diff --git a/advisories/unreviewed/2023/04/GHSA-3cvf-fpq3-c29m/GHSA-3cvf-fpq3-c29m.json b/advisories/unreviewed/2023/04/GHSA-3cvf-fpq3-c29m/GHSA-3cvf-fpq3-c29m.json index 2ed5a6aadb3..f619ab551c7 100644 --- a/advisories/unreviewed/2023/04/GHSA-3cvf-fpq3-c29m/GHSA-3cvf-fpq3-c29m.json +++ b/advisories/unreviewed/2023/04/GHSA-3cvf-fpq3-c29m/GHSA-3cvf-fpq3-c29m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3cvf-fpq3-c29m", - "modified": "2023-04-14T06:30:16Z", + "modified": "2025-02-11T18:31:11Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-25415" diff --git a/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json b/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json index 18b7298069e..a6e6620bb92 100644 --- a/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json +++ b/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-5c7q-4xhv-cmw9/GHSA-5c7q-4xhv-cmw9.json b/advisories/unreviewed/2023/04/GHSA-5c7q-4xhv-cmw9/GHSA-5c7q-4xhv-cmw9.json index b1376dd3473..d5d8b26fc82 100644 --- a/advisories/unreviewed/2023/04/GHSA-5c7q-4xhv-cmw9/GHSA-5c7q-4xhv-cmw9.json +++ b/advisories/unreviewed/2023/04/GHSA-5c7q-4xhv-cmw9/GHSA-5c7q-4xhv-cmw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c7q-4xhv-cmw9", - "modified": "2023-04-14T06:30:15Z", + "modified": "2025-02-11T18:31:11Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-25413" diff --git a/advisories/unreviewed/2023/04/GHSA-65vp-436r-q4g3/GHSA-65vp-436r-q4g3.json b/advisories/unreviewed/2023/04/GHSA-65vp-436r-q4g3/GHSA-65vp-436r-q4g3.json index 11e106a3f59..d603efdd6a0 100644 --- a/advisories/unreviewed/2023/04/GHSA-65vp-436r-q4g3/GHSA-65vp-436r-q4g3.json +++ b/advisories/unreviewed/2023/04/GHSA-65vp-436r-q4g3/GHSA-65vp-436r-q4g3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-384" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-788m-mc5j-98p8/GHSA-788m-mc5j-98p8.json b/advisories/unreviewed/2023/04/GHSA-788m-mc5j-98p8/GHSA-788m-mc5j-98p8.json index 8301cc6eccd..faa77825107 100644 --- a/advisories/unreviewed/2023/04/GHSA-788m-mc5j-98p8/GHSA-788m-mc5j-98p8.json +++ b/advisories/unreviewed/2023/04/GHSA-788m-mc5j-98p8/GHSA-788m-mc5j-98p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-788m-mc5j-98p8", - "modified": "2023-04-07T21:30:16Z", + "modified": "2025-02-11T18:30:59Z", "published": "2023-04-02T00:30:18Z", "aliases": [ "CVE-2023-26822" diff --git a/advisories/unreviewed/2023/04/GHSA-82cc-5xg5-62m7/GHSA-82cc-5xg5-62m7.json b/advisories/unreviewed/2023/04/GHSA-82cc-5xg5-62m7/GHSA-82cc-5xg5-62m7.json index 4c828eee35a..f2e84f05413 100644 --- a/advisories/unreviewed/2023/04/GHSA-82cc-5xg5-62m7/GHSA-82cc-5xg5-62m7.json +++ b/advisories/unreviewed/2023/04/GHSA-82cc-5xg5-62m7/GHSA-82cc-5xg5-62m7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82cc-5xg5-62m7", - "modified": "2023-04-14T06:30:16Z", + "modified": "2025-02-11T18:31:11Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-25411" diff --git a/advisories/unreviewed/2023/04/GHSA-96cq-cj7w-27g2/GHSA-96cq-cj7w-27g2.json b/advisories/unreviewed/2023/04/GHSA-96cq-cj7w-27g2/GHSA-96cq-cj7w-27g2.json index a9e8d8a4fc9..c4f190fca74 100644 --- a/advisories/unreviewed/2023/04/GHSA-96cq-cj7w-27g2/GHSA-96cq-cj7w-27g2.json +++ b/advisories/unreviewed/2023/04/GHSA-96cq-cj7w-27g2/GHSA-96cq-cj7w-27g2.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/04/GHSA-f6r3-7fw8-rpcg/GHSA-f6r3-7fw8-rpcg.json b/advisories/unreviewed/2023/04/GHSA-f6r3-7fw8-rpcg/GHSA-f6r3-7fw8-rpcg.json index 215fc490896..00d0d507f0e 100644 --- a/advisories/unreviewed/2023/04/GHSA-f6r3-7fw8-rpcg/GHSA-f6r3-7fw8-rpcg.json +++ b/advisories/unreviewed/2023/04/GHSA-f6r3-7fw8-rpcg/GHSA-f6r3-7fw8-rpcg.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/04/GHSA-gcwf-2p33-g9mp/GHSA-gcwf-2p33-g9mp.json b/advisories/unreviewed/2023/04/GHSA-gcwf-2p33-g9mp/GHSA-gcwf-2p33-g9mp.json index e611b40c59d..746c112442e 100644 --- a/advisories/unreviewed/2023/04/GHSA-gcwf-2p33-g9mp/GHSA-gcwf-2p33-g9mp.json +++ b/advisories/unreviewed/2023/04/GHSA-gcwf-2p33-g9mp/GHSA-gcwf-2p33-g9mp.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json index 275888b38f0..287fffcb150 100644 --- a/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json +++ b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-r57w-p77g-3j43/GHSA-r57w-p77g-3j43.json b/advisories/unreviewed/2023/04/GHSA-r57w-p77g-3j43/GHSA-r57w-p77g-3j43.json index a8362b5bb55..2837c87471f 100644 --- a/advisories/unreviewed/2023/04/GHSA-r57w-p77g-3j43/GHSA-r57w-p77g-3j43.json +++ b/advisories/unreviewed/2023/04/GHSA-r57w-p77g-3j43/GHSA-r57w-p77g-3j43.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r57w-p77g-3j43", - "modified": "2023-04-14T21:30:25Z", + "modified": "2025-02-11T18:31:00Z", "published": "2023-04-10T15:30:25Z", "aliases": [ "CVE-2023-1381" diff --git a/advisories/unreviewed/2023/04/GHSA-r7xv-7w95-w6c7/GHSA-r7xv-7w95-w6c7.json b/advisories/unreviewed/2023/04/GHSA-r7xv-7w95-w6c7/GHSA-r7xv-7w95-w6c7.json index 3eec52c342e..98d4af8e196 100644 --- a/advisories/unreviewed/2023/04/GHSA-r7xv-7w95-w6c7/GHSA-r7xv-7w95-w6c7.json +++ b/advisories/unreviewed/2023/04/GHSA-r7xv-7w95-w6c7/GHSA-r7xv-7w95-w6c7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-xfx8-2v9j-75g4/GHSA-xfx8-2v9j-75g4.json b/advisories/unreviewed/2023/04/GHSA-xfx8-2v9j-75g4/GHSA-xfx8-2v9j-75g4.json index e91864eeeb8..48fe8776f03 100644 --- a/advisories/unreviewed/2023/04/GHSA-xfx8-2v9j-75g4/GHSA-xfx8-2v9j-75g4.json +++ b/advisories/unreviewed/2023/04/GHSA-xfx8-2v9j-75g4/GHSA-xfx8-2v9j-75g4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfx8-2v9j-75g4", - "modified": "2023-04-14T06:30:15Z", + "modified": "2025-02-11T18:31:11Z", "published": "2023-04-11T21:31:02Z", "aliases": [ "CVE-2023-25407" diff --git a/advisories/unreviewed/2023/04/GHSA-xx9q-x7hp-rwhj/GHSA-xx9q-x7hp-rwhj.json b/advisories/unreviewed/2023/04/GHSA-xx9q-x7hp-rwhj/GHSA-xx9q-x7hp-rwhj.json index 9af5561b399..4af9f5f0c03 100644 --- a/advisories/unreviewed/2023/04/GHSA-xx9q-x7hp-rwhj/GHSA-xx9q-x7hp-rwhj.json +++ b/advisories/unreviewed/2023/04/GHSA-xx9q-x7hp-rwhj/GHSA-xx9q-x7hp-rwhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xx9q-x7hp-rwhj", - "modified": "2023-04-17T18:30:29Z", + "modified": "2025-02-11T18:31:09Z", "published": "2023-04-11T12:30:24Z", "aliases": [ "CVE-2023-27179" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://knowledge-base.secureflag.com/vulnerabilities/unrestricted_file_download/unrestricted_file_download_vulnerability.html" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/171894" + }, { "type": "WEB", "url": "https://www.gdidees.eu/cms-1-0.html" diff --git a/advisories/unreviewed/2023/04/GHSA-xxpv-gwrv-58xv/GHSA-xxpv-gwrv-58xv.json b/advisories/unreviewed/2023/04/GHSA-xxpv-gwrv-58xv/GHSA-xxpv-gwrv-58xv.json index 878675b52af..19a5fdb1c60 100644 --- a/advisories/unreviewed/2023/04/GHSA-xxpv-gwrv-58xv/GHSA-xxpv-gwrv-58xv.json +++ b/advisories/unreviewed/2023/04/GHSA-xxpv-gwrv-58xv/GHSA-xxpv-gwrv-58xv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxpv-gwrv-58xv", - "modified": "2023-04-14T06:30:15Z", + "modified": "2025-02-11T18:31:11Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-25414" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-m24w-wg7m-x27h/GHSA-m24w-wg7m-x27h.json b/advisories/unreviewed/2024/02/GHSA-m24w-wg7m-x27h/GHSA-m24w-wg7m-x27h.json index 60758c8e851..36bea55d935 100644 --- a/advisories/unreviewed/2024/02/GHSA-m24w-wg7m-x27h/GHSA-m24w-wg7m-x27h.json +++ b/advisories/unreviewed/2024/02/GHSA-m24w-wg7m-x27h/GHSA-m24w-wg7m-x27h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m24w-wg7m-x27h", - "modified": "2024-02-27T18:31:01Z", + "modified": "2025-02-11T18:31:11Z", "published": "2024-02-27T18:31:01Z", "aliases": [ "CVE-2024-1403" ], - "details": "In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The\nvulnerability is a bypass to authentication based on a failure to properly\nhandle username and password. Certain unexpected\ncontent passed into the credentials can lead to unauthorized access without proper\nauthentication.   \n\n\n\n\n\n\n", + "details": "In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The\nvulnerability is a bypass to authentication based on a failure to properly\nhandle username and password. Certain unexpected\ncontent passed into the credentials can lead to unauthorized access without proper\nauthentication.  ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json index 1d549f5f382..242dfacfea0 100644 --- a/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json +++ b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-35gq-67f6-phh5", - "modified": "2024-03-29T15:30:33Z", + "modified": "2025-02-11T18:31:13Z", "published": "2024-03-29T15:30:33Z", "aliases": [ "CVE-2024-30508" ], - "details": "Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.\n\n", + "details": "Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json b/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json index b5739f37075..572a8ebdd50 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json +++ b/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6cxc-vjp6-ff53", - "modified": "2024-03-27T12:30:41Z", + "modified": "2025-02-11T18:31:12Z", "published": "2024-03-27T12:30:41Z", "aliases": [ "CVE-2024-29931" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Go Maps (formerly WP Google Maps) WP Google Maps allows Reflected XSS.This issue affects WP Google Maps: from n/a through 9.0.29.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Go Maps (formerly WP Google Maps) WP Google Maps allows Reflected XSS.This issue affects WP Google Maps: from n/a through 9.0.29.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json b/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json index a623e009aab..b62a507d3d3 100644 --- a/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json +++ b/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9qhm-743f-cwmp", - "modified": "2024-03-29T15:30:33Z", + "modified": "2025-02-11T18:31:12Z", "published": "2024-03-29T15:30:33Z", "aliases": [ "CVE-2024-30502" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-h7x2-5334-q66p/GHSA-h7x2-5334-q66p.json b/advisories/unreviewed/2024/03/GHSA-h7x2-5334-q66p/GHSA-h7x2-5334-q66p.json index 2bad5360603..1f092658834 100644 --- a/advisories/unreviewed/2024/03/GHSA-h7x2-5334-q66p/GHSA-h7x2-5334-q66p.json +++ b/advisories/unreviewed/2024/03/GHSA-h7x2-5334-q66p/GHSA-h7x2-5334-q66p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-p34j-5cjx-gvfc/GHSA-p34j-5cjx-gvfc.json b/advisories/unreviewed/2024/03/GHSA-p34j-5cjx-gvfc/GHSA-p34j-5cjx-gvfc.json index 31534871763..2a3cdc0db9b 100644 --- a/advisories/unreviewed/2024/03/GHSA-p34j-5cjx-gvfc/GHSA-p34j-5cjx-gvfc.json +++ b/advisories/unreviewed/2024/03/GHSA-p34j-5cjx-gvfc/GHSA-p34j-5cjx-gvfc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q953-jqf9-xxc3/GHSA-q953-jqf9-xxc3.json b/advisories/unreviewed/2024/03/GHSA-q953-jqf9-xxc3/GHSA-q953-jqf9-xxc3.json index 1f9fe87a9fa..899afa67160 100644 --- a/advisories/unreviewed/2024/03/GHSA-q953-jqf9-xxc3/GHSA-q953-jqf9-xxc3.json +++ b/advisories/unreviewed/2024/03/GHSA-q953-jqf9-xxc3/GHSA-q953-jqf9-xxc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q953-jqf9-xxc3", - "modified": "2024-03-22T15:31:06Z", + "modified": "2025-02-11T18:31:12Z", "published": "2024-03-22T15:31:06Z", "aliases": [ "CVE-2024-2448" diff --git a/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json index 9d6352ee356..5965e7e59cd 100644 --- a/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json +++ b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vrgq-j293-jcx7", - "modified": "2024-03-29T15:30:33Z", + "modified": "2025-02-11T18:31:12Z", "published": "2024-03-29T15:30:33Z", "aliases": [ "CVE-2024-30504" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json index 2222af67b0b..15179c39ceb 100644 --- a/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json +++ b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-34r8-fv4m-hxcv/GHSA-34r8-fv4m-hxcv.json b/advisories/unreviewed/2024/05/GHSA-34r8-fv4m-hxcv/GHSA-34r8-fv4m-hxcv.json index e052d42a0ea..129f1149f8f 100644 --- a/advisories/unreviewed/2024/05/GHSA-34r8-fv4m-hxcv/GHSA-34r8-fv4m-hxcv.json +++ b/advisories/unreviewed/2024/05/GHSA-34r8-fv4m-hxcv/GHSA-34r8-fv4m-hxcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34r8-fv4m-hxcv", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:16Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4804" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7858-7mgv-mwpj/GHSA-7858-7mgv-mwpj.json b/advisories/unreviewed/2024/05/GHSA-7858-7mgv-mwpj/GHSA-7858-7mgv-mwpj.json index 32aa6c1c195..0de58b26806 100644 --- a/advisories/unreviewed/2024/05/GHSA-7858-7mgv-mwpj/GHSA-7858-7mgv-mwpj.json +++ b/advisories/unreviewed/2024/05/GHSA-7858-7mgv-mwpj/GHSA-7858-7mgv-mwpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7858-7mgv-mwpj", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:16Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4806" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7gfq-cm98-r33p/GHSA-7gfq-cm98-r33p.json b/advisories/unreviewed/2024/05/GHSA-7gfq-cm98-r33p/GHSA-7gfq-cm98-r33p.json index c1e0004d6d8..141ab5aa68f 100644 --- a/advisories/unreviewed/2024/05/GHSA-7gfq-cm98-r33p/GHSA-7gfq-cm98-r33p.json +++ b/advisories/unreviewed/2024/05/GHSA-7gfq-cm98-r33p/GHSA-7gfq-cm98-r33p.