Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-27 15:33:32 +00:00
parent 2231806dcf
commit f63e94108a
58 changed files with 985 additions and 81 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4fwr-mh5q-hchh",
"modified": "2025-02-26T21:06:49Z",
"modified": "2025-02-27T15:31:50Z",
"published": "2025-02-26T18:30:39Z",
"aliases": [
"CVE-2025-1634"
@@ -48,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/80b8eb41678cdccb46e964dc324d048a5ef00f4b"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:1885"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-1634"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phg3-gv66-q38x",
"modified": "2025-02-13T17:36:19Z",
"modified": "2025-02-27T15:31:50Z",
"published": "2025-02-13T15:31:25Z",
"aliases": [
"CVE-2025-1247"
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/02ff9ed45c3928edf2a0f8b906543606fed7cd53"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:1885"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-1247"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjhx-p7x7-qfq6",
"modified": "2023-03-18T06:30:16Z",
"modified": "2025-02-27T15:31:47Z",
"published": "2023-03-15T21:30:26Z",
"aliases": [
"CVE-2023-25344"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vxf-c798-m86j",
"modified": "2024-03-29T15:30:32Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30510"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wqc-p6hx-3xmx",
"modified": "2024-03-29T15:30:32Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30500"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP All-in-One Dynamic Content Framework.This issue affects CubeWP All-in-One Dynamic Content Framework: from n/a through 1.1.12.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP All-in-One Dynamic Content Framework.This issue affects CubeWP All-in-One Dynamic Content Framework: from n/a through 1.1.12.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-637c-qr5f-c3c8",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30430"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93v4-m245-8mrg",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30427"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pvw-c3qw-6hwh",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30478"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin Bulletin: from n/a through 3.8.5.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin Bulletin: from n/a through 3.8.5.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc9p-94fp-8jcw",
"modified": "2024-03-29T15:30:32Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30495"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqch-c6jh-g9xj",
"modified": "2024-03-29T15:30:32Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30497"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw2p-r2fm-9p6g",
"modified": "2024-03-29T15:30:32Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30501"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw2v-7qj3-3qrq",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30428"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x75q-8m6m-8c94",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30429"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25pf-crf2-9cqg",
"modified": "2024-04-03T15:30:42Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26699"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr\n\n[Why]\nThere is a potential memory access violation while\niterating through array of dcn35 clks.\n\n[How]\nLimit iteration per array size.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-129"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cp7-j8xg-p2m2",
"modified": "2024-04-03T18:30:43Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26774"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid dividing by 0 in mb_update_avg_fragment_size() when block bitmap corrupt\n\nDetermine if bb_fragments is 0 instead of determining bb_free to eliminate\nthe risk of dividing by zero when the block bitmap is corrupted.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-369"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jw4-rrq4-7g22",
"modified": "2024-06-26T00:31:36Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26776"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-sfc-v3xx: Return IRQ_NONE if no interrupts were detected\n\nReturn IRQ_NONE from the interrupt handler when no interrupt was\ndetected. Because an empty interrupt will cause a null pointer error:\n\n Unable to handle kernel NULL pointer dereference at virtual\n address 0000000000000008\n Call trace:\n complete+0x54/0x100\n hisi_sfc_v3xx_isr+0x2c/0x40 [spi_hisi_sfc_v3xx]\n __handle_irq_event_percpu+0x64/0x1e0\n handle_irq_event+0x7c/0x1cc",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cpw-m35q-r38g",
"modified": "2024-04-09T21:31:58Z",
"modified": "2025-02-27T15:31:50Z",
"published": "2024-04-09T21:31:57Z",
"aliases": [
"CVE-2024-1424"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m6c-v88j-qqxh",
"modified": "2024-06-27T12:30:44Z",
"modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26778"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: savage: Error out if pixclock equals zero\n\nThe userspace program could pass any values to the driver through\nioctl() interface. If the driver doesn't check the value of pixclock,\nit may cause divide-by-zero error.\n\nAlthough pixclock is checked in savagefb_decode_var(), but it is not\nchecked properly in savagefb_probe(). Fix this by checking whether\npixclock is zero in the function savagefb_check_var() before\ninfo->var.pixclock is used as the divisor.\n\nThis is similar to CVE-2022-3061 in i740fb which was fixed by\ncommit 15cf0b8.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-369"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"

Some files were not shown because too many files have changed in this diff Show More