From f86672153ea7b5f1e0d0bcb7e678bc3bf96db214 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 6 May 2025 21:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3j37-x46m-f23g.json | 3 +- .../GHSA-4xm5-4w7j-j8qm.json | 2 +- .../GHSA-8m8q-r5vq-5fg3.json | 4 +- .../GHSA-mcwm-rp7p-mm3c.json | 2 +- .../GHSA-rh5w-f4gw-ppw8.json | 2 +- .../GHSA-f2x8-4jwf-gqrg.json | 10 ++++- .../GHSA-w8cr-4wjm-8jwj.json | 1 + .../GHSA-2h36-2cxh-4whm.json | 4 +- .../GHSA-3697-9w4g-6gpf.json | 4 +- .../GHSA-3rq8-jv8q-ghj7.json | 4 +- .../GHSA-3v2r-gf9x-wpgw.json | 4 +- .../GHSA-4f2x-g7q8-5cjp.json | 4 +- .../GHSA-4f45-x86c-28mm.json | 4 +- .../GHSA-6gcw-xxjf-q6rm.json | 4 +- .../GHSA-84ww-4wqp-3333.json | 4 +- .../GHSA-8p4p-376x-fv7v.json | 4 +- .../GHSA-ccfm-q6rr-cwmr.json | 4 +- .../GHSA-fgf8-vx7f-99w6.json | 4 +- .../GHSA-fj87-wrmx-mhhj.json | 4 +- .../GHSA-fmvh-rqw4-xjgg.json | 4 +- .../GHSA-g7q8-m2m9-6rxm.json | 4 +- .../GHSA-h37x-544m-w8g9.json | 4 +- .../GHSA-j9r9-pw35-cqq2.json | 4 +- .../GHSA-jjr3-mpqc-7w9v.json | 4 +- .../GHSA-m455-p2ph-4m7m.json | 4 +- .../GHSA-p8c5-57m9-rp9f.json | 4 +- .../GHSA-qx6c-q8gv-5qrh.json | 4 +- .../GHSA-r3x3-pfq4-cvw2.json | 4 +- .../GHSA-v2vp-9rm4-g6h9.json | 4 +- .../GHSA-v4qp-vm8g-fvqc.json | 4 +- .../GHSA-vcqr-9c66-fvvh.json | 4 +- .../GHSA-x64r-97x8-7c32.json | 4 +- .../GHSA-gx2w-592v-wg4m.json | 4 +- .../GHSA-hvrj-r9f4-xr39.json | 2 +- .../GHSA-4r78-7mmp-3xjj.json | 4 +- .../GHSA-6wx8-g7xc-9qp2.json | 4 +- .../GHSA-76f8-6hfx-w3xj.json | 4 +- .../GHSA-7ghv-4mjc-99wp.json | 4 +- .../GHSA-85c2-wjfm-h4fw.json | 4 +- .../GHSA-8c8m-p9jj-3j4j.json | 4 +- .../GHSA-9w6g-r3rj-g5xg.json | 4 +- .../GHSA-c3p2-8x6x-wvh2.json | 4 +- .../GHSA-rv7j-2mm5-9fv2.json | 4 +- .../GHSA-v829-2px7-7w8w.json | 4 +- .../GHSA-ww6m-hg6p-rm96.json | 4 +- .../GHSA-x9r4-wx9q-2r6r.json | 4 +- .../GHSA-37hm-8cwf-jp7f.json | 3 +- .../GHSA-4hgg-qgc6-rv76.json | 3 +- .../GHSA-7967-r4q5-m6jj.json | 3 +- .../GHSA-7w58-2c67-8xhv.json | 3 +- .../GHSA-9gqj-qmq3-h3hc.json | 3 +- .../GHSA-gwgm-rvh4-63c2.json | 3 +- .../GHSA-jxj9-c3m8-f8q8.json | 3 +- .../GHSA-r94p-w2wf-q9c9.json | 3 +- .../GHSA-vc2p-rvx8-vfx3.json | 3 +- .../GHSA-x3jm-2wx8-ccv4.json | 3 +- .../GHSA-x6j2-4hm4-hxj3.json | 3 +- .../GHSA-2v3j-xqf9-rv5m.json | 4 +- .../GHSA-3gvf-4425-jjq6.json | 3 +- .../GHSA-7635-mr68-26j6.json | 4 +- .../GHSA-fg5v-3r25-5f95.json | 4 +- .../GHSA-g2mr-q8jv-5635.json | 4 +- .../GHSA-h2gq-85xh-8c3c.json | 4 +- .../GHSA-rgxv-4464-wf8w.json | 4 +- .../GHSA-wj74-fcp9-vrxp.json | 3 +- .../GHSA-wq76-hwvv-4gwx.json | 3 +- .../GHSA-3f9h-26qj-9vvx.json | 11 +++-- .../GHSA-54qp-w9cp-g8g3.json | 14 +++++- .../GHSA-7wfq-7p2f-6344.json | 6 ++- .../GHSA-9589-mpwg-8xq6.json | 14 +++++- .../GHSA-99xf-gcww-2c64.json | 14 +++++- .../GHSA-9qwg-ch53-9rxw.json | 14 +++++- .../GHSA-f4vp-qjpg-x8wq.json | 14 +++++- .../GHSA-fp4x-j6ch-w8q5.json | 14 +++++- .../GHSA-pr7v-prvv-52v8.json | 14 +++++- .../GHSA-pv37-78jj-hvqv.json | 14 +++++- .../GHSA-2pjg-x482-xwr4.json | 15 +++++-- .../GHSA-2xf7-h82x-mhhg.json | 15 +++++-- .../GHSA-34jg-44wj-8r3p.json | 29 ++++++++++++ .../GHSA-3864-88qj-q5jc.json | 15 +++++-- .../GHSA-49xp-c6gp-qwww.json | 44 +++++++++++++++++++ .../GHSA-698f-5447-3h5r.json | 15 +++++-- .../GHSA-6p4m-rffq-g464.json | 15 +++++-- .../GHSA-95mr-cf2h-w5jf.json | 29 ++++++++++++ .../GHSA-cpgg-gfx5-33r2.json | 44 +++++++++++++++++++ .../GHSA-h488-5g2w-vhxr.json | 36 +++++++++++++++ .../GHSA-jw23-2xqx-f9f7.json | 40 +++++++++++++++++ .../GHSA-mqr4-hr64-mrc9.json | 15 +++++-- .../GHSA-phr9-h376-r6rq.json | 15 +++++-- .../GHSA-prhf-69wc-jqmp.json | 15 +++++-- .../GHSA-qg2f-vrg7-hr49.json | 15 +++++-- .../GHSA-rfm8-87pc-cwp6.json | 44 +++++++++++++++++++ .../GHSA-vg32-cm75-rjr5.json | 44 +++++++++++++++++++ 93 files changed, 693 insertions(+), 125 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-49xp-c6gp-qwww/GHSA-49xp-c6gp-qwww.json create mode 100644 advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cpgg-gfx5-33r2/GHSA-cpgg-gfx5-33r2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h488-5g2w-vhxr/GHSA-h488-5g2w-vhxr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jw23-2xqx-f9f7/GHSA-jw23-2xqx-f9f7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rfm8-87pc-cwp6/GHSA-rfm8-87pc-cwp6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vg32-cm75-rjr5/GHSA-vg32-cm75-rjr5.json diff --git a/advisories/unreviewed/2022/05/GHSA-3j37-x46m-f23g/GHSA-3j37-x46m-f23g.json b/advisories/unreviewed/2022/05/GHSA-3j37-x46m-f23g/GHSA-3j37-x46m-f23g.json index 2f2d9d456e0..c31dbd03cfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j37-x46m-f23g/GHSA-3j37-x46m-f23g.json +++ b/advisories/unreviewed/2022/05/GHSA-3j37-x46m-f23g/GHSA-3j37-x46m-f23g.