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-86cm-6r27-h7c6/GHSA-86cm-6r27-h7c6.json b/advisories/unreviewed/2024/05/GHSA-86cm-6r27-h7c6/GHSA-86cm-6r27-h7c6.json index e6d16f42458..a66bf3288f1 100644 --- a/advisories/unreviewed/2024/05/GHSA-86cm-6r27-h7c6/GHSA-86cm-6r27-h7c6.json +++ b/advisories/unreviewed/2024/05/GHSA-86cm-6r27-h7c6/GHSA-86cm-6r27-h7c6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86cm-6r27-h7c6", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4801" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-972q-cq35-55qp/GHSA-972q-cq35-55qp.json b/advisories/unreviewed/2024/05/GHSA-972q-cq35-55qp/GHSA-972q-cq35-55qp.json index ea4a181deee..c0d6a380433 100644 --- a/advisories/unreviewed/2024/05/GHSA-972q-cq35-55qp/GHSA-972q-cq35-55qp.json +++ b/advisories/unreviewed/2024/05/GHSA-972q-cq35-55qp/GHSA-972q-cq35-55qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-972q-cq35-55qp", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4802" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-f3wf-gw24-9r2q/GHSA-f3wf-gw24-9r2q.json b/advisories/unreviewed/2024/05/GHSA-f3wf-gw24-9r2q/GHSA-f3wf-gw24-9r2q.json index 334a5e20261..30a8e79e898 100644 --- a/advisories/unreviewed/2024/05/GHSA-f3wf-gw24-9r2q/GHSA-f3wf-gw24-9r2q.json +++ b/advisories/unreviewed/2024/05/GHSA-f3wf-gw24-9r2q/GHSA-f3wf-gw24-9r2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3wf-gw24-9r2q", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4800" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-g8jf-2c26-3mph/GHSA-g8jf-2c26-3mph.json b/advisories/unreviewed/2024/05/GHSA-g8jf-2c26-3mph/GHSA-g8jf-2c26-3mph.json index a5283ce84c4..a80a80f6cf3 100644 --- a/advisories/unreviewed/2024/05/GHSA-g8jf-2c26-3mph/GHSA-g8jf-2c26-3mph.json +++ b/advisories/unreviewed/2024/05/GHSA-g8jf-2c26-3mph/GHSA-g8jf-2c26-3mph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8jf-2c26-3mph", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:16Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4805" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-j87v-mhh9-96qj/GHSA-j87v-mhh9-96qj.json b/advisories/unreviewed/2024/05/GHSA-j87v-mhh9-96qj/GHSA-j87v-mhh9-96qj.json index 0d9966a523f..7b5d9307125 100644 --- a/advisories/unreviewed/2024/05/GHSA-j87v-mhh9-96qj/GHSA-j87v-mhh9-96qj.json +++ b/advisories/unreviewed/2024/05/GHSA-j87v-mhh9-96qj/GHSA-j87v-mhh9-96qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j87v-mhh9-96qj", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T18:31:16Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4803" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-xgmh-f6r2-39xq/GHSA-xgmh-f6r2-39xq.json b/advisories/unreviewed/2024/05/GHSA-xgmh-f6r2-39xq/GHSA-xgmh-f6r2-39xq.json index bc4271e0698..b0dd72f9924 100644 --- a/advisories/unreviewed/2024/05/GHSA-xgmh-f6r2-39xq/GHSA-xgmh-f6r2-39xq.json +++ b/advisories/unreviewed/2024/05/GHSA-xgmh-f6r2-39xq/GHSA-xgmh-f6r2-39xq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-r7j2-qxcx-r6qq/GHSA-r7j2-qxcx-r6qq.json b/advisories/unreviewed/2024/06/GHSA-r7j2-qxcx-r6qq/GHSA-r7j2-qxcx-r6qq.json index 52aeebf5896..026889fcfdc 100644 --- a/advisories/unreviewed/2024/06/GHSA-r7j2-qxcx-r6qq/GHSA-r7j2-qxcx-r6qq.json +++ b/advisories/unreviewed/2024/06/GHSA-r7j2-qxcx-r6qq/GHSA-r7j2-qxcx-r6qq.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json b/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json index 39fa84575db..c9ab206d9ff 100644 --- a/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json +++ b/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-86vm-fj76-qh69/GHSA-86vm-fj76-qh69.json b/advisories/unreviewed/2024/10/GHSA-86vm-fj76-qh69/GHSA-86vm-fj76-qh69.json index c19e93aee60..eca504aa30c 100644 --- a/advisories/unreviewed/2024/10/GHSA-86vm-fj76-qh69/GHSA-86vm-fj76-qh69.json +++ b/advisories/unreviewed/2024/10/GHSA-86vm-fj76-qh69/GHSA-86vm-fj76-qh69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86vm-fj76-qh69", - "modified": "2024-10-09T15:32:18Z", + "modified": "2025-02-11T18:31:19Z", "published": "2024-10-09T15:32:18Z", "aliases": [ "CVE-2024-45720" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://subversion.apache.org/security/CVE-2024-45720-advisory.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/10/08/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json b/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json index f85fe224b17..828269e2eae 100644 --- a/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json +++ b/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffrw-8p66-394j", - "modified": "2024-11-19T18:30:58Z", + "modified": "2025-02-11T18:31:20Z", "published": "2024-11-18T09:31:14Z", "aliases": [ "CVE-2024-48962" @@ -38,11 +38,16 @@ { "type": "WEB", "url": "https://ofbiz.apache.org/security.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/16/2" } ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-2xg4-wc7m-f6pq/GHSA-2xg4-wc7m-f6pq.json b/advisories/unreviewed/2024/12/GHSA-2xg4-wc7m-f6pq/GHSA-2xg4-wc7m-f6pq.json index 08fec292874..a3146908a99 100644 --- a/advisories/unreviewed/2024/12/GHSA-2xg4-wc7m-f6pq/GHSA-2xg4-wc7m-f6pq.json +++ b/advisories/unreviewed/2024/12/GHSA-2xg4-wc7m-f6pq/GHSA-2xg4-wc7m-f6pq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xg4-wc7m-f6pq", - "modified": "2024-12-27T15:31:50Z", + "modified": "2025-02-11T18:31:22Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53174" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: make sure cache entry active before cache_show\n\nThe function `c_show` was called with protection from RCU. This only\nensures that `cp` will not be freed. Therefore, the reference count for\n`cp` can drop to zero, which will trigger a refcount use-after-free\nwarning when `cache_get` is called. To resolve this issue, use\n`cache_get_rcu` to ensure that `cp` remains active.\n\n------------[ cut here ]------------\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 7 PID: 822 at lib/refcount.c:25\nrefcount_warn_saturate+0xb1/0x120\nCPU: 7 UID: 0 PID: 822 Comm: cat Not tainted 6.12.0-rc3+ #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xb1/0x120\n\nCall Trace:\n \n c_show+0x2fc/0x380 [sunrpc]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n proc_reg_read+0xe1/0x140\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3gqx-rv8x-9m5c/GHSA-3gqx-rv8x-9m5c.json b/advisories/unreviewed/2024/12/GHSA-3gqx-rv8x-9m5c/GHSA-3gqx-rv8x-9m5c.json index b300d33f1ce..5d6e1904952 100644 --- a/advisories/unreviewed/2024/12/GHSA-3gqx-rv8x-9m5c/GHSA-3gqx-rv8x-9m5c.json +++ b/advisories/unreviewed/2024/12/GHSA-3gqx-rv8x-9m5c/GHSA-3gqx-rv8x-9m5c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3gqx-rv8x-9m5c", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-02-11T18:31:22Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53218" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix race in concurrent f2fs_stop_gc_thread\n\nIn my test case, concurrent calls to f2fs shutdown report the following\nstack trace:\n\n Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI\n CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85\n Call Trace:\n \n ? show_regs+0x8b/0xa0\n ? __die_body+0x26/0xa0\n ? die_addr+0x54/0x90\n ? exc_general_protection+0x24b/0x5c0\n ? asm_exc_general_protection+0x26/0x30\n ? kthread_stop+0x46/0x390\n f2fs_stop_gc_thread+0x6c/0x110\n f2fs_do_shutdown+0x309/0x3a0\n f2fs_ioc_shutdown+0x150/0x1c0\n __f2fs_ioctl+0xffd/0x2ac0\n f2fs_ioctl+0x76/0xe0\n vfs_ioctl+0x23/0x60\n __x64_sys_ioctl+0xce/0xf0\n x64_sys_call+0x2b1b/0x4540\n do_syscall_64+0xa7/0x240\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe root cause is a race condition in f2fs_stop_gc_thread() called from\ndifferent f2fs shutdown paths:\n\n [CPU0] [CPU1]\n ---------------------- -----------------------\n f2fs_stop_gc_thread f2fs_stop_gc_thread\n gc_th = sbi->gc_thread\n gc_th = sbi->gc_thread\n kfree(gc_th)\n sbi->gc_thread = NULL\n < gc_th != NULL >\n kthread_stop(gc_th->f2fs_gc_task) //UAF\n\nThe commit c7f114d864ac (\"f2fs: fix to avoid use-after-free in\nf2fs_stop_gc_thread()\") attempted to fix this issue by using a read\nsemaphore to prevent races between shutdown and remount threads, but\nit fails to prevent all race conditions.\n\nFix it by converting to write lock of s_umount in f2fs_do_shutdown().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5hh7-6vv2-v2hg/GHSA-5hh7-6vv2-v2hg.json b/advisories/unreviewed/2024/12/GHSA-5hh7-6vv2-v2hg/GHSA-5hh7-6vv2-v2hg.json index 0c28c88bc7f..3bb80732f53 100644 --- a/advisories/unreviewed/2024/12/GHSA-5hh7-6vv2-v2hg/GHSA-5hh7-6vv2-v2hg.json +++ b/advisories/unreviewed/2024/12/GHSA-5hh7-6vv2-v2hg/GHSA-5hh7-6vv2-v2hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5hh7-6vv2-v2hg", - "modified": "2024-12-27T15:31:50Z", + "modified": "2025-02-11T18:31:22Z", "published": "2024-12-27T15:31:50Z", "aliases": [ "CVE-2024-53177" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: prevent use-after-free due to open_cached_dir error paths\n\nIf open_cached_dir() encounters an error parsing the lease from the\nserver, the error handling may race with receiving a lease break,\nresulting in open_cached_dir() freeing the cfid while the queued work is\npending.\n\nUpdate open_cached_dir() to drop refs rather than directly freeing the\ncfid.\n\nHave cached_dir_lease_break(), cfids_laundromat_worker(), and\ninvalidate_all_cached_dirs() clear has_lease immediately while still\nholding cfids->cfid_list_lock, and then use this to also simplify the\nreference counting in cfids_laundromat_worker() and\ninvalidate_all_cached_dirs().\n\nFixes this KASAN splat (which manually injects an error and lease break\nin open_cached_dir()):\n\n==================================================================\nBUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0\nRead of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65\n\nCPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87\nHardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\nWorkqueue: cifsiod smb2_cached_lease_break\nCall Trace:\n \n dump_stack_lvl+0x77/0xb0\n print_report+0xce/0x660\n kasan_report+0xd3/0x110\n smb2_cached_lease_break+0x27/0xb0\n process_one_work+0x50a/0xc50\n worker_thread+0x2ba/0x530\n kthread+0x17c/0x1c0\n ret_from_fork+0x34/0x60\n ret_from_fork_asm+0x1a/0x30\n \n\nAllocated by task 2464:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n open_cached_dir+0xa7d/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 2464:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x51/0x70\n kfree+0x174/0x520\n open_cached_dir+0x97f/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nLast potentially related work creation:\n kasan_save_stack+0x33/0x60\n __kasan_record_aux_stack+0xad/0xc0\n insert_work+0x32/0x100\n __queue_work+0x5c9/0x870\n queue_work_on+0x82/0x90\n open_cached_dir+0x1369/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe buggy address belongs to the object at ffff88811cc24c00\n which belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 16 bytes inside of\n freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json b/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json index f06cb5d56a3..7bfd3f2f141 100644 --- a/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json +++ b/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-401" + "CWE-401", + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-g8xw-8x23-c5c8/GHSA-g8xw-8x23-c5c8.json b/advisories/unreviewed/2024/12/GHSA-g8xw-8x23-c5c8/GHSA-g8xw-8x23-c5c8.json index 14220e6a887..889f054fee2 100644 --- a/advisories/unreviewed/2024/12/GHSA-g8xw-8x23-c5c8/GHSA-g8xw-8x23-c5c8.json +++ b/advisories/unreviewed/2024/12/GHSA-g8xw-8x23-c5c8/GHSA-g8xw-8x23-c5c8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g8xw-8x23-c5c8", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-02-11T18:31:22Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53194" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Fix use-after-free of slot->bus on hot remove\n\nDennis reports a boot crash on recent Lenovo laptops with a USB4 dock.