x5f\n[ +0.000007] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000008] RIP: 0033:0x55bb7cd962bc\n[ +0.000007] Code: 4c 89 6c 24 18 4c 89 64 24 20 4c 89 74 24 28 0f 57 c0 0f 11 44 24 30 89 c7 48 8d 54 24 08 b8 10 00 00 00 be bc 64\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T12:15:26Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2hqc-v3c9-r36r/GHSA-2hqc-v3c9-r36r.json b/advisories/unreviewed/2025/02/GHSA-2hqc-v3c9-r36r/GHSA-2hqc-v3c9-r36r.json index a8fdc4a1588..720d7692b59 100644 --- a/advisories/unreviewed/2025/02/GHSA-2hqc-v3c9-r36r/GHSA-2hqc-v3c9-r36r.json +++ b/advisories/unreviewed/2025/02/GHSA-2hqc-v3c9-r36r/GHSA-2hqc-v3c9-r36r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2hqc-v3c9-r36r", - "modified": "2025-02-13T18:32:35Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-02-13T18:32:35Z", "aliases": [ "CVE-2025-25901" ], "details": "A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/WanSlaacCfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:50Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2m52-fc9q-48mj/GHSA-2m52-fc9q-48mj.json b/advisories/unreviewed/2025/02/GHSA-2m52-fc9q-48mj/GHSA-2m52-fc9q-48mj.json index 60c345fbcf2..3e4549d0339 100644 --- a/advisories/unreviewed/2025/02/GHSA-2m52-fc9q-48mj/GHSA-2m52-fc9q-48mj.json +++ b/advisories/unreviewed/2025/02/GHSA-2m52-fc9q-48mj/GHSA-2m52-fc9q-48mj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2m52-fc9q-48mj", - "modified": "2025-02-14T09:31:22Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-02-14T09:31:22Z", "aliases": [ "CVE-2025-1298" ], "details": "Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T08:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3947-v5cg-rpwj/GHSA-3947-v5cg-rpwj.json b/advisories/unreviewed/2025/02/GHSA-3947-v5cg-rpwj/GHSA-3947-v5cg-rpwj.json new file mode 100644 index 00000000000..98b777d021a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3947-v5cg-rpwj/GHSA-3947-v5cg-rpwj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3947-v5cg-rpwj", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2024-13689" + ], + "details": "The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13689" + }, + { + "type": "WEB", + "url": "https://support.undsgn.com/hc/en-us/articles/213454129-Change-Log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0a61e11-1137-4da0-8580-0a44300b1542?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-749g-9h7c-6xjr/GHSA-749g-9h7c-6xjr.json b/advisories/unreviewed/2025/02/GHSA-749g-9h7c-6xjr/GHSA-749g-9h7c-6xjr.json index e7172064410..2009a22e589 100644 --- a/advisories/unreviewed/2025/02/GHSA-749g-9h7c-6xjr/GHSA-749g-9h7c-6xjr.json +++ b/advisories/unreviewed/2025/02/GHSA-749g-9h7c-6xjr/GHSA-749g-9h7c-6xjr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-c5g7-7w25-772m/GHSA-c5g7-7w25-772m.json b/advisories/unreviewed/2025/02/GHSA-c5g7-7w25-772m/GHSA-c5g7-7w25-772m.json new file mode 100644 index 00000000000..6ca5edb74e2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c5g7-7w25-772m/GHSA-c5g7-7w25-772m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5g7-7w25-772m", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2024-57050" + ], + "details": "A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57050" + }, + { + "type": "WEB", + "url": "https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/WR840N%20v6/ACL%20bypass%20Vulnerability%20in%20TP-Link%20TL-WR840N.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json b/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json new file mode 100644 index 00000000000..2a302fe67ef --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c82f-pmfx-x3vv/GHSA-c82f-pmfx-x3vv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c82f-pmfx-x3vv", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2025-21702" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npfifo_tail_enqueue: Drop new packet when sch->limit == 0\n\nExpected behaviour:\nIn case we reach scheduler's limit, pfifo_tail_enqueue() will drop a\npacket in scheduler's queue and decrease scheduler's qlen by one.\nThen, pfifo_tail_enqueue() enqueue new packet and increase\nscheduler's qlen by one. Finally, pfifo_tail_enqueue() return\n`NET_XMIT_CN` status code.\n\nWeird behaviour:\nIn case we set `sch->limit == 0` and trigger pfifo_tail_enqueue() on a\nscheduler that has no packet, the 'drop a packet' step will do nothing.\nThis means the scheduler's qlen still has value equal 0.\nThen, we continue to enqueue new packet and increase scheduler's qlen by\none. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by\none and return `NET_XMIT_CN` status code.