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4xm5-4w7j-j8qm/GHSA-4xm5-4w7j-j8qm.json b/advisories/unreviewed/2022/05/GHSA-4xm5-4w7j-j8qm/GHSA-4xm5-4w7j-j8qm.json index a9850c4f4ff..7390c476a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xm5-4w7j-j8qm/GHSA-4xm5-4w7j-j8qm.json +++ b/advisories/unreviewed/2022/05/GHSA-4xm5-4w7j-j8qm/GHSA-4xm5-4w7j-j8qm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xm5-4w7j-j8qm", - "modified": "2022-05-13T01:16:10Z", + "modified": "2025-05-06T21:30:36Z", "published": "2022-05-13T01:16:10Z", "aliases": [ "CVE-2018-6336" diff --git a/advisories/unreviewed/2022/05/GHSA-8m8q-r5vq-5fg3/GHSA-8m8q-r5vq-5fg3.json b/advisories/unreviewed/2022/05/GHSA-8m8q-r5vq-5fg3/GHSA-8m8q-r5vq-5fg3.json index ed7157d96ef..16043fcac2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m8q-r5vq-5fg3/GHSA-8m8q-r5vq-5fg3.json +++ b/advisories/unreviewed/2022/05/GHSA-8m8q-r5vq-5fg3/GHSA-8m8q-r5vq-5fg3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcwm-rp7p-mm3c/GHSA-mcwm-rp7p-mm3c.json b/advisories/unreviewed/2022/05/GHSA-mcwm-rp7p-mm3c/GHSA-mcwm-rp7p-mm3c.json index a6fa4be4bc9..bca3b40a54c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcwm-rp7p-mm3c/GHSA-mcwm-rp7p-mm3c.json +++ b/advisories/unreviewed/2022/05/GHSA-mcwm-rp7p-mm3c/GHSA-mcwm-rp7p-mm3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcwm-rp7p-mm3c", - "modified": "2022-05-13T01:50:44Z", + "modified": "2025-05-06T21:30:36Z", "published": "2022-05-13T01:50:44Z", "aliases": [ "CVE-2018-18600" diff --git a/advisories/unreviewed/2022/05/GHSA-rh5w-f4gw-ppw8/GHSA-rh5w-f4gw-ppw8.json b/advisories/unreviewed/2022/05/GHSA-rh5w-f4gw-ppw8/GHSA-rh5w-f4gw-ppw8.json index 4c8c1b12f06..37981c9727d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh5w-f4gw-ppw8/GHSA-rh5w-f4gw-ppw8.json +++ b/advisories/unreviewed/2022/05/GHSA-rh5w-f4gw-ppw8/GHSA-rh5w-f4gw-ppw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh5w-f4gw-ppw8", - "modified": "2022-05-14T01:33:06Z", + "modified": "2025-05-06T21:30:36Z", "published": "2022-05-14T01:33:06Z", "aliases": [ "CVE-2018-18601" diff --git a/advisories/unreviewed/2022/10/GHSA-f2x8-4jwf-gqrg/GHSA-f2x8-4jwf-gqrg.json b/advisories/unreviewed/2022/10/GHSA-f2x8-4jwf-gqrg/GHSA-f2x8-4jwf-gqrg.json index 7aba5b70177..f2a48d0b85d 100644 --- a/advisories/unreviewed/2022/10/GHSA-f2x8-4jwf-gqrg/GHSA-f2x8-4jwf-gqrg.json +++ b/advisories/unreviewed/2022/10/GHSA-f2x8-4jwf-gqrg/GHSA-f2x8-4jwf-gqrg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2x8-4jwf-gqrg", - "modified": "2022-11-01T19:00:31Z", + "modified": "2025-05-06T21:30:36Z", "published": "2022-10-31T12:00:19Z", "aliases": [ "CVE-2022-40617" @@ -19,10 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40617" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3GAYIOCSLU57C45CO4UE4IV4JZE4W3L" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J3GAYIOCSLU57C45CO4UE4IV4JZE4W3L" }, + { + "type": "WEB", + "url": "https://www.strongswan.org/blog/2022/10/03/strongswan-vulnerability-%28cve-2022-40617%29.html" + }, { "type": "WEB", "url": "https://www.strongswan.org/blog/2022/10/03/strongswan-vulnerability-(cve-2022-40617).html" diff --git a/advisories/unreviewed/2022/10/GHSA-w8cr-4wjm-8jwj/GHSA-w8cr-4wjm-8jwj.json b/advisories/unreviewed/2022/10/GHSA-w8cr-4wjm-8jwj/GHSA-w8cr-4wjm-8jwj.json index 205f8e77686..c1141226877 100644 --- a/advisories/unreviewed/2022/10/GHSA-w8cr-4wjm-8jwj/GHSA-w8cr-4wjm-8jwj.json +++ b/advisories/unreviewed/2022/10/GHSA-w8cr-4wjm-8jwj/GHSA-w8cr-4wjm-8jwj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-352" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-2h36-2cxh-4whm/GHSA-2h36-2cxh-4whm.json b/advisories/unreviewed/2022/11/GHSA-2h36-2cxh-4whm/GHSA-2h36-2cxh-4whm.json index f0619cf82a0..2ba7268959f 100644 --- a/advisories/unreviewed/2022/11/GHSA-2h36-2cxh-4whm/GHSA-2h36-2cxh-4whm.json +++ b/advisories/unreviewed/2022/11/GHSA-2h36-2cxh-4whm/GHSA-2h36-2cxh-4whm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-3697-9w4g-6gpf/GHSA-3697-9w4g-6gpf.json b/advisories/unreviewed/2022/11/GHSA-3697-9w4g-6gpf/GHSA-3697-9w4g-6gpf.json index ff8f920dd2e..0cf1e23ad09 100644 --- a/advisories/unreviewed/2022/11/GHSA-3697-9w4g-6gpf/GHSA-3697-9w4g-6gpf.json +++ b/advisories/unreviewed/2022/11/GHSA-3697-9w4g-6gpf/GHSA-3697-9w4g-6gpf.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-3rq8-jv8q-ghj7/GHSA-3rq8-jv8q-ghj7.json b/advisories/unreviewed/2022/11/GHSA-3rq8-jv8q-ghj7/GHSA-3rq8-jv8q-ghj7.json index a1041df9425..f39a266b139 100644 --- a/advisories/unreviewed/2022/11/GHSA-3rq8-jv8q-ghj7/GHSA-3rq8-jv8q-ghj7.json +++ b/advisories/unreviewed/2022/11/GHSA-3rq8-jv8q-ghj7/GHSA-3rq8-jv8q-ghj7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-3v2r-gf9x-wpgw/GHSA-3v2r-gf9x-wpgw.json b/advisories/unreviewed/2022/11/GHSA-3v2r-gf9x-wpgw/GHSA-3v2r-gf9x-wpgw.json index bfb766c1fcd..e34d78823f2 100644 --- a/advisories/unreviewed/2022/11/GHSA-3v2r-gf9x-wpgw/GHSA-3v2r-gf9x-wpgw.json +++ b/advisories/unreviewed/2022/11/GHSA-3v2r-gf9x-wpgw/GHSA-3v2r-gf9x-wpgw.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4f2x-g7q8-5cjp/GHSA-4f2x-g7q8-5cjp.json b/advisories/unreviewed/2022/11/GHSA-4f2x-g7q8-5cjp/GHSA-4f2x-g7q8-5cjp.json index 4532cf8318d..90c404e2e41 100644 --- a/advisories/unreviewed/2022/11/GHSA-4f2x-g7q8-5cjp/GHSA-4f2x-g7q8-5cjp.json +++ b/advisories/unreviewed/2022/11/GHSA-4f2x-g7q8-5cjp/GHSA-4f2x-g7q8-5cjp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4f45-x86c-28mm/GHSA-4f45-x86c-28mm.json b/advisories/unreviewed/2022/11/GHSA-4f45-x86c-28mm/GHSA-4f45-x86c-28mm.json index 49951349489..4fa024a6a3b 100644 --- a/advisories/unreviewed/2022/11/GHSA-4f45-x86c-28mm/GHSA-4f45-x86c-28mm.json +++ b/advisories/unreviewed/2022/11/GHSA-4f45-x86c-28mm/GHSA-4f45-x86c-28mm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-6gcw-xxjf-q6rm/GHSA-6gcw-xxjf-q6rm.json b/advisories/unreviewed/2022/11/GHSA-6gcw-xxjf-q6rm/GHSA-6gcw-xxjf-q6rm.json index 22427f90f79..f26b1714802 100644 --- a/advisories/unreviewed/2022/11/GHSA-6gcw-xxjf-q6rm/GHSA-6gcw-xxjf-q6rm.json +++ b/advisories/unreviewed/2022/11/GHSA-6gcw-xxjf-q6rm/GHSA-6gcw-xxjf-q6rm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-84ww-4wqp-3333/GHSA-84ww-4wqp-3333.json b/advisories/unreviewed/2022/11/GHSA-84ww-4wqp-3333/GHSA-84ww-4wqp-3333.json index a790e00f457..54d93b653cb 100644 --- a/advisories/unreviewed/2022/11/GHSA-84ww-4wqp-3333/GHSA-84ww-4wqp-3333.json +++ b/advisories/unreviewed/2022/11/GHSA-84ww-4wqp-3333/GHSA-84ww-4wqp-3333.