diff --git a/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json b/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json index 8c19ee637df..434445463df 100644 --- a/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json +++ b/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json b/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json index eb23c31d65d..80969354f75 100644 --- a/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json +++ b/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v8v-cp6r-mq7c", - "modified": "2022-09-27T00:00:20Z", + "modified": "2025-05-27T15:31:17Z", "published": "2022-09-25T00:00:27Z", "aliases": [ "CVE-2022-41322" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RRNAPU33PHEH64P77YL3AJO6CTZGHTX" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI" diff --git a/advisories/unreviewed/2022/09/GHSA-7448-x2vg-9pm2/GHSA-7448-x2vg-9pm2.json b/advisories/unreviewed/2022/09/GHSA-7448-x2vg-9pm2/GHSA-7448-x2vg-9pm2.json index 15cda6211bb..fa74e098f4c 100644 --- a/advisories/unreviewed/2022/09/GHSA-7448-x2vg-9pm2/GHSA-7448-x2vg-9pm2.json +++ b/advisories/unreviewed/2022/09/GHSA-7448-x2vg-9pm2/GHSA-7448-x2vg-9pm2.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-98" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-79xc-f76g-hpg4/GHSA-79xc-f76g-hpg4.json b/advisories/unreviewed/2022/09/GHSA-79xc-f76g-hpg4/GHSA-79xc-f76g-hpg4.json index b51824cd267..b565b86f32d 100644 --- a/advisories/unreviewed/2022/09/GHSA-79xc-f76g-hpg4/GHSA-79xc-f76g-hpg4.json +++ b/advisories/unreviewed/2022/09/GHSA-79xc-f76g-hpg4/GHSA-79xc-f76g-hpg4.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-h886-rpm5-x6pr/GHSA-h886-rpm5-x6pr.json b/advisories/unreviewed/2022/09/GHSA-h886-rpm5-x6pr/GHSA-h886-rpm5-x6pr.json index bd9bb4f25e9..a29fdc90d49 100644 --- a/advisories/unreviewed/2022/09/GHSA-h886-rpm5-x6pr/GHSA-h886-rpm5-x6pr.json +++ b/advisories/unreviewed/2022/09/GHSA-h886-rpm5-x6pr/GHSA-h886-rpm5-x6pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h886-rpm5-x6pr", - "modified": "2022-09-25T00:00:15Z", + "modified": "2025-05-27T15:31:16Z", "published": "2022-09-23T00:00:29Z", "aliases": [ "CVE-2022-31937" diff --git a/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json b/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json index 16b8675406e..6dc119036d9 100644 --- a/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json +++ b/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qj7c-f3xj-jxpv", - "modified": "2022-09-27T00:00:21Z", + "modified": "2025-05-27T15:31:17Z", "published": "2022-09-25T00:00:21Z", "aliases": [ "CVE-2022-40188" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00008.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIMDNIUI7GTUEKIBBYYW7OCTJQFPDNXL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2VE5K3VDUHJOIA2IGT3G5R76IBADMNE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO6LIVQS62MI5GG4OVYB5RHVZMYNHAHG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIMDNIUI7GTUEKIBBYYW7OCTJQFPDNXL" @@ -42,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-407" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json b/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json index 2a94953c9b7..a4a30370b8a 100644 --- a/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json +++ b/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2rq-mrc8-r79h", - "modified": "2022-09-25T00:00:15Z", + "modified": "2025-05-27T15:31:16Z", "published": "2022-09-25T00:00:15Z", "aliases": [ "CVE-2022-37235" diff --git a/advisories/unreviewed/2022/09/GHSA-x6xq-xccv-wjp3/GHSA-x6xq-xccv-wjp3.json b/advisories/unreviewed/2022/09/GHSA-x6xq-xccv-wjp3/GHSA-x6xq-xccv-wjp3.json index 112bc9ef146..22a9ac1cfc2 100644 --- a/advisories/unreviewed/2022/09/GHSA-x6xq-xccv-wjp3/GHSA-x6xq-xccv-wjp3.json +++ b/advisories/unreviewed/2022/09/GHSA-x6xq-xccv-wjp3/GHSA-x6xq-xccv-wjp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x6xq-xccv-wjp3", - "modified": "2022-09-28T00:00:25Z", + "modified": "2025-05-27T15:31:16Z", "published": "2022-09-23T00:00:30Z", "aliases": [ "CVE-2022-37234" diff --git a/advisories/unreviewed/2023/12/GHSA-244w-g82v-mjgw/GHSA-244w-g82v-mjgw.json b/advisories/unreviewed/2023/12/GHSA-244w-g82v-mjgw/GHSA-244w-g82v-mjgw.json index 9606a226603..2e0df97025b 100644 --- a/advisories/unreviewed/2023/12/GHSA-244w-g82v-mjgw/GHSA-244w-g82v-mjgw.json +++ b/advisories/unreviewed/2023/12/GHSA-244w-g82v-mjgw/GHSA-244w-g82v-mjgw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-244w-g82v-mjgw", - "modified": "2023-12-13T21:30:28Z", + "modified": "2025-05-27T15:31:17Z", "published": "2023-12-11T06:30:26Z", "aliases": [ "CVE-2023-48425" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-8qpf-hj9q-p3rg/GHSA-8qpf-hj9q-p3rg.json b/advisories/unreviewed/2023/12/GHSA-8qpf-hj9q-p3rg/GHSA-8qpf-hj9q-p3rg.json index 9ec68fae238..acb0c55fc91 100644 --- a/advisories/unreviewed/2023/12/GHSA-8qpf-hj9q-p3rg/GHSA-8qpf-hj9q-p3rg.json +++ b/advisories/unreviewed/2023/12/GHSA-8qpf-hj9q-p3rg/GHSA-8qpf-hj9q-p3rg.