\n\nThe problem is:\nLet's say we have two qdiscs: Qdisc_A and Qdisc_B.\n - Qdisc_A's type must have '->graft()' function to create parent/child relationship.\n Let's say Qdisc_A's type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.\n - Qdisc_B's type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.\n - Qdisc_B is configured to have `sch->limit == 0`.\n - Qdisc_A is configured to route the enqueued's packet to Qdisc_B.\n\nEnqueue packet through Qdisc_A will lead to:\n - hfsc_enqueue(Qdisc_A) -> pfifo_tail_enqueue(Qdisc_B)\n - Qdisc_B->q.qlen += 1\n - pfifo_tail_enqueue() return `NET_XMIT_CN`\n - hfsc_enqueue() check for `NET_XMIT_SUCCESS` and see `NET_XMIT_CN` => hfsc_enqueue() don't increase qlen of Qdisc_A.\n\nThe whole process lead to a situation where Qdisc_A->q.qlen == 0 and Qdisc_B->q.qlen == 1.\nReplace 'hfsc' with other type (for example: 'drr') still lead to the same problem.\nThis violate the design where parent's qlen should equal to the sum of its childrens'qlen.\n\nBug impact: This issue can be used for user->kernel privilege escalation when it is reachable.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21702" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/647cef20e649c576dff271e018d5d15d998b629d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6a079c3b6f95378f26e2aeda520cb3176f7067b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e40cb34b7f247fe2e366fd192700d1b4f38196ca" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cg2m-239p-9xhp/GHSA-cg2m-239p-9xhp.json b/advisories/unreviewed/2025/02/GHSA-cg2m-239p-9xhp/GHSA-cg2m-239p-9xhp.json new file mode 100644 index 00000000000..4e1f7761689 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cg2m-239p-9xhp/GHSA-cg2m-239p-9xhp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg2m-239p-9xhp", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2024-57046" + ], + "details": "A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding \"?x=1.gif\" to the the requested url, it will be recognized as passing the authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57046" + }, + { + "type": "WEB", + "url": "https://github.com/Shuanunio/CVE_Requests/blob/main/Netgear/DGN2200/ACL%20bypass%20Vulnerability%20in%20Netgear%20DGN2200.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json b/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json new file mode 100644 index 00000000000..45b66c2ea99 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg86-m5xc-jqrm", + "modified": "2025-02-18T15:31:09Z", + "published": "2025-02-18T15:31:09Z", + "aliases": [ + "CVE-2025-21703" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetem: Update sch->q.qlen before qdisc_tree_reduce_backlog()\n\nqdisc_tree_reduce_backlog() notifies parent qdisc only if child\nqdisc becomes empty, therefore we need to reduce the backlog of the\nchild qdisc before calling it. Otherwise it would miss the opportunity\nto call cops->qlen_notify(), in the case of DRR, it resulted in UAF\nsince DRR uses ->qlen_notify() to maintain its active list.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21703" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f8e3f4a4b8b90ad274dfbc66fc7d55cb582f4d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6312555249082d6d8cc5321ff725df05482d8b83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/638ba5089324796c2ee49af10427459c2de35f71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/839ecc583fa00fab785fde1c85a326743657fd32" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ffvr-gmp3-xx43/GHSA-ffvr-gmp3-xx43.json b/advisories/unreviewed/2025/02/GHSA-ffvr-gmp3-xx43/GHSA-ffvr-gmp3-xx43.json index 5f5f2d8f446..524a75fe031 100644 --- a/advisories/unreviewed/2025/02/GHSA-ffvr-gmp3-xx43/GHSA-ffvr-gmp3-xx43.json +++ b/advisories/unreviewed/2025/02/GHSA-ffvr-gmp3-xx43/GHSA-ffvr-gmp3-xx43.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffvr-gmp3-xx43", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-02-14T15:31:05Z", "aliases": [ "CVE-2024-56180" ], "details": "CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\\linux\\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T14:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json b/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json index 4bd77cf09ad..81e014d92b6 100644 --- a/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json +++ b/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg38-pgj3-5w5f", - "modified": "2025-02-14T21:31:05Z", + "modified": "2025-02-18T15:31:07Z", "published": "2025-02-14T21:31:05Z", "aliases": [ "CVE-2024-31144" ], "details": "For a brief summary of Xapi terminology, see:\n\n https://xapi-project.github.io/xen-api/overview.html#object-model-overview \n\nXapi contains functionality to backup and restore metadata about Virtual\nMachines and Storage Repositories (SRs).