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-524" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-8p4p-376x-fv7v/GHSA-8p4p-376x-fv7v.json b/advisories/unreviewed/2022/11/GHSA-8p4p-376x-fv7v/GHSA-8p4p-376x-fv7v.json index eca6f5d7558..65bf33045ae 100644 --- a/advisories/unreviewed/2022/11/GHSA-8p4p-376x-fv7v/GHSA-8p4p-376x-fv7v.json +++ b/advisories/unreviewed/2022/11/GHSA-8p4p-376x-fv7v/GHSA-8p4p-376x-fv7v.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-ccfm-q6rr-cwmr/GHSA-ccfm-q6rr-cwmr.json b/advisories/unreviewed/2022/11/GHSA-ccfm-q6rr-cwmr/GHSA-ccfm-q6rr-cwmr.json index fb733a52e17..8b5bee4b0ae 100644 --- a/advisories/unreviewed/2022/11/GHSA-ccfm-q6rr-cwmr/GHSA-ccfm-q6rr-cwmr.json +++ b/advisories/unreviewed/2022/11/GHSA-ccfm-q6rr-cwmr/GHSA-ccfm-q6rr-cwmr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-642" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-fgf8-vx7f-99w6/GHSA-fgf8-vx7f-99w6.json b/advisories/unreviewed/2022/11/GHSA-fgf8-vx7f-99w6/GHSA-fgf8-vx7f-99w6.json index 840f6c45554..68887bf7baa 100644 --- a/advisories/unreviewed/2022/11/GHSA-fgf8-vx7f-99w6/GHSA-fgf8-vx7f-99w6.json +++ b/advisories/unreviewed/2022/11/GHSA-fgf8-vx7f-99w6/GHSA-fgf8-vx7f-99w6.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-fj87-wrmx-mhhj/GHSA-fj87-wrmx-mhhj.json b/advisories/unreviewed/2022/11/GHSA-fj87-wrmx-mhhj/GHSA-fj87-wrmx-mhhj.json index dcc3231bfec..6fa90a0d00b 100644 --- a/advisories/unreviewed/2022/11/GHSA-fj87-wrmx-mhhj/GHSA-fj87-wrmx-mhhj.json +++ b/advisories/unreviewed/2022/11/GHSA-fj87-wrmx-mhhj/GHSA-fj87-wrmx-mhhj.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-fmvh-rqw4-xjgg/GHSA-fmvh-rqw4-xjgg.json b/advisories/unreviewed/2022/11/GHSA-fmvh-rqw4-xjgg/GHSA-fmvh-rqw4-xjgg.json index 46b3239341b..76da1de871e 100644 --- a/advisories/unreviewed/2022/11/GHSA-fmvh-rqw4-xjgg/GHSA-fmvh-rqw4-xjgg.json +++ b/advisories/unreviewed/2022/11/GHSA-fmvh-rqw4-xjgg/GHSA-fmvh-rqw4-xjgg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-g7q8-m2m9-6rxm/GHSA-g7q8-m2m9-6rxm.json b/advisories/unreviewed/2022/11/GHSA-g7q8-m2m9-6rxm/GHSA-g7q8-m2m9-6rxm.json index dc2fb58eb97..8da49f28bdf 100644 --- a/advisories/unreviewed/2022/11/GHSA-g7q8-m2m9-6rxm/GHSA-g7q8-m2m9-6rxm.json +++ b/advisories/unreviewed/2022/11/GHSA-g7q8-m2m9-6rxm/GHSA-g7q8-m2m9-6rxm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-h37x-544m-w8g9/GHSA-h37x-544m-w8g9.json b/advisories/unreviewed/2022/11/GHSA-h37x-544m-w8g9/GHSA-h37x-544m-w8g9.json index fe16a6c144f..ae6b3e066b6 100644 --- a/advisories/unreviewed/2022/11/GHSA-h37x-544m-w8g9/GHSA-h37x-544m-w8g9.json +++ b/advisories/unreviewed/2022/11/GHSA-h37x-544m-w8g9/GHSA-h37x-544m-w8g9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-j9r9-pw35-cqq2/GHSA-j9r9-pw35-cqq2.json b/advisories/unreviewed/2022/11/GHSA-j9r9-pw35-cqq2/GHSA-j9r9-pw35-cqq2.json index 46cac7acbaa..e9b2ec76366 100644 --- a/advisories/unreviewed/2022/11/GHSA-j9r9-pw35-cqq2/GHSA-j9r9-pw35-cqq2.json +++ b/advisories/unreviewed/2022/11/GHSA-j9r9-pw35-cqq2/GHSA-j9r9-pw35-cqq2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-jjr3-mpqc-7w9v/GHSA-jjr3-mpqc-7w9v.json b/advisories/unreviewed/2022/11/GHSA-jjr3-mpqc-7w9v/GHSA-jjr3-mpqc-7w9v.json index 93d0251c9b9..a61f5074c6f 100644 --- a/advisories/unreviewed/2022/11/GHSA-jjr3-mpqc-7w9v/GHSA-jjr3-mpqc-7w9v.json +++ b/advisories/unreviewed/2022/11/GHSA-jjr3-mpqc-7w9v/GHSA-jjr3-mpqc-7w9v.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-m455-p2ph-4m7m/GHSA-m455-p2ph-4m7m.json b/advisories/unreviewed/2022/11/GHSA-m455-p2ph-4m7m/GHSA-m455-p2ph-4m7m.json index c854a17ae94..e7a6d0790ad 100644 --- a/advisories/unreviewed/2022/11/GHSA-m455-p2ph-4m7m/GHSA-m455-p2ph-4m7m.json +++ b/advisories/unreviewed/2022/11/GHSA-m455-p2ph-4m7m/GHSA-m455-p2ph-4m7m.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-p8c5-57m9-rp9f/GHSA-p8c5-57m9-rp9f.json b/advisories/unreviewed/2022/11/GHSA-p8c5-57m9-rp9f/GHSA-p8c5-57m9-rp9f.json index 81714fa593c..67225c6e95c 100644 --- a/advisories/unreviewed/2022/11/GHSA-p8c5-57m9-rp9f/GHSA-p8c5-57m9-rp9f.json +++ b/advisories/unreviewed/2022/11/GHSA-p8c5-57m9-rp9f/GHSA-p8c5-57m9-rp9f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-qx6c-q8gv-5qrh/GHSA-qx6c-q8gv-5qrh.json b/advisories/unreviewed/2022/11/GHSA-qx6c-q8gv-5qrh/GHSA-qx6c-q8gv-5qrh.json index d406eabbe26..61a05f08601 100644 --- a/advisories/unreviewed/2022/11/GHSA-qx6c-q8gv-5qrh/GHSA-qx6c-q8gv-5qrh.json +++ b/advisories/unreviewed/2022/11/GHSA-qx6c-q8gv-5qrh/GHSA-qx6c-q8gv-5qrh.