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-wwc4-3prx-5752/GHSA-wwc4-3prx-5752.json b/advisories/unreviewed/2023/12/GHSA-wwc4-3prx-5752/GHSA-wwc4-3prx-5752.json index 19c8b6fab31..a877503210a 100644 --- a/advisories/unreviewed/2023/12/GHSA-wwc4-3prx-5752/GHSA-wwc4-3prx-5752.json +++ b/advisories/unreviewed/2023/12/GHSA-wwc4-3prx-5752/GHSA-wwc4-3prx-5752.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-x9qc-m3q8-9g77/GHSA-x9qc-m3q8-9g77.json b/advisories/unreviewed/2023/12/GHSA-x9qc-m3q8-9g77/GHSA-x9qc-m3q8-9g77.json index e343463c245..d859e0ffcd2 100644 --- a/advisories/unreviewed/2023/12/GHSA-x9qc-m3q8-9g77/GHSA-x9qc-m3q8-9g77.json +++ b/advisories/unreviewed/2023/12/GHSA-x9qc-m3q8-9g77/GHSA-x9qc-m3q8-9g77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9qc-m3q8-9g77", - "modified": "2023-12-12T09:30:32Z", + "modified": "2025-05-27T15:31:18Z", "published": "2023-12-12T09:30:32Z", "aliases": [ "CVE-2023-41117" diff --git a/advisories/unreviewed/2024/04/GHSA-pfvj-h8r5-43h5/GHSA-pfvj-h8r5-43h5.json b/advisories/unreviewed/2024/04/GHSA-pfvj-h8r5-43h5/GHSA-pfvj-h8r5-43h5.json index 5207c2a34b5..3d85f03c229 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfvj-h8r5-43h5/GHSA-pfvj-h8r5-43h5.json +++ b/advisories/unreviewed/2024/04/GHSA-pfvj-h8r5-43h5/GHSA-pfvj-h8r5-43h5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pfvj-h8r5-43h5", - "modified": "2024-04-11T03:34:59Z", + "modified": "2025-05-27T15:31:19Z", "published": "2024-04-11T03:34:59Z", "aliases": [ "CVE-2024-27967" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json b/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json index 6dea58bf88d..e8c168e5527 100644 --- a/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json +++ b/advisories/unreviewed/2024/04/GHSA-qvgv-g72v-425q/GHSA-qvgv-g72v-425q.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-129" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json b/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json index d60d4801521..6e518d82f63 100644 --- a/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json +++ b/advisories/unreviewed/2025/04/GHSA-2w6r-mvp4-65v2/GHSA-2w6r-mvp4-65v2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-23fp-mrfv-cwv4/GHSA-23fp-mrfv-cwv4.json b/advisories/unreviewed/2025/05/GHSA-23fp-mrfv-cwv4/GHSA-23fp-mrfv-cwv4.json index 524c252436a..fedfae12548 100644 --- a/advisories/unreviewed/2025/05/GHSA-23fp-mrfv-cwv4/GHSA-23fp-mrfv-cwv4.json +++ b/advisories/unreviewed/2025/05/GHSA-23fp-mrfv-cwv4/GHSA-23fp-mrfv-cwv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23fp-mrfv-cwv4", - "modified": "2025-05-27T06:30:34Z", + "modified": "2025-05-27T15:31:25Z", "published": "2025-05-27T06:30:34Z", "aliases": [ "CVE-2025-48827" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce" + }, + { + "type": "WEB", + "url": "https://kevintel.com/CVE-2025-48827" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json b/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json index df88368159e..488d9314f80 100644 --- a/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json +++ b/advisories/unreviewed/2025/05/GHSA-28x8-4wmv-cxfw/GHSA-28x8-4wmv-cxfw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3c6j-3hg7-vq95/GHSA-3c6j-3hg7-vq95.json b/advisories/unreviewed/2025/05/GHSA-3c6j-3hg7-vq95/GHSA-3c6j-3hg7-vq95.json new file mode 100644 index 00000000000..7d80f14ac18 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3c6j-3hg7-vq95/GHSA-3c6j-3hg7-vq95.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c6j-3hg7-vq95", + "modified": "2025-05-27T15:31:26Z", + "published": "2025-05-27T15:31:26Z", + "aliases": [ + "CVE-2025-5244" + ], + "details": "A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5244" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=16010" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32858" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310346" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310346" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584634" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hh2-42f8-hvgp/GHSA-3hh2-42f8-hvgp.json b/advisories/unreviewed/2025/05/GHSA-3hh2-42f8-hvgp/GHSA-3hh2-42f8-hvgp.json