\n\nThe metadata itself is stored in a Virtual Disk Image (VDI) inside an\nSR. This is used for two purposes; a general backup of metadata\n(e.g. to recover from a host failure if the filer is still good), and\nPortable SRs (e.g. using an external hard drive to move VMs to another\nhost).\n\nMetadata is only restored as an explicit administrator action, but\noccurs in cases where the host has no information about the SR, and must\nlocate the metadata VDI in order to retrieve the metadata.\n\nThe metadata VDI is located by searching (in UUID alphanumeric order)\neach VDI, mounting it, and seeing if there is a suitable metadata file\npresent. The first matching VDI is deemed to be the metadata VDI, and\nis restored from.\n\nIn the general case, the content of VDIs are controlled by the VM owner,\nand should not be trusted by the host administrator.\n\nA malicious guest can manipulate its disk to appear to be a metadata\nbackup.\n\nA guest cannot choose the UUIDs of its VDIs, but a guest with one disk\nhas a 50% chance of sorting ahead of the legitimate metadata backup. A\nguest with two disks has a 75% chance, etc.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T21:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jhqw-cq3q-2p2g/GHSA-jhqw-cq3q-2p2g.json b/advisories/unreviewed/2025/02/GHSA-jhqw-cq3q-2p2g/GHSA-jhqw-cq3q-2p2g.json new file mode 100644 index 00000000000..d12ca7e8963 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jhqw-cq3q-2p2g/GHSA-jhqw-cq3q-2p2g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhqw-cq3q-2p2g", + "modified": "2025-02-18T15:31:07Z", + "published": "2025-02-18T15:31:07Z", + "aliases": [ + "CVE-2025-1269" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1269" + }, + { + "type": "WEB", + "url": "https://github.com/limanmys/core/releases/tag/release.master.1010" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json b/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json new file mode 100644 index 00000000000..743a9c20fda --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5jc-239c-pvvf", + "modified": "2025-02-18T15:31:07Z", + "published": "2025-02-18T15:31:07Z", + "aliases": [ + "CVE-2025-1414" + ], + "details": "Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1414" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1943179" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qhjq-4w73-8cmv/GHSA-qhjq-4w73-8cmv.json b/advisories/unreviewed/2025/02/GHSA-qhjq-4w73-8cmv/GHSA-qhjq-4w73-8cmv.json index 31ed5f44a8f..e036efeb8dd 100644 --- a/advisories/unreviewed/2025/02/GHSA-qhjq-4w73-8cmv/GHSA-qhjq-4w73-8cmv.json +++ b/advisories/unreviewed/2025/02/GHSA-qhjq-4w73-8cmv/GHSA-qhjq-4w73-8cmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhjq-4w73-8cmv", - "modified": "2025-02-13T18:32:35Z", + "modified": "2025-02-18T15:31:06Z", "published": "2025-02-13T18:32:34Z", "aliases": [ "CVE-2025-25897" ], "details": "A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qr32-fcm4-m5h9/GHSA-qr32-fcm4-m5h9.json b/advisories/unreviewed/2025/02/GHSA-qr32-fcm4-m5h9/GHSA-qr32-fcm4-m5h9.json new file mode 100644 index 00000000000..8428416db1a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qr32-fcm4-m5h9/GHSA-qr32-fcm4-m5h9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr32-fcm4-m5h9", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2024-57049" + ], + "details": "A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57049" + }, + { + "type": "WEB", + "url": "https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/archer%20c20/ACL%20bypass%20Vulnerability%20in%20TP-Link%20archer%20c20.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wc7r-hp6q-64m9/GHSA-wc7r-hp6q-64m9.json b/advisories/unreviewed/2025/02/GHSA-wc7r-hp6q-64m9/GHSA-wc7r-hp6q-64m9.json new file mode 100644 index 00000000000..62e2415dea9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wc7r-hp6q-64m9/GHSA-wc7r-hp6q-64m9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc7r-hp6q-64m9", + "modified": "2025-02-18T15:31:08Z", + "published": "2025-02-18T15:31:08Z", + "aliases": [ + "CVE-2024-57045" + ], + "details": "A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57045" + }, + { + "type": "WEB", + "url": "https://github.com/Shuanunio/CVE_Requests/blob/main/D-Link/DIR-859/ACL%20bypass%20Vulnerability%20in%20D-Link%20DIR-859.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T15:15:16Z" + } +} \ No newline at end of file