\n\nSince commit 0fc70886569c (\"thunderbolt: Reset USB4 v2 host router\") and\ncommit 59a54c5f3dbd (\"thunderbolt: Reset topology created by the boot\nfirmware\"), USB4 v2 and v1 Host Routers are reset on probe of the\nthunderbolt driver.\n\nThe reset clears the Presence Detect State and Data Link Layer Link Active\nbits at the USB4 Host Router's Root Port and thus causes hot removal of the\ndock.\n\nThe crash occurs when pciehp is unbound from one of the dock's Downstream\nPorts: pciehp creates a pci_slot on bind and destroys it on unbind. The\npci_slot contains a pointer to the pci_bus below the Downstream Port, but\na reference on that pci_bus is never acquired. The pci_bus is destroyed\nbefore the pci_slot, so a use-after-free ensues when pci_slot_release()\naccesses slot->bus.\n\nIn principle this should not happen because pci_stop_bus_device() unbinds\npciehp (and therefore destroys the pci_slot) before the pci_bus is\ndestroyed by pci_remove_bus_device().\n\nHowever the stacktrace provided by Dennis shows that pciehp is unbound from\npci_remove_bus_device() instead of pci_stop_bus_device(). To understand\nthe significance of this, one needs to know that the PCI core uses a two\nstep process to remove a portion of the hierarchy: It first unbinds all\ndrivers in the sub-hierarchy in pci_stop_bus_device() and then actually\nremoves the devices in pci_remove_bus_device(). There is no precaution to\nprevent driver binding in-between pci_stop_bus_device() and\npci_remove_bus_device().\n\nIn Dennis' case, it seems removal of the hierarchy by pciehp races with\ndriver binding by pci_bus_add_devices(). pciehp is bound to the\nDownstream Port after pci_stop_bus_device() has run, so it is unbound by\npci_remove_bus_device() instead of pci_stop_bus_device(). Because the\npci_bus has already been destroyed at that point, accesses to it result in\na use-after-free.\n\nOne might conclude that driver binding needs to be prevented after\npci_stop_bus_device() has run. However it seems risky that pci_slot points\nto pci_bus without holding a reference. Solely relying on correct ordering\nof driver unbind versus pci_bus destruction is certainly not defensive\nprogramming.\n\nIf pci_slot has a need to access data in pci_bus, it ought to acquire a\nreference. Amend pci_create_slot() accordingly. Dennis reports that the\ncrash is not reproducible with this change.\n\nAbridged stacktrace:\n\n pcieport 0000:00:07.0: PME: Signaling with IRQ 156\n pcieport 0000:00:07.0: pciehp: Slot #12 AttnBtn- PwrCtrl- MRL- AttnInd- PwrInd- HotPlug+ Surprise+ Interlock- NoCompl+ IbPresDis- LLActRep+\n pci_bus 0000:20: dev 00, created physical slot 12\n pcieport 0000:00:07.0: pciehp: Slot(12): Card not present\n ...\n pcieport 0000:21:02.0: pciehp: pcie_disable_notification: SLOTCTRL d8 write cmd 0\n Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 13 UID: 0 PID: 134 Comm: irq/156-pciehp Not tainted 6.11.0-devel+ #1\n RIP: 0010:dev_driver_string+0x12/0x40\n pci_destroy_slot\n pciehp_remove\n pcie_port_remove_service\n device_release_driver_internal\n bus_remove_device\n device_del\n device_unregister\n remove_iter\n device_for_each_child\n pcie_portdrv_remove\n pci_device_remove\n device_release_driver_internal\n bus_remove_device\n device_del\n pci_remove_bus_device (recursive invocation)\n pci_remove_bus_device\n pciehp_unconfigure_device\n pciehp_disable_slot\n pciehp_handle_presence_or_link_change\n pciehp_ist", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:27Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j5g7-ch8c-pw9m/GHSA-j5g7-ch8c-pw9m.json b/advisories/unreviewed/2024/12/GHSA-j5g7-ch8c-pw9m/GHSA-j5g7-ch8c-pw9m.json index bcb3b0e8409..893a59a0560 100644 --- a/advisories/unreviewed/2024/12/GHSA-j5g7-ch8c-pw9m/GHSA-j5g7-ch8c-pw9m.json +++ b/advisories/unreviewed/2024/12/GHSA-j5g7-ch8c-pw9m/GHSA-j5g7-ch8c-pw9m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j5g7-ch8c-pw9m", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-02-11T18:31:22Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53216" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release svc_expkey/svc_export with rcu_work\n\nThe last reference for `cache_head` can be reduced to zero in `c_show`\nand `e_show`(using `rcu_read_lock` and `rcu_read_unlock`). Consequently,\n`svc_export_put` and `expkey_put` will be invoked, leading to two\nissues:\n\n1. The `svc_export_put` will directly free ex_uuid. However,\n `e_show`/`c_show` will access `ex_uuid` after `cache_put`, which can\n trigger a use-after-free issue, shown below.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in svc_export_show+0x362/0x430 [nfsd]\n Read of size 1 at addr ff11000010fdc120 by task cat/870\n\n CPU: 1 UID: 0 PID: 870 Comm: cat Not tainted 6.12.0-rc3+ #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n 1.16.1-2.fc37 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x53/0x70\n print_address_description.constprop.0+0x2c/0x3a0\n print_report+0xb9/0x280\n kasan_report+0xae/0xe0\n svc_export_show+0x362/0x430 [nfsd]\n c_show+0x161/0x390 [sunrpc]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n proc_reg_read+0xe1/0x140\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Allocated by task 830:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __kmalloc_node_track_caller_noprof+0x1bc/0x400\n kmemdup_noprof+0x22/0x50\n svc_export_parse+0x8a9/0xb80 [nfsd]\n cache_do_downcall+0x71/0xa0 [sunrpc]\n cache_write_procfs+0x8e/0xd0 [sunrpc]\n proc_reg_write+0xe1/0x140\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 868:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kfree+0xf3/0x3e0\n svc_export_put+0x87/0xb0 [nfsd]\n cache_purge+0x17f/0x1f0 [sunrpc]\n nfsd_destroy_serv+0x226/0x2d0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n2. We cannot sleep while using `rcu_read_lock`/`rcu_read_unlock`.\n However, `svc_export_put`/`expkey_put` will call path_put, which\n subsequently triggers a sleeping operation due to the following\n `dput`.\n\n =============================\n WARNING: suspicious RCU usage\n 5.10.0-dirty #141 Not tainted\n -----------------------------\n ...\n Call Trace:\n dump_stack+0x9a/0xd0\n ___might_sleep+0x231/0x240\n dput+0x39/0x600\n path_put+0x1b/0x30\n svc_export_put+0x17/0x80\n e_show+0x1c9/0x200\n seq_read_iter+0x63f/0x7c0\n seq_read+0x226/0x2d0\n vfs_read+0x113/0x2c0\n ksys_read+0xc9/0x170\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nFix these issues by using `rcu_work` to help release\n`svc_expkey`/`svc_export`. This approach allows for an asynchronous\ncontext to invoke `path_put` and also facilitates the freeing of\n`uuid/exp/key` after an RCU grace period.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m5rf-wjr7-895f/GHSA-m5rf-wjr7-895f.json b/advisories/unreviewed/2024/12/GHSA-m5rf-wjr7-895f/GHSA-m5rf-wjr7-895f.json index 22fe246df1b..b47406c2f2b 100644 --- a/advisories/unreviewed/2024/12/GHSA-m5rf-wjr7-895f/GHSA-m5rf-wjr7-895f.json +++ b/advisories/unreviewed/2024/12/GHSA-m5rf-wjr7-895f/GHSA-m5rf-wjr7-895f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m5rf-wjr7-895f", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-02-11T18:31:27Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56619" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()\n\nSyzbot reported that when searching for records in a directory where the\ninode's i_size is corrupted and has a large value, memory access outside\nthe folio/page range may occur, or a use-after-free bug may be detected if\nKASAN is enabled.\n\nThis is because nilfs_last_byte(), which is called by nilfs_find_entry()\nand others to calculate the number of valid bytes of directory data in a\npage from i_size and the page index, loses the upper 32 bits of the 64-bit\nsize information due to an inappropriate type of local variable to which\nthe i_size value is assigned.\n\nThis caused a large byte offset value due to underflow in the end address\ncalculation in the calling nilfs_find_entry(), resulting in memory access\nthat exceeds the folio/page size.\n\nFix this issue by changing the type of the local variable causing the bit\nloss from \"unsigned int\" to \"u64\". The return value of nilfs_last_byte()\nis also of type \"unsigned int\", but it is truncated so as not to exceed\nPAGE_SIZE and no bit loss occurs, so no change is required.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-r5pj-8mrw-4gqj/GHSA-r5pj-8mrw-4gqj.json b/advisories/unreviewed/2024/12/GHSA-r5pj-8mrw-4gqj/GHSA-r5pj-8mrw-4gqj.json index 7cc8de4cebb..165e60d590b 100644 --- a/advisories/unreviewed/2024/12/GHSA-r5pj-8mrw-4gqj/GHSA-r5pj-8mrw-4gqj.json +++ b/advisories/unreviewed/2024/12/GHSA-r5pj-8mrw-4gqj/GHSA-r5pj-8mrw-4gqj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5pj-8mrw-4gqj", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-02-11T18:31:23Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56558" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: make sure exp active before svc_export_show\n\nThe function `e_show` was called with protection from RCU. This only\nensures that `exp` will not be freed. Therefore, the reference count for\n`exp` can drop to zero, which will trigger a refcount use-after-free\nwarning when `exp_get` is called. To resolve this issue, use\n`cache_get_rcu` to ensure that `exp` remains active.\n\n------------[ cut here ]------------\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 3 PID: 819 at lib/refcount.c:25\nrefcount_warn_saturate+0xb1/0x120\nCPU: 3 UID: 0 PID: 819 Comm: cat Not tainted 6.12.0-rc3+ #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xb1/0x120\n...\nCall Trace:\n \n e_show+0x20b/0x230 [nfsd]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v5r3-wf29-qq37/GHSA-v5r3-wf29-qq37.json b/advisories/unreviewed/2024/12/GHSA-v5r3-wf29-qq37/GHSA-v5r3-wf29-qq37.json index 8be4d4bdda0..25ab0c0fdca 100644 --- a/advisories/unreviewed/2024/12/GHSA-v5r3-wf29-qq37/GHSA-v5r3-wf29-qq37.json +++ b/advisories/unreviewed/2024/12/GHSA-v5r3-wf29-qq37/GHSA-v5r3-wf29-qq37.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v5r3-wf29-qq37", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-02-11T18:31:27Z", "published": "2024-12-28T12:30:46Z", "aliases": [ "CVE-2024-56678" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/mm/fault: Fix kfence page fault reporting\n\ncopy_from_kernel_nofault() can be called when doing read of /proc/kcore.\n/proc/kcore can have some unmapped kfence objects which when read via\ncopy_from_kernel_nofault() can cause page faults. Since *_nofault()\nfunctions define their own fixup table for handling fault, use that\ninstead of asking kfence to handle such faults.\n\nHence we search the exception tables for the nip which generated the\nfault. If there is an entry then we let the fixup table handler handle the\npage fault by returning an error from within ___do_page_fault().\n\nThis can be easily triggered if someone tries to do dd from /proc/kcore.