new file mode 100644 index 00000000000..0b037b33901 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hh2-42f8-hvgp/GHSA-3hh2-42f8-hvgp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hh2-42f8-hvgp", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-5247" + ], + "details": "A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \\view\\url.go. The manipulation of the argument r leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5247" + }, + { + "type": "WEB", + "url": "https://github.com/A7cc/cve/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310349" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310349" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584798" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json b/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json index b82830364e4..08ee995e543 100644 --- a/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json +++ b/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4wg2-vfcc-fg3p/GHSA-4wg2-vfcc-fg3p.json b/advisories/unreviewed/2025/05/GHSA-4wg2-vfcc-fg3p/GHSA-4wg2-vfcc-fg3p.json index 0645deb3619..274a551d019 100644 --- a/advisories/unreviewed/2025/05/GHSA-4wg2-vfcc-fg3p/GHSA-4wg2-vfcc-fg3p.json +++ b/advisories/unreviewed/2025/05/GHSA-4wg2-vfcc-fg3p/GHSA-4wg2-vfcc-fg3p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-58pj-rcxg-3vhg/GHSA-58pj-rcxg-3vhg.json b/advisories/unreviewed/2025/05/GHSA-58pj-rcxg-3vhg/GHSA-58pj-rcxg-3vhg.json index 955aef10945..baf6e101824 100644 --- a/advisories/unreviewed/2025/05/GHSA-58pj-rcxg-3vhg/GHSA-58pj-rcxg-3vhg.json +++ b/advisories/unreviewed/2025/05/GHSA-58pj-rcxg-3vhg/GHSA-58pj-rcxg-3vhg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58pj-rcxg-3vhg", - "modified": "2025-05-27T06:30:34Z", + "modified": "2025-05-27T15:31:25Z", "published": "2025-05-27T06:30:34Z", "aliases": [ "CVE-2025-48828" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce" + }, + { + "type": "WEB", + "url": "https://kevintel.com/CVE-2025-48828" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json b/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json index ceff1f7ba07..ad91d5a9eb2 100644 --- a/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json +++ b/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7p2h-v67m-x5qx/GHSA-7p2h-v67m-x5qx.json b/advisories/unreviewed/2025/05/GHSA-7p2h-v67m-x5qx/GHSA-7p2h-v67m-x5qx.json new file mode 100644 index 00000000000..8823a005296 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7p2h-v67m-x5qx/GHSA-7p2h-v67m-x5qx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p2h-v67m-x5qx", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-48798" + ], + "details": "A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48798" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-48798" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rph-qq97-wqp5/GHSA-7rph-qq97-wqp5.json b/advisories/unreviewed/2025/05/GHSA-7rph-qq97-wqp5/GHSA-7rph-qq97-wqp5.json new file mode 100644 index 00000000000..01798136db9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7rph-qq97-wqp5/GHSA-7rph-qq97-wqp5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rph-qq97-wqp5", + "modified": "2025-05-27T15:31:26Z", + "published": "2025-05-27T15:31:26Z", + "aliases": [ + "CVE-2025-5264" + ], + "details": "Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5264" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950001" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-43" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json b/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json index 74e0e06deda..d2370bf04dd 100644 --- a/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json +++ b/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json b/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json index 702ac8a3e99..14a9dfb01ea 100644 --- a/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json +++ b/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json b/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json index 93902d5d690..10740be62d5 100644 --- a/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json +++ b/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c444-p25j-g43x/GHSA-c444-p25j-g43x.json b/advisories/unreviewed/2025/05/GHSA-c444-p25j-g43x/GHSA-c444-p25j-g43x.json new file mode 100644 index 00000000000..10d40f657a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c444-p25j-g43x/GHSA-c444-p25j-g43x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c444-p25j-g43x", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-48796" + ], + "details": "A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48796" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-48796" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cjg5-jj7w-g8q6/GHSA-cjg5-jj7w-g8q6.json