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-r3x3-pfq4-cvw2/GHSA-r3x3-pfq4-cvw2.json b/advisories/unreviewed/2022/11/GHSA-r3x3-pfq4-cvw2/GHSA-r3x3-pfq4-cvw2.json index 2c1f6256f2b..7a22e8feb33 100644 --- a/advisories/unreviewed/2022/11/GHSA-r3x3-pfq4-cvw2/GHSA-r3x3-pfq4-cvw2.json +++ b/advisories/unreviewed/2022/11/GHSA-r3x3-pfq4-cvw2/GHSA-r3x3-pfq4-cvw2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-v2vp-9rm4-g6h9/GHSA-v2vp-9rm4-g6h9.json b/advisories/unreviewed/2022/11/GHSA-v2vp-9rm4-g6h9/GHSA-v2vp-9rm4-g6h9.json index 934fea31130..4fbb326c9a7 100644 --- a/advisories/unreviewed/2022/11/GHSA-v2vp-9rm4-g6h9/GHSA-v2vp-9rm4-g6h9.json +++ b/advisories/unreviewed/2022/11/GHSA-v2vp-9rm4-g6h9/GHSA-v2vp-9rm4-g6h9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-v4qp-vm8g-fvqc/GHSA-v4qp-vm8g-fvqc.json b/advisories/unreviewed/2022/11/GHSA-v4qp-vm8g-fvqc/GHSA-v4qp-vm8g-fvqc.json index 6c96f622ed8..55733980995 100644 --- a/advisories/unreviewed/2022/11/GHSA-v4qp-vm8g-fvqc/GHSA-v4qp-vm8g-fvqc.json +++ b/advisories/unreviewed/2022/11/GHSA-v4qp-vm8g-fvqc/GHSA-v4qp-vm8g-fvqc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-vcqr-9c66-fvvh/GHSA-vcqr-9c66-fvvh.json b/advisories/unreviewed/2022/11/GHSA-vcqr-9c66-fvvh/GHSA-vcqr-9c66-fvvh.json index 9a55f6dc3cc..a98086d3ec5 100644 --- a/advisories/unreviewed/2022/11/GHSA-vcqr-9c66-fvvh/GHSA-vcqr-9c66-fvvh.json +++ b/advisories/unreviewed/2022/11/GHSA-vcqr-9c66-fvvh/GHSA-vcqr-9c66-fvvh.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-x64r-97x8-7c32/GHSA-x64r-97x8-7c32.json b/advisories/unreviewed/2022/11/GHSA-x64r-97x8-7c32/GHSA-x64r-97x8-7c32.json index efa2da85a31..fd058b9410b 100644 --- a/advisories/unreviewed/2022/11/GHSA-x64r-97x8-7c32/GHSA-x64r-97x8-7c32.json +++ b/advisories/unreviewed/2022/11/GHSA-x64r-97x8-7c32/GHSA-x64r-97x8-7c32.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-gx2w-592v-wg4m/GHSA-gx2w-592v-wg4m.json b/advisories/unreviewed/2023/12/GHSA-gx2w-592v-wg4m/GHSA-gx2w-592v-wg4m.json index da8af7fe9fe..fdcf3f4458b 100644 --- a/advisories/unreviewed/2023/12/GHSA-gx2w-592v-wg4m/GHSA-gx2w-592v-wg4m.json +++ b/advisories/unreviewed/2023/12/GHSA-gx2w-592v-wg4m/GHSA-gx2w-592v-wg4m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json b/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json index 13902e0181a..9174dbc5368 100644 --- a/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json +++ b/advisories/unreviewed/2023/12/GHSA-hvrj-r9f4-xr39/GHSA-hvrj-r9f4-xr39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hvrj-r9f4-xr39", - "modified": "2024-01-02T15:30:23Z", + "modified": "2025-05-06T21:30:40Z", "published": "2023-12-20T03:30:23Z", "aliases": [ "CVE-2023-27172" diff --git a/advisories/unreviewed/2024/02/GHSA-4r78-7mmp-3xjj/GHSA-4r78-7mmp-3xjj.json b/advisories/unreviewed/2024/02/GHSA-4r78-7mmp-3xjj/GHSA-4r78-7mmp-3xjj.json index 7deb4634ef4..f60c47cba53 100644 --- a/advisories/unreviewed/2024/02/GHSA-4r78-7mmp-3xjj/GHSA-4r78-7mmp-3xjj.json +++ b/advisories/unreviewed/2024/02/GHSA-4r78-7mmp-3xjj/GHSA-4r78-7mmp-3xjj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4r78-7mmp-3xjj", - "modified": "2024-02-12T21:30:54Z", + "modified": "2025-05-06T21:30:40Z", "published": "2024-02-12T21:30:54Z", "aliases": [ "CVE-2024-0166" ], - "details": "\nDell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.\n\n", + "details": "Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json index 875df6bf743..bbff71d258c 100644 --- a/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json +++ b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6wx8-g7xc-9qp2", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:41Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-22061" ], - "details": "A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands ", + "details": "A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json index 5d2efb3e669..ae4c96e2e4a 100644 --- a/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json +++ b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-76f8-6hfx-w3xj", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-23530" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json index 04656882a1e..5b2283cef25 100644 --- a/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json +++ b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7ghv-4mjc-99wp", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-23532" ], - "details": "An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution. ", + "details": "An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json index a384636e8de..9857316a468 100644 --- a/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json +++ b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-85c2-wjfm-h4fw", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:41Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-23529" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json index 080409300a4..3b003bc5ed7 100644 --- a/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json +++ b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8c8m-p9jj-3j4j", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:41Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-23528" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json index e4b3248bc2e..10732457730 100644 --- a/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json +++ b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9w6g-r3rj-g5xg", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:41Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-23526" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json index 15caaf68d16..c8a6d396f12 100644 --- a/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json +++ b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c3p2-8x6x-wvh2", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-24993" ], - "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json index 10271cbb204..b81dbc6b0ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json +++ b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rv7j-2mm5-9fv2", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-23534" ], - "details": "An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "details": "An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json index 1416783b0ac..a1ab4b06a57 100644 --- a/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json +++ b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v829-2px7-7w8w", - "modified": "2024-04-19T03:31:02Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:02Z", "aliases": [ "CVE-2024-23531" ], - "details": "An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory. ", + "details": "An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json index 768dfd77e31..42e57becf1a 100644 --- a/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json +++ b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ww6m-hg6p-rm96", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-23533" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json index 0c30c3d8c22..32951286ba2 100644 --- a/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json +++ b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x9r4-wx9q-2r6r", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-05-06T21:30:42Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-24995" ], - "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. ", + "details": "A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json index 0397411c338..2be9b6d4c1b 100644 --- a/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json +++ b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json index 8212db377ac..dc3bfe1bc13 100644 --- a/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json +++ b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json index 88a13bcbe3c..9d7578750e3 100644 --- a/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json +++ b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json index 1a673a18616..b039d985281 100644 --- a/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json +++ b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json index 10416a83383..daf78f67f4e 100644 --- a/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json +++ b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json index 15e6689a156..2d5b89b483e 100644 --- a/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json +++ b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json index 8f17ca73251..9e29b404cce 100644 --- a/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json +++ b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json index b0bc9538e2b..538abc3c1ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json +++ b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json index eb05e3f9056..a30db7bbd6f 100644 --- a/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json +++ b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json index 55aa24fd34e..ec158c48f57 100644 --- a/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json +++ b/advisories/unreviewed/2024/06/GHSA-x3jm-2wx8-ccv4/GHSA-x3jm-2wx8-ccv4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json index e51a53a32a0..82505cd5c35 100644 --- a/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json +++ b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json index eb90241b9df..d35e5506f9a 100644 --- a/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json +++ b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json b/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json index ba1252e2f26..3cb26404a09 100644 --- a/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json +++ b/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json index e42f45bdeaa..4494e2ac7d6 100644 --- a/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json +++ b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json index 3595a9788a5..2f0a1ab6897 100644 --- a/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json +++ b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-g2mr-q8jv-5635/GHSA-g2mr-q8jv-5635.json b/advisories/unreviewed/2025/03/GHSA-g2mr-q8jv-5635/GHSA-g2mr-q8jv-5635.json index bd6969ad110..f249c6d4125 100644 --- a/advisories/unreviewed/2025/03/GHSA-g2mr-q8jv-5635/GHSA-g2mr-q8jv-5635.json +++ b/advisories/unreviewed/2025/03/GHSA-g2mr-q8jv-5635/GHSA-g2mr-q8jv-5635.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json index 567a3b7634b..c316d4adcd2 100644 --- a/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json +++ b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json index a613e13fe80..e77d4274380 100644 --- a/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json +++ b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json b/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json index 8c90c6ae811..5d51f10e445 100644 --- a/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json +++ b/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json b/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json index f65d2c5bea8..2b693ca43be 100644 --- a/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json +++ b/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json b/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json index a6e07ce97c8..3ba0957d91a 100644 --- a/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json +++ b/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3f9h-26qj-9vvx", - "modified": "2025-04-21T09:32:10Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-21T09:32:10Z", "aliases": [ "CVE-2025-25228" ], "details": "A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-21T08:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json index cc62af902d4..18b97aaf5af 100644 --- a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json +++ b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54qp-w9cp-g8g3", - "modified": "2025-05-05T03:30:19Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32053" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32053" diff --git a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json index 2385673c3f5..3cebe4702a7 100644 --- a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json +++ b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wfq-7p2f-6344", - "modified": "2025-05-05T03:30:20Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32907" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32907" diff --git a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json index ad04e9f30fa..d0ca0d7c737 100644 --- a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json +++ b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9589-mpwg-8xq6", - "modified": "2025-05-06T15:30:55Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32913" @@ -27,10 +27,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4538" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32913" diff --git a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json index 3c165aa63a8..4679189b74f 100644 --- a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json +++ b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99xf-gcww-2c64", - "modified": "2025-05-05T03:30:20Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32050" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32050" diff --git a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json index 473c9c9bf56..3d9b4a5841c 100644 --- a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json +++ b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qwg-ch53-9rxw", - "modified": "2025-05-05T03:30:19Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32052" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32052" diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json index d4ae61444ca..69a378c70c3 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json +++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-qjpg-x8wq", - "modified": "2025-05-06T15:30:55Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32906" @@ -27,10 +27,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4538" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32906" diff --git a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json index 68e76ff0e6c..6ded7552cb9 100644 --- a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json +++ b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp4x-j6ch-w8q5", - "modified": "2025-05-06T15:30:56Z", + "modified": "2025-05-06T21:30:47Z", "published": "2025-04-15T18:31:45Z", "aliases": [ "CVE-2025-32911" @@ -27,10 +27,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4538" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32911" diff --git a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json index 06278c471eb..1b92764e42f 100644 --- a/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json +++ b/advisories/unreviewed/2025/04/GHSA-pr7v-prvv-52v8/GHSA-pr7v-prvv-52v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr7v-prvv-52v8", - "modified": "2025-05-06T15:30:56Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46421" @@ -27,10 +27,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4538" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46421" diff --git a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json index ac7b9e5a28f..d490cc436ed 100644 --- a/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json +++ b/advisories/unreviewed/2025/04/GHSA-pv37-78jj-hvqv/GHSA-pv37-78jj-hvqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv37-78jj-hvqv", - "modified": "2025-05-06T15:30:56Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-04-24T15:30:49Z", "aliases": [ "CVE-2025-46420" @@ -27,10 +27,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4440" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4508" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4538" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4568" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-46420" diff --git a/advisories/unreviewed/2025/05/GHSA-2pjg-x482-xwr4/GHSA-2pjg-x482-xwr4.json b/advisories/unreviewed/2025/05/GHSA-2pjg-x482-xwr4/GHSA-2pjg-x482-xwr4.json index 269510313ee..8aff5dfbff9 100644 --- a/advisories/unreviewed/2025/05/GHSA-2pjg-x482-xwr4/GHSA-2pjg-x482-xwr4.json +++ b/advisories/unreviewed/2025/05/GHSA-2pjg-x482-xwr4/GHSA-2pjg-x482-xwr4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2pjg-x482-xwr4", - "modified": "2025-05-06T18:30:38Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:38Z", "aliases": [ "CVE-2025-45492" ], "details": "Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T16:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json b/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json index 21babb7a3dd..85097f5f0f0 100644 --- a/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json +++ b/advisories/unreviewed/2025/05/GHSA-2xf7-h82x-mhhg/GHSA-2xf7-h82x-mhhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xf7-h82x-mhhg", - "modified": "2025-05-05T18:32:54Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-05T18:32:53Z", "aliases": [ "CVE-2025-4051" ], "details": "Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T18:15:44Z" diff --git a/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json b/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json new file mode 100644 index 00000000000..24a628b7a9a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-34jg-44wj-8r3p/GHSA-34jg-44wj-8r3p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34jg-44wj-8r3p", + "modified": "2025-05-06T21:30:49Z", + "published": "2025-05-06T21:30:49Z", + "aliases": [ + "CVE-2025-44073" + ], + "details": "SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44073" + }, + { + "type": "WEB", + "url": "https://github.com/202110420106/CVE/blob/master/seacms/seacms_comment_news_sql.