\neg. dd if=/proc/kcore of=/dev/null bs=1M\n\nSome example false negatives:\n\n ===============================\n BUG: KFENCE: invalid read in copy_from_kernel_nofault+0x9c/0x1a0\n Invalid read at 0xc0000000fdff0000:\n copy_from_kernel_nofault+0x9c/0x1a0\n 0xc00000000665f950\n read_kcore_iter+0x57c/0xa04\n proc_reg_read_iter+0xe4/0x16c\n vfs_read+0x320/0x3ec\n ksys_read+0x90/0x154\n system_call_exception+0x120/0x310\n system_call_vectored_common+0x15c/0x2ec\n\n BUG: KFENCE: use-after-free read in copy_from_kernel_nofault+0x9c/0x1a0\n Use-after-free read at 0xc0000000fe050000 (in kfence-#2):\n copy_from_kernel_nofault+0x9c/0x1a0\n 0xc00000000665f950\n read_kcore_iter+0x57c/0xa04\n proc_reg_read_iter+0xe4/0x16c\n vfs_read+0x320/0x3ec\n ksys_read+0x90/0x154\n system_call_exception+0x120/0x310\n system_call_vectored_common+0x15c/0x2ec", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json b/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json index 3d4511402dc..0d72a679f04 100644 --- a/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json +++ b/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-w2rf-r2gq-hxp9/GHSA-w2rf-r2gq-hxp9.json b/advisories/unreviewed/2025/01/GHSA-w2rf-r2gq-hxp9/GHSA-w2rf-r2gq-hxp9.json index 6479ad5fc91..d09e2af96fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-w2rf-r2gq-hxp9/GHSA-w2rf-r2gq-hxp9.json +++ b/advisories/unreviewed/2025/01/GHSA-w2rf-r2gq-hxp9/GHSA-w2rf-r2gq-hxp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w2rf-r2gq-hxp9", - "modified": "2025-01-11T15:30:27Z", + "modified": "2025-02-11T18:31:28Z", "published": "2025-01-11T15:30:27Z", "aliases": [ "CVE-2024-41149" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: avoid to reuse `hctx` not removed from cpuhp callback list\n\nIf the 'hctx' isn't removed from cpuhp callback list, we can't reuse it,\notherwise use-after-free may be triggered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-11T13:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json b/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json index 0e09b19ba64..34f0328b719 100644 --- a/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json +++ b/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w7pq-rmwm-c759", - "modified": "2025-02-02T12:30:24Z", + "modified": "2025-02-11T18:31:28Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57887" diff --git a/advisories/unreviewed/2025/02/GHSA-25h6-xmmh-34gc/GHSA-25h6-xmmh-34gc.json b/advisories/unreviewed/2025/02/GHSA-25h6-xmmh-34gc/GHSA-25h6-xmmh-34gc.json new file mode 100644 index 00000000000..db085397b07 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-25h6-xmmh-34gc/GHSA-25h6-xmmh-34gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25h6-xmmh-34gc", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21369" + ], + "details": "Microsoft Digest Authentication Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21369" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2f84-gmq2-v8m2/GHSA-2f84-gmq2-v8m2.json b/advisories/unreviewed/2025/02/GHSA-2f84-gmq2-v8m2/GHSA-2f84-gmq2-v8m2.json new file mode 100644 index 00000000000..bb536d73366 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2f84-gmq2-v8m2/GHSA-2f84-gmq2-v8m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f84-gmq2-v8m2", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21208" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21208" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2jmc-8g4c-98px/GHSA-2jmc-8g4c-98px.json b/advisories/unreviewed/2025/02/GHSA-2jmc-8g4c-98px/GHSA-2jmc-8g4c-98px.json new file mode 100644 index 00000000000..8852810c7c7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2jmc-8g4c-98px/GHSA-2jmc-8g4c-98px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jmc-8g4c-98px", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21121" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21121" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-352f-c86f-rrhx/GHSA-352f-c86f-rrhx.json b/advisories/unreviewed/2025/02/GHSA-352f-c86f-rrhx/GHSA-352f-c86f-rrhx.json new file mode 100644 index 00000000000..f2e6e4e92ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-352f-c86f-rrhx/GHSA-352f-c86f-rrhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-352f-c86f-rrhx", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21322" + ], + "details": "Microsoft PC Manager Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21322" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21322" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-36hw-x3cc-m258/GHSA-36hw-x3cc-m258.json b/advisories/unreviewed/2025/02/GHSA-36hw-x3cc-m258/GHSA-36hw-x3cc-m258.json new file mode 100644 index 00000000000..cf94a6f91f1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-36hw-x3cc-m258/GHSA-36hw-x3cc-m258.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36hw-x3cc-m258", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24411" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24411" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-38pv-jq7m-mrw3/GHSA-38pv-jq7m-mrw3.json b/advisories/unreviewed/2025/02/GHSA-38pv-jq7m-mrw3/GHSA-38pv-jq7m-mrw3.json new file mode 100644 index 00000000000..1f8d1dcca00 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-38pv-jq7m-mrw3/GHSA-38pv-jq7m-mrw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38pv-jq7m-mrw3", + "modified": "2025-02-11T18:31:33Z", + "published": "2025-02-11T18:31:33Z", + "aliases": [ + "CVE-2024-10644" + ], + "details": "Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10644" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-39c9-242x-fjqf/GHSA-39c9-242x-fjqf.json b/advisories/unreviewed/2025/02/GHSA-39c9-242x-fjqf/GHSA-39c9-242x-fjqf.json new file mode 100644 index 00000000000..1e39e34ba77 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-39c9-242x-fjqf/GHSA-39c9-242x-fjqf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39c9-242x-fjqf", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-12755" + ], + "details": "A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12755" + }, + { + "type": "WEB", + "url": "https://support.avaya.com/css/public/documents/101091836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3cfg-w257-cgf8/GHSA-3cfg-w257-cgf8.json b/advisories/unreviewed/2025/02/GHSA-3cfg-w257-cgf8/GHSA-3cfg-w257-cgf8.json new file mode 100644 index 00000000000..9c18819d745 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3cfg-w257-cgf8/GHSA-3cfg-w257-cgf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cfg-w257-cgf8", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24408" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24408" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3fgj-qpvr-j8qg/GHSA-3fgj-qpvr-j8qg.json b/advisories/unreviewed/2025/02/GHSA-3fgj-qpvr-j8qg/GHSA-3fgj-qpvr-j8qg.json new file mode 100644 index 00000000000..81b4777636d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3fgj-qpvr-j8qg/GHSA-3fgj-qpvr-j8qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fgj-qpvr-j8qg", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24420" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24420" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3w7j-22pr-7fp6/GHSA-3w7j-22pr-7fp6.json b/advisories/unreviewed/2025/02/GHSA-3w7j-22pr-7fp6/GHSA-3w7j-22pr-7fp6.json new file mode 100644 index 00000000000..fbfe0bad8a2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3w7j-22pr-7fp6/GHSA-3w7j-22pr-7fp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w7j-22pr-7fp6", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21337" + ], + "details": "Windows NTFS Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21337" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-42h6-4vvm-4f49/GHSA-42h6-4vvm-4f49.json b/advisories/unreviewed/2025/02/GHSA-42h6-4vvm-4f49/GHSA-42h6-4vvm-4f49.json index 14876abaeea..3fedf049e7f 100644 --- a/advisories/unreviewed/2025/02/GHSA-42h6-4vvm-4f49/GHSA-42h6-4vvm-4f49.json +++ b/advisories/unreviewed/2025/02/GHSA-42h6-4vvm-4f49/GHSA-42h6-4vvm-4f49.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-552" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json b/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json new file mode 100644 index 00000000000..898bd9a9501 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-469f-wf4f-3jjv", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24437" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain elevated privileges. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24437" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-47m6-2q4v-m2vx/GHSA-47m6-2q4v-m2vx.json b/advisories/unreviewed/2025/02/GHSA-47m6-2q4v-m2vx/GHSA-47m6-2q4v-m2vx.json new file mode 100644 index 00000000000..69bf23bcc8f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-47m6-2q4v-m2vx/GHSA-47m6-2q4v-m2vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47m6-2q4v-m2vx", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21259" + ], + "details": "Microsoft Outlook Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21259" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4fcp-ccxj-vf2h/GHSA-4fcp-ccxj-vf2h.json b/advisories/unreviewed/2025/02/GHSA-4fcp-ccxj-vf2h/GHSA-4fcp-ccxj-vf2h.json new file mode 100644 index 00000000000..4324cd68846 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4fcp-ccxj-vf2h/GHSA-4fcp-ccxj-vf2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fcp-ccxj-vf2h", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21200" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21200" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4fv3-v4jw-2q2p/GHSA-4fv3-v4jw-2q2p.json b/advisories/unreviewed/2025/02/GHSA-4fv3-v4jw-2q2p/GHSA-4fv3-v4jw-2q2p.json new file mode 100644 index 00000000000..0e60091be3e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4fv3-v4jw-2q2p/GHSA-4fv3-v4jw-2q2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fv3-v4jw-2q2p", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-1126" + ], + "details": "A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1126" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-807" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4hpj-87mp-j2fq/GHSA-4hpj-87mp-j2fq.json b/advisories/unreviewed/2025/02/GHSA-4hpj-87mp-j2fq/GHSA-4hpj-87mp-j2fq.json new file mode 100644 index 00000000000..917f1515c10 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4hpj-87mp-j2fq/GHSA-4hpj-87mp-j2fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hpj-87mp-j2fq", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21368" + ], + "details": "Microsoft Digest Authentication Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21368" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4wjr-89vg-3hx6/GHSA-4wjr-89vg-3hx6.json b/advisories/unreviewed/2025/02/GHSA-4wjr-89vg-3hx6/GHSA-4wjr-89vg-3hx6.json new file mode 100644 index 00000000000..201b170b6d1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4wjr-89vg-3hx6/GHSA-4wjr-89vg-3hx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wjr-89vg-3hx6", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-11771" + ], + "details": "Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11771" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-539v-w87w-w62c/GHSA-539v-w87w-w62c.json b/advisories/unreviewed/2025/02/GHSA-539v-w87w-w62c/GHSA-539v-w87w-w62c.json new file mode 100644 index 00000000000..607e8161ad0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-539v-w87w-w62c/GHSA-539v-w87w-w62c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-539v-w87w-w62c", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24424" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24424" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5572-v74v-4p6x/GHSA-5572-v74v-4p6x.json b/advisories/unreviewed/2025/02/GHSA-5572-v74v-4p6x/GHSA-5572-v74v-4p6x.json new file mode 100644 index 00000000000..5aaa85c1197 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5572-v74v-4p6x/GHSA-5572-v74v-4p6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5572-v74v-4p6x", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21201" + ], + "details": "Windows Telephony Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21201" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21201" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-59vj-grh4-hp2j/GHSA-59vj-grh4-hp2j.json b/advisories/unreviewed/2025/02/GHSA-59vj-grh4-hp2j/GHSA-59vj-grh4-hp2j.json index edcbff5cac2..9c26c932ce6 100644 --- a/advisories/unreviewed/2025/02/GHSA-59vj-grh4-hp2j/GHSA-59vj-grh4-hp2j.json +++ b/advisories/unreviewed/2025/02/GHSA-59vj-grh4-hp2j/GHSA-59vj-grh4-hp2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59vj-grh4-hp2j", - "modified": "2025-02-07T12:31:19Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-07T12:31:19Z", "aliases": [ "CVE-2025-25167" diff --git a/advisories/unreviewed/2025/02/GHSA-5fcc-vrrh-rv6c/GHSA-5fcc-vrrh-rv6c.json b/advisories/unreviewed/2025/02/GHSA-5fcc-vrrh-rv6c/GHSA-5fcc-vrrh-rv6c.json new file mode 100644 index 00000000000..4f69c008bdb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5fcc-vrrh-rv6c/GHSA-5fcc-vrrh-rv6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fcc-vrrh-rv6c", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21400" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21400" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5fhq-7w32-vhww/GHSA-5fhq-7w32-vhww.json