b/advisories/unreviewed/2025/05/GHSA-cjg5-jj7w-g8q6/GHSA-cjg5-jj7w-g8q6.json index d6301e4ea6b..e995175ba9a 100644 --- a/advisories/unreviewed/2025/05/GHSA-cjg5-jj7w-g8q6/GHSA-cjg5-jj7w-g8q6.json +++ b/advisories/unreviewed/2025/05/GHSA-cjg5-jj7w-g8q6/GHSA-cjg5-jj7w-g8q6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cmxp-xm59-3rjf/GHSA-cmxp-xm59-3rjf.json b/advisories/unreviewed/2025/05/GHSA-cmxp-xm59-3rjf/GHSA-cmxp-xm59-3rjf.json new file mode 100644 index 00000000000..e24c3be90b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cmxp-xm59-3rjf/GHSA-cmxp-xm59-3rjf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmxp-xm59-3rjf", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-3704" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a before 5.5.5.\n\nThe patch is available exclusively on GitHub at https://github.com/dbarproductions/pta-volunteer-sign-up-sheets , as the vendor encounters difficulties using SVN to deploy to the WordPress.org repository.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3704" + }, + { + "type": "WEB", + "url": "https://github.com/dbarproductions/pta-volunteer-sign-up-sheets/archive/refs/tags/5.5.5.zip" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pta-volunteer-sign-up-sheets/vulnerability/wordpress-volunteer-sign-up-sheets-plugin-5-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ff8j-mq3g-w56r/GHSA-ff8j-mq3g-w56r.json b/advisories/unreviewed/2025/05/GHSA-ff8j-mq3g-w56r/GHSA-ff8j-mq3g-w56r.json index fa3dbd34b6d..958a542f29f 100644 --- a/advisories/unreviewed/2025/05/GHSA-ff8j-mq3g-w56r/GHSA-ff8j-mq3g-w56r.json +++ b/advisories/unreviewed/2025/05/GHSA-ff8j-mq3g-w56r/GHSA-ff8j-mq3g-w56r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-fjj5-r59g-88g7/GHSA-fjj5-r59g-88g7.json b/advisories/unreviewed/2025/05/GHSA-fjj5-r59g-88g7/GHSA-fjj5-r59g-88g7.json new file mode 100644 index 00000000000..d32d4f96c12 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fjj5-r59g-88g7/GHSA-fjj5-r59g-88g7.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjj5-r59g-88g7", + "modified": "2025-05-27T15:31:27Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5265" + ], + "details": "Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.\n*This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5265" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1962301" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-43" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h36q-jch3-f9mw/GHSA-h36q-jch3-f9mw.json b/advisories/unreviewed/2025/05/GHSA-h36q-jch3-f9mw/GHSA-h36q-jch3-f9mw.json new file mode 100644 index 00000000000..2d03f44531b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h36q-jch3-f9mw/GHSA-h36q-jch3-f9mw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h36q-jch3-f9mw", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-5272" + ], + "details": "Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5272" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1726254%2C1742738%2C1960121" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h92g-mrpv-x8v2/GHSA-h92g-mrpv-x8v2.json b/advisories/unreviewed/2025/05/GHSA-h92g-mrpv-x8v2/GHSA-h92g-mrpv-x8v2.json new file mode 100644 index 00000000000..65a89a6bc5b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h92g-mrpv-x8v2/GHSA-h92g-mrpv-x8v2.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h92g-mrpv-x8v2", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-5245" + ], + "details": "A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5245" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=16004" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32829" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310347" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310347" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584635" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hf6r-227w-qwf9/GHSA-hf6r-227w-qwf9.json b/advisories/unreviewed/2025/05/GHSA-hf6r-227w-qwf9/GHSA-hf6r-227w-qwf9.json new file mode 100644 index 00000000000..cc790ee1cb3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hf6r-227w-qwf9/GHSA-hf6r-227w-qwf9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf6r-227w-qwf9", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5270" + ], + "details": "In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5270" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1910298" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hrhw-58x6-vqj7/GHSA-hrhw-58x6-vqj7.json