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T21:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3864-88qj-q5jc/GHSA-3864-88qj-q5jc.json b/advisories/unreviewed/2025/05/GHSA-3864-88qj-q5jc/GHSA-3864-88qj-q5jc.json index 2e53183578f..2ea15989115 100644 --- a/advisories/unreviewed/2025/05/GHSA-3864-88qj-q5jc/GHSA-3864-88qj-q5jc.json +++ b/advisories/unreviewed/2025/05/GHSA-3864-88qj-q5jc/GHSA-3864-88qj-q5jc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3864-88qj-q5jc", - "modified": "2025-05-06T18:30:38Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:38Z", "aliases": [ "CVE-2025-45488" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-49xp-c6gp-qwww/GHSA-49xp-c6gp-qwww.json b/advisories/unreviewed/2025/05/GHSA-49xp-c6gp-qwww/GHSA-49xp-c6gp-qwww.json new file mode 100644 index 00000000000..5746700dee9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-49xp-c6gp-qwww/GHSA-49xp-c6gp-qwww.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49xp-c6gp-qwww", + "modified": "2025-05-06T21:30:49Z", + "published": "2025-05-06T21:30:49Z", + "aliases": [ + "CVE-2025-47419" + ], + "details": "Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.\n\nThe device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords.\n\n\nThis issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47419" + }, + { + "type": "WEB", + "url": "https://security.crestron.com" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T21:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-698f-5447-3h5r/GHSA-698f-5447-3h5r.json b/advisories/unreviewed/2025/05/GHSA-698f-5447-3h5r/GHSA-698f-5447-3h5r.json index e1d10567a3f..1bade5d255e 100644 --- a/advisories/unreviewed/2025/05/GHSA-698f-5447-3h5r/GHSA-698f-5447-3h5r.json +++ b/advisories/unreviewed/2025/05/GHSA-698f-5447-3h5r/GHSA-698f-5447-3h5r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-698f-5447-3h5r", - "modified": "2025-05-06T18:30:38Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:38Z", "aliases": [ "CVE-2025-45487" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6p4m-rffq-g464/GHSA-6p4m-rffq-g464.json b/advisories/unreviewed/2025/05/GHSA-6p4m-rffq-g464/GHSA-6p4m-rffq-g464.json index 014e8a6269c..2f762103275 100644 --- a/advisories/unreviewed/2025/05/GHSA-6p4m-rffq-g464/GHSA-6p4m-rffq-g464.json +++ b/advisories/unreviewed/2025/05/GHSA-6p4m-rffq-g464/GHSA-6p4m-rffq-g464.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p4m-rffq-g464", - "modified": "2025-05-06T18:30:38Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:38Z", "aliases": [ "CVE-2025-45489" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T16:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json b/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json new file mode 100644 index 00000000000..6b4b5ff6a2f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-95mr-cf2h-w5jf/GHSA-95mr-cf2h-w5jf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95mr-cf2h-w5jf", + "modified": "2025-05-06T21:30:48Z", + "published": "2025-05-06T21:30:48Z", + "aliases": [ + "CVE-2025-44899" + ], + "details": "There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44899" + }, + { + "type": "WEB", + "url": "https://github.com/faqiadegege/IoTVuln/blob/main/tenda_RX3_fromSetWifiGusetBasic_shareSpeed_overflow/detail.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T21:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cpgg-gfx5-33r2/GHSA-cpgg-gfx5-33r2.json b/advisories/unreviewed/2025/05/GHSA-cpgg-gfx5-33r2/GHSA-cpgg-gfx5-33r2.json new file mode 100644 index 00000000000..138c71a447e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cpgg-gfx5-33r2/GHSA-cpgg-gfx5-33r2.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpgg-gfx5-33r2", + "modified": "2025-05-06T21:30:49Z", + "published": "2025-05-06T21:30:49Z", + "aliases": [ + "CVE-2025-47418" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.