b/advisories/unreviewed/2025/02/GHSA-5fhq-7w32-vhww/GHSA-5fhq-7w32-vhww.json new file mode 100644 index 00000000000..8d253abbef4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5fhq-7w32-vhww/GHSA-5fhq-7w32-vhww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fhq-7w32-vhww", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21418" + ], + "details": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21418" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21418" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5h34-2v2x-rw9w/GHSA-5h34-2v2x-rw9w.json b/advisories/unreviewed/2025/02/GHSA-5h34-2v2x-rw9w/GHSA-5h34-2v2x-rw9w.json new file mode 100644 index 00000000000..fed704e3ec5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5h34-2v2x-rw9w/GHSA-5h34-2v2x-rw9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h34-2v2x-rw9w", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21359" + ], + "details": "Windows Kernel Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21359" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21359" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-656q-fx2w-8ccv/GHSA-656q-fx2w-8ccv.json b/advisories/unreviewed/2025/02/GHSA-656q-fx2w-8ccv/GHSA-656q-fx2w-8ccv.json new file mode 100644 index 00000000000..d364a4ad10a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-656q-fx2w-8ccv/GHSA-656q-fx2w-8ccv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-656q-fx2w-8ccv", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24429" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24429" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-68fp-23v5-2qjg/GHSA-68fp-23v5-2qjg.json b/advisories/unreviewed/2025/02/GHSA-68fp-23v5-2qjg/GHSA-68fp-23v5-2qjg.json new file mode 100644 index 00000000000..659ebb76ba1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-68fp-23v5-2qjg/GHSA-68fp-23v5-2qjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68fp-23v5-2qjg", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24419" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24419" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6935-7595-p6j6/GHSA-6935-7595-p6j6.json b/advisories/unreviewed/2025/02/GHSA-6935-7595-p6j6/GHSA-6935-7595-p6j6.json new file mode 100644 index 00000000000..b7af463be6f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6935-7595-p6j6/GHSA-6935-7595-p6j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6935-7595-p6j6", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24426" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24426" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6ff8-jrfg-43hh/GHSA-6ff8-jrfg-43hh.json b/advisories/unreviewed/2025/02/GHSA-6ff8-jrfg-43hh/GHSA-6ff8-jrfg-43hh.json new file mode 100644 index 00000000000..b4bbf41eed5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6ff8-jrfg-43hh/GHSA-6ff8-jrfg-43hh.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ff8-jrfg-43hh", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24425" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to circumvent intended security mechanisms by manipulating the logic of the application's operations causing limited data modification. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24425" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6rfg-cmrr-c9j6/GHSA-6rfg-cmrr-c9j6.json b/advisories/unreviewed/2025/02/GHSA-6rfg-cmrr-c9j6/GHSA-6rfg-cmrr-c9j6.json new file mode 100644 index 00000000000..c331df62814 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6rfg-cmrr-c9j6/GHSA-6rfg-cmrr-c9j6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rfg-cmrr-c9j6", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-33504" + ], + "details": "A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/orangecertcc/security-research/security/advisories/GHSA-pgc3-m5p5-4vc3" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33504" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json b/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json new file mode 100644 index 00000000000..965f10f3096 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w27-c66f-gvhq", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24430" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24430" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-75j8-9mw5-6mp8/GHSA-75j8-9mw5-6mp8.json b/advisories/unreviewed/2025/02/GHSA-75j8-9mw5-6mp8/GHSA-75j8-9mw5-6mp8.json new file mode 100644 index 00000000000..73b8e400949 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-75j8-9mw5-6mp8/GHSA-75j8-9mw5-6mp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75j8-9mw5-6mp8", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21379" + ], + "details": "DHCP Client Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21379" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21379" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-77rp-fp5p-7wgw/GHSA-77rp-fp5p-7wgw.json b/advisories/unreviewed/2025/02/GHSA-77rp-fp5p-7wgw/GHSA-77rp-fp5p-7wgw.json new file mode 100644 index 00000000000..e0c5c940204 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-77rp-fp5p-7wgw/GHSA-77rp-fp5p-7wgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77rp-fp5p-7wgw", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-13842" + ], + "details": "A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13842" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json b/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json new file mode 100644 index 00000000000..003e8d9c6f6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jmr-43qj-pw47", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24432" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24432" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7w3h-vqp8-323r/GHSA-7w3h-vqp8-323r.json b/advisories/unreviewed/2025/02/GHSA-7w3h-vqp8-323r/GHSA-7w3h-vqp8-323r.json new file mode 100644 index 00000000000..2b22f858ea7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7w3h-vqp8-323r/GHSA-7w3h-vqp8-323r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w3h-vqp8-323r", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-36508" + ], + "details": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36508" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7wx7-289w-5fpm/GHSA-7wx7-289w-5fpm.json b/advisories/unreviewed/2025/02/GHSA-7wx7-289w-5fpm/GHSA-7wx7-289w-5fpm.json new file mode 100644 index 00000000000..a07428cdcbb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7wx7-289w-5fpm/GHSA-7wx7-289w-5fpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wx7-289w-5fpm", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21182" + ], + "details": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21182" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json b/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json new file mode 100644 index 00000000000..dcefecab4fc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82p4-55gj-956p", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24435" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24435" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-86j4-r2vh-3f28/GHSA-86j4-r2vh-3f28.json b/advisories/unreviewed/2025/02/GHSA-86j4-r2vh-3f28/GHSA-86j4-r2vh-3f28.json new file mode 100644 index 00000000000..351f3ff90c3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-86j4-r2vh-3f28/GHSA-86j4-r2vh-3f28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86j4-r2vh-3f28", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24418" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24418" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-86pr-h8wv-6hgc/GHSA-86pr-h8wv-6hgc.json b/advisories/unreviewed/2025/02/GHSA-86pr-h8wv-6hgc/GHSA-86pr-h8wv-6hgc.json new file mode 100644 index 00000000000..710bab66061 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-86pr-h8wv-6hgc/GHSA-86pr-h8wv-6hgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86pr-h8wv-6hgc", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21386" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21386" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-884v-fpxm-8fhr/GHSA-884v-fpxm-8fhr.json b/advisories/unreviewed/2025/02/GHSA-884v-fpxm-8fhr/GHSA-884v-fpxm-8fhr.json new file mode 100644 index 00000000000..2802de137cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-884v-fpxm-8fhr/GHSA-884v-fpxm-8fhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-884v-fpxm-8fhr", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21184" + ], + "details": "Windows Core Messaging Elevation of Privileges Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21184" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json b/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json new file mode 100644 index 00000000000..62b62d622bd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8884-7rm9-mrx4", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24438" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24438" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-89gg-gc7x-gwhp/GHSA-89gg-gc7x-gwhp.json b/advisories/unreviewed/2025/02/GHSA-89gg-gc7x-gwhp/GHSA-89gg-gc7x-gwhp.json new file mode 100644 index 00000000000..a63c2fb59a1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-89gg-gc7x-gwhp/GHSA-89gg-gc7x-gwhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89gg-gc7x-gwhp", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-40586" + ], + "details": "An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40586" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-279" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8ccx-r52j-39f8/GHSA-8ccx-r52j-39f8.json b/advisories/unreviewed/2025/02/GHSA-8ccx-r52j-39f8/GHSA-8ccx-r52j-39f8.json new file mode 100644 index 00000000000..d806af3d69a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8ccx-r52j-39f8/GHSA-8ccx-r52j-39f8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ccx-r52j-39f8", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-35279" + ], + "details": "A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabric service is running on the exposed interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35279" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8hp7-6pv7-c4rv/GHSA-8hp7-6pv7-c4rv.json b/advisories/unreviewed/2025/02/GHSA-8hp7-6pv7-c4rv/GHSA-8hp7-6pv7-c4rv.json new file mode 100644 index 00000000000..6a3f19bfd61 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8hp7-6pv7-c4rv/GHSA-8hp7-6pv7-c4rv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hp7-6pv7-c4rv", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2023-40721" + ], + "details": "A use of externally-controlled format string vulnerability [CWE-134] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.6, FortiProxy version 7.4.0 and before 7.2.7, FortiPAM version 1.1.2 and before 1.0.3, FortiSwitchManager version 7.2.0 through 7.2.2 and before 7.0.2 allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40721" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-261" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-134" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8pmq-vh8m-9xj5/GHSA-8pmq-vh8m-9xj5.json b/advisories/unreviewed/2025/02/GHSA-8pmq-vh8m-9xj5/GHSA-8pmq-vh8m-9xj5.json new file mode 100644 index 00000000000..c76e97f3f06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8pmq-vh8m-9xj5/GHSA-8pmq-vh8m-9xj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pmq-vh8m-9xj5", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21347" + ], + "details": "Windows Deployment Services Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21347" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-94c3-phmr-h8qw/GHSA-94c3-phmr-h8qw.json b/advisories/unreviewed/2025/02/GHSA-94c3-phmr-h8qw/GHSA-94c3-phmr-h8qw.json new file mode 100644 index 00000000000..4eb11dfaf13 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-94c3-phmr-h8qw/GHSA-94c3-phmr-h8qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c3-phmr-h8qw", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21420" + ], + "details": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21420" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21420" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-94mc-r26h-rwj7/GHSA-94mc-r26h-rwj7.json b/advisories/unreviewed/2025/02/GHSA-94mc-r26h-rwj7/GHSA-94mc-r26h-rwj7.json index 7b12e27d5ce..fa52c487229 100644 --- a/advisories/unreviewed/2025/02/GHSA-94mc-r26h-rwj7/GHSA-94mc-r26h-rwj7.json +++ b/advisories/unreviewed/2025/02/GHSA-94mc-r26h-rwj7/GHSA-94mc-r26h-rwj7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94mc-r26h-rwj7", - "modified": "2025-02-09T12:30:53Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-09T12:30:53Z", "aliases": [ "CVE-2024-57949" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity()\n\nThe following call-chain leads to enabling interrupts in a nested interrupt\ndisabled section:\n\nirq_set_vcpu_affinity()\n irq_get_desc_lock()\n raw_spin_lock_irqsave() <--- Disable interrupts\n its_irq_set_vcpu_affinity()\n guard(raw_spinlock_irq) <--- Enables interrupts when leaving the guard()\n irq_put_desc_unlock() <--- Warns because interrupts are enabled\n\nThis was broken in commit b97e8a2f7130, which replaced the original\nraw_spin_[un]lock() pair with guard(raw_spinlock_irq).