b/advisories/unreviewed/2025/05/GHSA-hrhw-58x6-vqj7/GHSA-hrhw-58x6-vqj7.json new file mode 100644 index 00000000000..fd3b7034740 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hrhw-58x6-vqj7/GHSA-hrhw-58x6-vqj7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrhw-58x6-vqj7", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-48797" + ], + "details": "A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48797" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-48797" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2368558" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jc7v-r8h6-xr5c/GHSA-jc7v-r8h6-xr5c.json b/advisories/unreviewed/2025/05/GHSA-jc7v-r8h6-xr5c/GHSA-jc7v-r8h6-xr5c.json new file mode 100644 index 00000000000..7d2e5ad31bb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jc7v-r8h6-xr5c/GHSA-jc7v-r8h6-xr5c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc7v-r8h6-xr5c", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5271" + ], + "details": "Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5271" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1920348" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m3v8-8px9-3652/GHSA-m3v8-8px9-3652.json b/advisories/unreviewed/2025/05/GHSA-m3v8-8px9-3652/GHSA-m3v8-8px9-3652.json new file mode 100644 index 00000000000..9892392a62a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m3v8-8px9-3652/GHSA-m3v8-8px9-3652.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3v8-8px9-3652", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-5246" + ], + "details": "A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /hms/admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5246" + }, + { + "type": "WEB", + "url": "https://github.com/snkercyber/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310348" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310348" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.584718" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m885-h2wc-h2w3/GHSA-m885-h2wc-h2w3.json b/advisories/unreviewed/2025/05/GHSA-m885-h2wc-h2w3/GHSA-m885-h2wc-h2w3.json new file mode 100644 index 00000000000..980e43e180c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m885-h2wc-h2w3/GHSA-m885-h2wc-h2w3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m885-h2wc-h2w3", + "modified": "2025-05-27T15:31:27Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5268" + ], + "details": "Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5268" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1950136%2C1958121%2C1960499%2C1962634" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pfhv-4q3r-34jw/GHSA-pfhv-4q3r-34jw.json b/advisories/unreviewed/2025/05/GHSA-pfhv-4q3r-34jw/GHSA-pfhv-4q3r-34jw.json new file mode 100644 index 00000000000..997ef21f9d3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pfhv-4q3r-34jw/GHSA-pfhv-4q3r-34jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfhv-4q3r-34jw", + "modified": "2025-05-27T15:31:28Z", + "published": "2025-05-27T15:31:28Z", + "aliases": [ + "CVE-2025-2236" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services.\n\nThis issue affects Advanced Authentication versions before 6.5.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:C/RE:M/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2236" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000039947" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjg4-cx24-6mjc/GHSA-pjg4-cx24-6mjc.json b/advisories/unreviewed/2025/05/GHSA-pjg4-cx24-6mjc/GHSA-pjg4-cx24-6mjc.json new file mode 100644 index 00000000000..b2786e00a03 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pjg4-cx24-6mjc/GHSA-pjg4-cx24-6mjc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjg4-cx24-6mjc", + "modified": "2025-05-27T15:31:26Z", + "published": "2025-05-27T15:31:26Z", + "aliases": [ + "CVE-2025-5263" + ], + "details": "Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5263" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1960745" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-43" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json b/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json index 8db92076a07..6b1ec300d08 100644 --- a/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json +++ b/advisories/unreviewed/2025/05/GHSA-q5xr-h2vq-97x6/GHSA-q5xr-h2vq-97x6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q5xr-h2vq-97x6", - "modified": "2025-05-26T18:30:25Z", + "modified": "2025-05-27T15:31:25Z", "published": "2025-05-26T18:30:25Z", "aliases": [ "CVE-2025-23394" ], "details": "A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-61" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-26T16:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qjw8-8452-9587/GHSA-qjw8-8452-9587.json b/advisories/unreviewed/2025/05/GHSA-qjw8-8452-9587/GHSA-qjw8-8452-9587.json new file mode 100644 index 00000000000..42152402b54 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qjw8-8452-9587/GHSA-qjw8-8452-9587.