\n\nThere is no visible indication when the system is recording and recording can be enabled remotely via a network API. \nThis issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47418" + }, + { + "type": "WEB", + "url": "https://security.crestron.com" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T21:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h488-5g2w-vhxr/GHSA-h488-5g2w-vhxr.json b/advisories/unreviewed/2025/05/GHSA-h488-5g2w-vhxr/GHSA-h488-5g2w-vhxr.json new file mode 100644 index 00000000000..9f20b821774 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h488-5g2w-vhxr/GHSA-h488-5g2w-vhxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h488-5g2w-vhxr", + "modified": "2025-05-06T21:30:49Z", + "published": "2025-05-06T21:30:49Z", + "aliases": [ + "CVE-2025-0649" + ], + "details": "Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0649" + }, + { + "type": "WEB", + "url": "https://github.com/tensorflow/serving/commit/6cb013167d13f2ed3930aabb86dbc2c8c53f5adf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T21:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jw23-2xqx-f9f7/GHSA-jw23-2xqx-f9f7.json b/advisories/unreviewed/2025/05/GHSA-jw23-2xqx-f9f7/GHSA-jw23-2xqx-f9f7.json new file mode 100644 index 00000000000..57305cecbb3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jw23-2xqx-f9f7/GHSA-jw23-2xqx-f9f7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw23-2xqx-f9f7", + "modified": "2025-05-06T21:30:48Z", + "published": "2025-05-06T21:30:48Z", + "aliases": [ + "CVE-2024-12225" + ], + "details": "A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12225" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-12225" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330484" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqr4-hr64-mrc9/GHSA-mqr4-hr64-mrc9.json b/advisories/unreviewed/2025/05/GHSA-mqr4-hr64-mrc9/GHSA-mqr4-hr64-mrc9.json index 524423af8d8..dffa47e1a78 100644 --- a/advisories/unreviewed/2025/05/GHSA-mqr4-hr64-mrc9/GHSA-mqr4-hr64-mrc9.json +++ b/advisories/unreviewed/2025/05/GHSA-mqr4-hr64-mrc9/GHSA-mqr4-hr64-mrc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mqr4-hr64-mrc9", - "modified": "2025-05-06T18:30:40Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:40Z", "aliases": [ "CVE-2025-44900" ], "details": "In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T18:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-phr9-h376-r6rq/GHSA-phr9-h376-r6rq.json b/advisories/unreviewed/2025/05/GHSA-phr9-h376-r6rq/GHSA-phr9-h376-r6rq.json index 5b81957ae12..833bd9fc53c 100644 --- a/advisories/unreviewed/2025/05/GHSA-phr9-h376-r6rq/GHSA-phr9-h376-r6rq.json +++ b/advisories/unreviewed/2025/05/GHSA-phr9-h376-r6rq/GHSA-phr9-h376-r6rq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phr9-h376-r6rq", - "modified": "2025-05-06T18:30:38Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:38Z", "aliases": [ "CVE-2025-45490" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T16:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-prhf-69wc-jqmp/GHSA-prhf-69wc-jqmp.json b/advisories/unreviewed/2025/05/GHSA-prhf-69wc-jqmp/GHSA-prhf-69wc-jqmp.json index 469ac087683..e6f54c2be39 100644 --- a/advisories/unreviewed/2025/05/GHSA-prhf-69wc-jqmp/GHSA-prhf-69wc-jqmp.json +++ b/advisories/unreviewed/2025/05/GHSA-prhf-69wc-jqmp/GHSA-prhf-69wc-jqmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prhf-69wc-jqmp", - "modified": "2025-05-06T18:30:39Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:39Z", "aliases": [ "CVE-2025-26262" ], "details": "An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T17:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qg2f-vrg7-hr49/GHSA-qg2f-vrg7-hr49.json b/advisories/unreviewed/2025/05/GHSA-qg2f-vrg7-hr49/GHSA-qg2f-vrg7-hr49.json index dabef3bd6fa..45de0d910e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-qg2f-vrg7-hr49/GHSA-qg2f-vrg7-hr49.json +++ b/advisories/unreviewed/2025/05/GHSA-qg2f-vrg7-hr49/GHSA-qg2f-vrg7-hr49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qg2f-vrg7-hr49", - "modified": "2025-05-06T18:30:39Z", + "modified": "2025-05-06T21:30:48Z", "published": "2025-05-06T18:30:39Z", "aliases": [ "CVE-2025-45250" ], "details": "MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-06T17:16:12Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rfm8-87pc-cwp6/GHSA-rfm8-87pc-cwp6.json b/advisories/unreviewed/2025/05/GHSA-rfm8-87pc-cwp6/GHSA-rfm8-87pc-cwp6.json new file mode 100644 index 00000000000..570c2bd6499 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rfm8-87pc-cwp6/GHSA-rfm8-87pc-cwp6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfm8-87pc-cwp6", + "modified": "2025-05-06T21:30:49Z", + "published": "2025-05-06T21:30:49Z", + "aliases": [ + "CVE-2025-47417" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse.\n\n\n\nWhen Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is being done.\n\n\nThis issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47417" + }, + { + "type": "WEB", + "url": "https://security.crestron.com" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/Software-Firmware/Software/Automate-VX-Software/6-4-1-8" + }, + { + "type": "WEB", + "url": "https://www.crestron.com/release_notes/automate_vx_6.4.1.8_release_notes.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vg32-cm75-rjr5/GHSA-vg32-cm75-rjr5.json b/advisories/unreviewed/2025/05/GHSA-vg32-cm75-rjr5/GHSA-vg32-cm75-rjr5.json new file mode 100644 index 00000000000..f6e4a0510a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vg32-cm75-rjr5/GHSA-vg32-cm75-rjr5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg32-cm75-rjr5", + "modified": "2025-05-06T21:30:48Z", + "published": "2025-05-06T21:30:48Z", + "aliases": [ + "CVE-2025-47256" + ], + "details": "Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47256" + }, + { + "type": "WEB", + "url": "https://github.com/libxmp/libxmp/issues/847" + }, + { + "type": "WEB", + "url": "https://github.com/GCatt-AS/CVE-2025-47256" + }, + { + "type": "WEB", + "url": "https://github.com/libxmp/libxmp/blob/ec22d1c7b93c8f681f8504a6c61c6f8a52458a10/src/loaders/prowizard/pha.c#L35" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T20:15:27Z" + } +} \ No newline at end of file