\n\nFix the issue by using guard(raw_spinlock).\n\n[ tglx: Massaged change log ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-09T12:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-954p-ff72-327w/GHSA-954p-ff72-327w.json b/advisories/unreviewed/2025/02/GHSA-954p-ff72-327w/GHSA-954p-ff72-327w.json new file mode 100644 index 00000000000..09ae257ff5c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-954p-ff72-327w/GHSA-954p-ff72-327w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-954p-ff72-327w", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24406" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to modify files that are stored outside the restricted directory. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24406" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9gpm-8mwr-673m/GHSA-9gpm-8mwr-673m.json b/advisories/unreviewed/2025/02/GHSA-9gpm-8mwr-673m/GHSA-9gpm-8mwr-673m.json new file mode 100644 index 00000000000..2ae27c3ea7c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9gpm-8mwr-673m/GHSA-9gpm-8mwr-673m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gpm-8mwr-673m", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24423" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24423" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9h2w-m8h7-gx2j/GHSA-9h2w-m8h7-gx2j.json b/advisories/unreviewed/2025/02/GHSA-9h2w-m8h7-gx2j/GHSA-9h2w-m8h7-gx2j.json new file mode 100644 index 00000000000..6f6c5b05f18 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9h2w-m8h7-gx2j/GHSA-9h2w-m8h7-gx2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h2w-m8h7-gx2j", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21158" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21158" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json b/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json index 5598368d6e1..d3ab2621241 100644 --- a/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json +++ b/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9hm7-j2jc-wh96", - "modified": "2025-02-11T06:30:27Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-11T06:30:27Z", "aliases": [ "CVE-2024-13570" ], "details": "The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T06:15:19Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json b/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json index 73861daf971..6ac827d9d13 100644 --- a/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json +++ b/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m2c-327v-gghq", - "modified": "2025-02-11T06:30:27Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-11T06:30:27Z", "aliases": [ "CVE-2024-13544" ], "details": "The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T06:15:19Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9ppp-g4g9-895w/GHSA-9ppp-g4g9-895w.json b/advisories/unreviewed/2025/02/GHSA-9ppp-g4g9-895w/GHSA-9ppp-g4g9-895w.json new file mode 100644 index 00000000000..e8ef708ee83 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9ppp-g4g9-895w/GHSA-9ppp-g4g9-895w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ppp-g4g9-895w", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-13813" + ], + "details": "Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13813" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9qpm-p6ch-fh75/GHSA-9qpm-p6ch-fh75.json b/advisories/unreviewed/2025/02/GHSA-9qpm-p6ch-fh75/GHSA-9qpm-p6ch-fh75.json new file mode 100644 index 00000000000..c2cbfd500cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9qpm-p6ch-fh75/GHSA-9qpm-p6ch-fh75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpm-p6ch-fh75", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21160" + ], + "details": "Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21160" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb25-11.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xvm-jq49-f479/GHSA-9xvm-jq49-f479.json b/advisories/unreviewed/2025/02/GHSA-9xvm-jq49-f479/GHSA-9xvm-jq49-f479.json new file mode 100644 index 00000000000..82d8cdf2d1a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xvm-jq49-f479/GHSA-9xvm-jq49-f479.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xvm-jq49-f479", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21157" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21157" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c228-pg9x-pq8r/GHSA-c228-pg9x-pq8r.json b/advisories/unreviewed/2025/02/GHSA-c228-pg9x-pq8r/GHSA-c228-pg9x-pq8r.json new file mode 100644 index 00000000000..0c636d9214b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c228-pg9x-pq8r/GHSA-c228-pg9x-pq8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c228-pg9x-pq8r", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21183" + ], + "details": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21183" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c32r-2v88-64qc/GHSA-c32r-2v88-64qc.json b/advisories/unreviewed/2025/02/GHSA-c32r-2v88-64qc/GHSA-c32r-2v88-64qc.json new file mode 100644 index 00000000000..6ac97af0d5c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c32r-2v88-64qc/GHSA-c32r-2v88-64qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c32r-2v88-64qc", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24042" + ], + "details": "Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24042" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c845-pqj5-pcfx/GHSA-c845-pqj5-pcfx.json b/advisories/unreviewed/2025/02/GHSA-c845-pqj5-pcfx/GHSA-c845-pqj5-pcfx.json new file mode 100644 index 00000000000..ccbb91e9594 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c845-pqj5-pcfx/GHSA-c845-pqj5-pcfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c845-pqj5-pcfx", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21394" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21394" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21394" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cg8r-2vc3-jvc7/GHSA-cg8r-2vc3-jvc7.json b/advisories/unreviewed/2025/02/GHSA-cg8r-2vc3-jvc7/GHSA-cg8r-2vc3-jvc7.json new file mode 100644 index 00000000000..3ca73f1275e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cg8r-2vc3-jvc7/GHSA-cg8r-2vc3-jvc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg8r-2vc3-jvc7", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-27781" + ], + "details": "An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox at least versions 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27781" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ch34-523r-q5vg/GHSA-ch34-523r-q5vg.json b/advisories/unreviewed/2025/02/GHSA-ch34-523r-q5vg/GHSA-ch34-523r-q5vg.json new file mode 100644 index 00000000000..f77cfd47e87 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ch34-523r-q5vg/GHSA-ch34-523r-q5vg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch34-523r-q5vg", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21383" + ], + "details": "Microsoft Excel Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21383" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cjp8-9pqq-fmqg/GHSA-cjp8-9pqq-fmqg.json b/advisories/unreviewed/2025/02/GHSA-cjp8-9pqq-fmqg/GHSA-cjp8-9pqq-fmqg.json new file mode 100644 index 00000000000..675a5fd7a91 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cjp8-9pqq-fmqg/GHSA-cjp8-9pqq-fmqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjp8-9pqq-fmqg", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-24470" + ], + "details": "An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24470" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cjxh-w6v6-6g7p/GHSA-cjxh-w6v6-6g7p.json b/advisories/unreviewed/2025/02/GHSA-cjxh-w6v6-6g7p/GHSA-cjxh-w6v6-6g7p.json new file mode 100644 index 00000000000..0d7ec2b094c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cjxh-w6v6-6g7p/GHSA-cjxh-w6v6-6g7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjxh-w6v6-6g7p", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24407" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24407" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cp3g-mr7f-v756/GHSA-cp3g-mr7f-v756.json b/advisories/unreviewed/2025/02/GHSA-cp3g-mr7f-v756/GHSA-cp3g-mr7f-v756.json new file mode 100644 index 00000000000..0619ca8d700 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cp3g-mr7f-v756/GHSA-cp3g-mr7f-v756.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp3g-mr7f-v756", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21190" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21190" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json b/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json new file mode 100644 index 00000000000..254cb35f4eb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f9rw-96g7-cwhw/GHSA-f9rw-96g7-cwhw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9rw-96g7-cwhw", + "modified": "2025-02-11T18:31:43Z", + "published": "2025-02-11T18:31:43Z", + "aliases": [ + "CVE-2025-26495" + ], + "details": "Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26495" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=000390611&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json b/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json new file mode 100644 index 00000000000..9956f25e0da --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhw6-3mj5-w9gv", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24414" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24414" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json b/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json new file mode 100644 index 00000000000..4a1de02785c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp9w-9x2r-74qr", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21123" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21123" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fppq-f2m6-xv5c/GHSA-fppq-f2m6-xv5c.json b/advisories/unreviewed/2025/02/GHSA-fppq-f2m6-xv5c/GHSA-fppq-f2m6-xv5c.json new file mode 100644 index 00000000000..909dd777f44 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fppq-f2m6-xv5c/GHSA-fppq-f2m6-xv5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fppq-f2m6-xv5c", + "modified": "2025-02-11T18:31:43Z", + "published": "2025-02-11T18:31:43Z", + "aliases": [ + "CVE-2025-24434" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24434" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fwv6-m7wj-gm63/GHSA-fwv6-m7wj-gm63.json b/advisories/unreviewed/2025/02/GHSA-fwv6-m7wj-gm63/GHSA-fwv6-m7wj-gm63.json new file mode 100644 index 00000000000..ecd99a0f08a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fwv6-m7wj-gm63/GHSA-fwv6-m7wj-gm63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwv6-m7wj-gm63", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21376" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21376" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json b/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json new file mode 100644 index 00000000000..26ab3da1c17 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3j6-9753-8mp2", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24417" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24417" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g5rj-645r-67rh/GHSA-g5rj-645r-67rh.json b/advisories/unreviewed/2025/02/GHSA-g5rj-645r-67rh/GHSA-g5rj-645r-67rh.json new file mode 100644 index 00000000000..0eb594449ff --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g5rj-645r-67rh/GHSA-g5rj-645r-67rh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5rj-645r-67rh", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-50567" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50567" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-438" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g6rc-7qwp-r256/GHSA-g6rc-7qwp-r256.json b/advisories/unreviewed/2025/02/GHSA-g6rc-7qwp-r256/GHSA-g6rc-7qwp-r256.json index 9ea09858c7a..fb0a4d04bfc 100644 --- a/advisories/unreviewed/2025/02/GHSA-g6rc-7qwp-r256/GHSA-g6rc-7qwp-r256.json +++ b/advisories/unreviewed/2025/02/GHSA-g6rc-7qwp-r256/GHSA-g6rc-7qwp-r256.