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjw8-8452-9587", + "modified": "2025-05-27T15:31:27Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5269" + ], + "details": "Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5269" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1924108" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json b/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json index 90b39d5b2a2..33399a45876 100644 --- a/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json +++ b/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json b/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json index 7f6a29a2f73..cd7073af569 100644 --- a/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json +++ b/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json b/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json index 81ddf91f471..de69aef7d58 100644 --- a/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json +++ b/advisories/unreviewed/2025/05/GHSA-rh76-vmrr-w867/GHSA-rh76-vmrr-w867.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v5j6-fjmw-w724/GHSA-v5j6-fjmw-w724.json b/advisories/unreviewed/2025/05/GHSA-v5j6-fjmw-w724/GHSA-v5j6-fjmw-w724.json new file mode 100644 index 00000000000..1d47a28f74e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5j6-fjmw-w724/GHSA-v5j6-fjmw-w724.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5j6-fjmw-w724", + "modified": "2025-05-27T15:31:26Z", + "published": "2025-05-27T15:31:26Z", + "aliases": [ + "CVE-2025-5262" + ], + "details": "A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5262" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1962421" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-43" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v6p6-vqmj-q998/GHSA-v6p6-vqmj-q998.json b/advisories/unreviewed/2025/05/GHSA-v6p6-vqmj-q998/GHSA-v6p6-vqmj-q998.json index f10c9ec557b..aabbe748623 100644 --- a/advisories/unreviewed/2025/05/GHSA-v6p6-vqmj-q998/GHSA-v6p6-vqmj-q998.json +++ b/advisories/unreviewed/2025/05/GHSA-v6p6-vqmj-q998/GHSA-v6p6-vqmj-q998.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v6p6-vqmj-q998", - "modified": "2025-05-26T12:30:30Z", + "modified": "2025-05-27T15:31:25Z", "published": "2025-05-26T12:30:29Z", "aliases": [ "CVE-2025-35003" ], "details": "Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI and UART components) that may result in system crash, denial of service, or arbitrary code execution, after receiving maliciously crafted packets.\n\nNuttX's Bluetooth HCI/UART stack users are advised to upgrade to version 12.9.0, which fixes the identified implementation issues.\n\nThis issue affects Apache NuttX: from 7.25 before 12.9.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-26T10:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xg8q-ggjx-6hx2/GHSA-xg8q-ggjx-6hx2.json b/advisories/unreviewed/2025/05/GHSA-xg8q-ggjx-6hx2/GHSA-xg8q-ggjx-6hx2.json new file mode 100644 index 00000000000..8be1ef7b5ee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xg8q-ggjx-6hx2/GHSA-xg8q-ggjx-6hx2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg8q-ggjx-6hx2", + "modified": "2025-05-27T15:31:27Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5267" + ], + "details": "A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5267" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1954137" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xv7q-j96c-5r6v/GHSA-xv7q-j96c-5r6v.json b/advisories/unreviewed/2025/05/GHSA-xv7q-j96c-5r6v/GHSA-xv7q-j96c-5r6v.json new file mode 100644 index 00000000000..179b0f91e94 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xv7q-j96c-5r6v/GHSA-xv7q-j96c-5r6v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv7q-j96c-5r6v", + "modified": "2025-05-27T15:31:27Z", + "published": "2025-05-27T15:31:27Z", + "aliases": [ + "CVE-2025-5266" + ], + "details": "Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5266" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1965628" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-42" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-27T13:15:22Z" + } +} \ No newline at end of file