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-449", "CWE-451" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-g8jx-gxq8-gg28/GHSA-g8jx-gxq8-gg28.json b/advisories/unreviewed/2025/02/GHSA-g8jx-gxq8-gg28/GHSA-g8jx-gxq8-gg28.json new file mode 100644 index 00000000000..b0772312ad7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g8jx-gxq8-gg28/GHSA-g8jx-gxq8-gg28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8jx-gxq8-gg28", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-12058" + ], + "details": "External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12058" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g9v9-w2cq-vjc2/GHSA-g9v9-w2cq-vjc2.json b/advisories/unreviewed/2025/02/GHSA-g9v9-w2cq-vjc2/GHSA-g9v9-w2cq-vjc2.json new file mode 100644 index 00000000000..6996fb89fdc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g9v9-w2cq-vjc2/GHSA-g9v9-w2cq-vjc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9v9-w2cq-vjc2", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21352" + ], + "details": "Internet Connection Sharing (ICS) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21352" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21352" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json b/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json new file mode 100644 index 00000000000..6f6e5733787 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc27-rvvm-q77r", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24415" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24415" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json b/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json new file mode 100644 index 00000000000..8c9c5c0b74e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghpr-6qhr-rpp8", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24436" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24436" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json b/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json new file mode 100644 index 00000000000..55cc0eb3bc5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjxp-46rq-wg4q", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24410" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24410" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gv9m-9fjq-vfqq/GHSA-gv9m-9fjq-vfqq.json b/advisories/unreviewed/2025/02/GHSA-gv9m-9fjq-vfqq/GHSA-gv9m-9fjq-vfqq.json new file mode 100644 index 00000000000..60bd117e075 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gv9m-9fjq-vfqq/GHSA-gv9m-9fjq-vfqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv9m-9fjq-vfqq", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2025-22467" + ], + "details": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22467" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h3rm-rvv5-pghv/GHSA-h3rm-rvv5-pghv.json b/advisories/unreviewed/2025/02/GHSA-h3rm-rvv5-pghv/GHSA-h3rm-rvv5-pghv.json new file mode 100644 index 00000000000..c7bc4a8ff0d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h3rm-rvv5-pghv/GHSA-h3rm-rvv5-pghv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3rm-rvv5-pghv", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21373" + ], + "details": "Windows Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21373" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h42c-p46c-32vf/GHSA-h42c-p46c-32vf.json b/advisories/unreviewed/2025/02/GHSA-h42c-p46c-32vf/GHSA-h42c-p46c-32vf.json new file mode 100644 index 00000000000..594f3865b29 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h42c-p46c-32vf/GHSA-h42c-p46c-32vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h42c-p46c-32vf", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21406" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21406" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21406" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h55v-j7qg-4vf6/GHSA-h55v-j7qg-4vf6.json b/advisories/unreviewed/2025/02/GHSA-h55v-j7qg-4vf6/GHSA-h55v-j7qg-4vf6.json new file mode 100644 index 00000000000..758f880391e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h55v-j7qg-4vf6/GHSA-h55v-j7qg-4vf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h55v-j7qg-4vf6", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-52968" + ], + "details": "An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52968" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json b/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json new file mode 100644 index 00000000000..cc64e19ff7a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6q4-jv34-9rpm", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21181" + ], + "details": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21181" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h6vc-5925-xpc3/GHSA-h6vc-5925-xpc3.json b/advisories/unreviewed/2025/02/GHSA-h6vc-5925-xpc3/GHSA-h6vc-5925-xpc3.json new file mode 100644 index 00000000000..48541195c8e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h6vc-5925-xpc3/GHSA-h6vc-5925-xpc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6vc-5925-xpc3", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21349" + ], + "details": "Windows Remote Desktop Configuration Service Tampering Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21349" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hh9v-pv5p-4675/GHSA-hh9v-pv5p-4675.json b/advisories/unreviewed/2025/02/GHSA-hh9v-pv5p-4675/GHSA-hh9v-pv5p-4675.json new file mode 100644 index 00000000000..c723cd7a2b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hh9v-pv5p-4675/GHSA-hh9v-pv5p-4675.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh9v-pv5p-4675", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21155" + ], + "details": "Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21155" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-09.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmpg-p67j-959p/GHSA-hmpg-p67j-959p.json b/advisories/unreviewed/2025/02/GHSA-hmpg-p67j-959p/GHSA-hmpg-p67j-959p.json new file mode 100644 index 00000000000..7fd244e5227 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hmpg-p67j-959p/GHSA-hmpg-p67j-959p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmpg-p67j-959p", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-40591" + ], + "details": "An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40591" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hpjc-rrq5-mqv8/GHSA-hpjc-rrq5-mqv8.json b/advisories/unreviewed/2025/02/GHSA-hpjc-rrq5-mqv8/GHSA-hpjc-rrq5-mqv8.json new file mode 100644 index 00000000000..7171b963dcf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hpjc-rrq5-mqv8/GHSA-hpjc-rrq5-mqv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpjc-rrq5-mqv8", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-52966" + ], + "details": "An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52966" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hq9p-wcjc-wqxg/GHSA-hq9p-wcjc-wqxg.json b/advisories/unreviewed/2025/02/GHSA-hq9p-wcjc-wqxg/GHSA-hq9p-wcjc-wqxg.json new file mode 100644 index 00000000000..ac5dc240d4c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hq9p-wcjc-wqxg/GHSA-hq9p-wcjc-wqxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq9p-wcjc-wqxg", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21391" + ], + "details": "Windows Storage Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21391" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hrr3-x5rf-qxxj/GHSA-hrr3-x5rf-qxxj.json b/advisories/unreviewed/2025/02/GHSA-hrr3-x5rf-qxxj/GHSA-hrr3-x5rf-qxxj.json new file mode 100644 index 00000000000..cd1fd691156 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hrr3-x5rf-qxxj/GHSA-hrr3-x5rf-qxxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrr3-x5rf-qxxj", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21254" + ], + "details": "Internet Connection Sharing (ICS) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21254" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hwfp-94f2-m6rh/GHSA-hwfp-94f2-m6rh.json b/advisories/unreviewed/2025/02/GHSA-hwfp-94f2-m6rh/GHSA-hwfp-94f2-m6rh.json new file mode 100644 index 00000000000..5aaa8bfd5da --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hwfp-94f2-m6rh/GHSA-hwfp-94f2-m6rh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwfp-94f2-m6rh", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21212" + ], + "details": "Internet Connection Sharing (ICS) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21212" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hx9v-7g8v-336c/GHSA-hx9v-7g8v-336c.json b/advisories/unreviewed/2025/02/GHSA-hx9v-7g8v-336c/GHSA-hx9v-7g8v-336c.json new file mode 100644 index 00000000000..0bb6233887d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hx9v-7g8v-336c/GHSA-hx9v-7g8v-336c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx9v-7g8v-336c", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24422" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24422" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j397-m7mx-jcv9/GHSA-j397-m7mx-jcv9.json b/advisories/unreviewed/2025/02/GHSA-j397-m7mx-jcv9/GHSA-j397-m7mx-jcv9.json index b7e9e15feb7..5e912944e2d 100644 --- a/advisories/unreviewed/2025/02/GHSA-j397-m7mx-jcv9/GHSA-j397-m7mx-jcv9.json +++ b/advisories/unreviewed/2025/02/GHSA-j397-m7mx-jcv9/GHSA-j397-m7mx-jcv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j397-m7mx-jcv9", - "modified": "2025-02-09T12:30:53Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-09T12:30:53Z", "aliases": [ "CVE-2025-21685" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race\n\nThe yt2_1380_fc_serdev_probe() function calls devm_serdev_device_open()\nbefore setting the client ops via serdev_device_set_client_ops(). This\nordering can trigger a NULL pointer dereference in the serdev controller's\nreceive_buf handler, as it assumes serdev->ops is valid when\nSERPORT_ACTIVE is set.\n\nThis is similar to the issue fixed in commit 5e700b384ec1\n(\"platform/chrome: cros_ec_uart: properly fix race condition\") where\ndevm_serdev_device_open() was called before fully initializing the\ndevice.\n\nFix the race by ensuring client ops are set before enabling the port via\ndevm_serdev_device_open().\n\nNote, serdev_device_set_baudrate() and serdev_device_set_flow_control()\ncalls should be after the devm_serdev_device_open() call.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-09T12:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-j397-w275-xjh3/GHSA-j397-w275-xjh3.json b/advisories/unreviewed/2025/02/GHSA-j397-w275-xjh3/GHSA-j397-w275-xjh3.json new file mode 100644 index 00000000000..754cd31b4dc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j397-w275-xjh3/GHSA-j397-w275-xjh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j397-w275-xjh3", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21198" + ], + "details": "Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21198" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21198" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j422-qwm6-mjwf/GHSA-j422-qwm6-mjwf.json b/advisories/unreviewed/2025/02/GHSA-j422-qwm6-mjwf/GHSA-j422-qwm6-mjwf.json new file mode 100644 index 00000000000..e8e11da4e2c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j422-qwm6-mjwf/GHSA-j422-qwm6-mjwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j422-qwm6-mjwf", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-13843" + ], + "details": "Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13843" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j5wx-x974-9cqx/GHSA-j5wx-x974-9cqx.json b/advisories/unreviewed/2025/02/GHSA-j5wx-x974-9cqx/GHSA-j5wx-x974-9cqx.json index 7bb73230a91..73aad63fb75 100644 --- a/advisories/unreviewed/2025/02/GHSA-j5wx-x974-9cqx/GHSA-j5wx-x974-9cqx.json +++ b/advisories/unreviewed/2025/02/GHSA-j5wx-x974-9cqx/GHSA-j5wx-x974-9cqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5wx-x974-9cqx", - "modified": "2025-02-07T12:31:19Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-07T12:31:19Z", "aliases": [ "CVE-2025-25168" diff --git a/advisories/unreviewed/2025/02/GHSA-j648-pq8h-2wmc/GHSA-j648-pq8h-2wmc.json b/advisories/unreviewed/2025/02/GHSA-j648-pq8h-2wmc/GHSA-j648-pq8h-2wmc.json new file mode 100644 index 00000000000..cf9f9833cb4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j648-pq8h-2wmc/GHSA-j648-pq8h-2wmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j648-pq8h-2wmc", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21414" + ], + "details": "Windows Core Messaging Elevation of Privileges Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21414" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21414" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j69f-cppg-2jx6/GHSA-j69f-cppg-2jx6.json b/advisories/unreviewed/2025/02/GHSA-j69f-cppg-2jx6/GHSA-j69f-cppg-2jx6.json new file mode 100644 index 00000000000..fff75744dda --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j69f-cppg-2jx6/GHSA-j69f-cppg-2jx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69f-cppg-2jx6", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24039" + ], + "details": "Visual Studio Code Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24039" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jfhj-4777-rw55/GHSA-jfhj-4777-rw55.json b/advisories/unreviewed/2025/02/GHSA-jfhj-4777-rw55/GHSA-jfhj-4777-rw55.json new file mode 100644 index 00000000000..80c96e8a46b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jfhj-4777-rw55/GHSA-jfhj-4777-rw55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfhj-4777-rw55", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21397" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21397" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jgrg-xx2q-5xgc/GHSA-jgrg-xx2q-5xgc.json b/advisories/unreviewed/2025/02/GHSA-jgrg-xx2q-5xgc/GHSA-jgrg-xx2q-5xgc.json new file mode 100644 index 00000000000..8f13d3e3115 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jgrg-xx2q-5xgc/GHSA-jgrg-xx2q-5xgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgrg-xx2q-5xgc", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-47908" + ], + "details": "OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47908" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jrp8-vq3h-w34w/GHSA-jrp8-vq3h-w34w.json b/advisories/unreviewed/2025/02/GHSA-jrp8-vq3h-w34w/GHSA-jrp8-vq3h-w34w.json index b67605df3a8..faa3c05f40f 100644 --- a/advisories/unreviewed/2025/02/GHSA-jrp8-vq3h-w34w/GHSA-jrp8-vq3h-w34w.json +++ b/advisories/unreviewed/2025/02/GHSA-jrp8-vq3h-w34w/GHSA-jrp8-vq3h-w34w.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-552" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-m36r-2732-xm94/GHSA-m36r-2732-xm94.json b/advisories/unreviewed/2025/02/GHSA-m36r-2732-xm94/GHSA-m36r-2732-xm94.json new file mode 100644 index 00000000000..9c44a7f77f8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m36r-2732-xm94/GHSA-m36r-2732-xm94.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m36r-2732-xm94", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21159" + ], + "details": "Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21159" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb25-11.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m38j-r6w7-c465/GHSA-m38j-r6w7-c465.json b/advisories/unreviewed/2025/02/GHSA-m38j-r6w7-c465/GHSA-m38j-r6w7-c465.json new file mode 100644 index 00000000000..2a7f110f600 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m38j-r6w7-c465/GHSA-m38j-r6w7-c465.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m38j-r6w7-c465", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21125" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21125" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json b/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json new file mode 100644 index 00000000000..14f739051d0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4rg-mpp2-97px", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24412" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24412" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json b/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json index 39445b5d6c7..da04cc8fafa 100644 --- a/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json +++ b/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4w5-f9xf-8fgr", - "modified": "2025-02-09T12:30:53Z", + "modified": "2025-02-11T18:31:33Z", "published": "2025-02-09T12:30:53Z", "aliases": [ "CVE-2025-21684" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: xilinx: Convert gpio_lock to raw spinlock\n\nirq_chip functions may be called in raw spinlock context. Therefore, we\nmust also use a raw spinlock for our own internal locking.\n\nThis fixes the following lockdep splat:\n\n[ 5.349336] =============================\n[ 5.353349] [ BUG: Invalid wait context ]\n[ 5.357361] 6.13.0-rc5+ #69 Tainted: G W\n[ 5.363031] -----------------------------\n[ 5.367045] kworker/u17:1/44 is trying to lock:\n[ 5.371587] ffffff88018b02c0 (&chip->gpio_lock){....}-{3:3}, at: xgpio_irq_unmask (drivers/gpio/gpio-xilinx.c:433 (discriminator 8))\n[ 5.380079] other info that might help us debug this:\n[ 5.385138] context-{5:5}\n[ 5.387762] 5 locks held by kworker/u17:1/44:\n[ 5.392123] #0: ffffff8800014958 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work (kernel/workqueue.c:3204)\n[ 5.402260] #1: ffffffc082fcbdd8 (deferred_probe_work){+.+.}-{0:0}, at: process_one_work (kernel/workqueue.c:3205)\n[ 5.411528] #2: ffffff880172c900 (&dev->mutex){....}-{4:4}, at: __device_attach (drivers/base/dd.c:1006)\n[ 5.419929] #3: ffffff88039c8268 (request_class#2){+.+.}-{4:4}, at: __setup_irq (kernel/irq/internals.h:156 kernel/irq/manage.c:1596)\n[ 5.428331] #4: ffffff88039c80c8 (lock_class#2){....}-{2:2}, at: __setup_irq (kernel/irq/manage.c:1614)\n[ 5.436472] stack backtrace:\n[ 5.439359] CPU: 2 UID: 0 PID: 44 Comm: kworker/u17:1 Tainted: G W 6.13.0-rc5+ #69\n[ 5.448690] Tainted: [W]=WARN\n[ 5.451656] Hardware name: xlnx,zynqmp (DT)\n[ 5.455845] Workqueue: events_unbound deferred_probe_work_func\n[ 5.461699] Call trace:\n[ 5.464147] show_stack+0x18/0x24 C\n[ 5.467821] dump_stack_lvl (lib/dump_stack.c:123)\n[ 5.471501] dump_stack (lib/dump_stack.c:130)\n[ 5.474824] __lock_acquire (kernel/locking/lockdep.c:4828 kernel/locking/lockdep.c:4898 kernel/locking/lockdep.c:5176)\n[ 5.478758] lock_acquire (arch/arm64/include/asm/percpu.h:40 kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5851 kernel/locking/lockdep.c:5814)\n[ 5.482429] _raw_spin_lock_irqsave (include/linux/spinlock_api_smp.h:111 kernel/locking/spinlock.c:162)\n[ 5.486797] xgpio_irq_unmask (drivers/gpio/gpio-xilinx.c:433 (discriminator 8))\n[ 5.490737] irq_enable (kernel/irq/internals.h:236 kernel/irq/chip.c:170 kernel/irq/chip.c:439 kernel/irq/chip.c:432 kernel/irq/chip.c:345)\n[ 5.494060] __irq_startup (kernel/irq/internals.h:241 kernel/irq/chip.c:180 kernel/irq/chip.c:250)\n[ 5.497645] irq_startup (kernel/irq/chip.c:270)\n[ 5.501143] __setup_irq (kernel/irq/manage.c:1807)\n[ 5.504728] request_threaded_irq (kernel/irq/manage.c:2208)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-09T12:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m6q5-p4cr-h7fh/GHSA-m6q5-p4cr-h7fh.json b/advisories/unreviewed/2025/02/GHSA-m6q5-p4cr-h7fh/GHSA-m6q5-p4cr-h7fh.json new file mode 100644 index 00000000000..c5f9f98b568 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m6q5-p4cr-h7fh/GHSA-m6q5-p4cr-h7fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6q5-p4cr-h7fh", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24036" + ], + "details": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24036" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24036" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m9qp-v432-82vj/GHSA-m9qp-v432-82vj.json b/advisories/unreviewed/2025/02/GHSA-m9qp-v432-82vj/GHSA-m9qp-v432-82vj.json new file mode 100644 index 00000000000..d235cff2744 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m9qp-v432-82vj/GHSA-m9qp-v432-82vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9qp-v432-82vj", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21126" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21126" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mfvh-6rjh-8jrp/GHSA-mfvh-6rjh-8jrp.json b/advisories/unreviewed/2025/02/GHSA-mfvh-6rjh-8jrp/GHSA-mfvh-6rjh-8jrp.json new file mode 100644 index 00000000000..cfb31df7100 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mfvh-6rjh-8jrp/GHSA-mfvh-6rjh-8jrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfvh-6rjh-8jrp", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-12756" + ], + "details": "An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12756" + }, + { + "type": "WEB", + "url": "https://support.avaya.com/css/public/documents/101091836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mhwv-rjc9-g3g8/GHSA-mhwv-rjc9-g3g8.json b/advisories/unreviewed/2025/02/GHSA-mhwv-rjc9-g3g8/GHSA-mhwv-rjc9-g3g8.json new file mode 100644 index 00000000000..ac0a65bbe7c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mhwv-rjc9-g3g8/GHSA-mhwv-rjc9-g3g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhwv-rjc9-g3g8", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21377" + ], + "details": "NTLM Hash Disclosure Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21377" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json b/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json new file mode 100644 index 00000000000..2c52c7f9b63 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm87-rrqx-94cr", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24428" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24428" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p59c-xgjv-wj3r/GHSA-p59c-xgjv-wj3r.json b/advisories/unreviewed/2025/02/GHSA-p59c-xgjv-wj3r/GHSA-p59c-xgjv-wj3r.json new file mode 100644 index 00000000000..2e44084f202 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p59c-xgjv-wj3r/GHSA-p59c-xgjv-wj3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p59c-xgjv-wj3r", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21358" + ], + "details": "Windows Core Messaging Elevation of Privileges Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21358" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21358" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p59f-4xmh-83r9/GHSA-p59f-4xmh-83r9.json b/advisories/unreviewed/2025/02/GHSA-p59f-4xmh-83r9/GHSA-p59f-4xmh-83r9.json new file mode 100644 index 00000000000..06c292759c0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p59f-4xmh-83r9/GHSA-p59f-4xmh-83r9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p59f-4xmh-83r9", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21163" + ], + "details": "Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21163" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb25-11.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p76j-345f-qxpw/GHSA-p76j-345f-qxpw.json b/advisories/unreviewed/2025/02/GHSA-p76j-345f-qxpw/GHSA-p76j-345f-qxpw.json index 277461e83aa..fef3d06f124 100644 --- a/advisories/unreviewed/2025/02/GHSA-p76j-345f-qxpw/GHSA-p76j-345f-qxpw.json +++ b/advisories/unreviewed/2025/02/GHSA-p76j-345f-qxpw/GHSA-p76j-345f-qxpw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-648" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json b/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json new file mode 100644 index 00000000000..52d7edda128 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p87j-c6xv-g28x", + "modified": "2025-02-11T18:31:43Z", + "published": "2025-02-11T18:31:43Z", + "aliases": [ + "CVE-2025-26494" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26494" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=001534936&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pv9c-fcpr-29jv/GHSA-pv9c-fcpr-29jv.json b/advisories/unreviewed/2025/02/GHSA-pv9c-fcpr-29jv/GHSA-pv9c-fcpr-29jv.json new file mode 100644 index 00000000000..d54a119e515 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pv9c-fcpr-29jv/GHSA-pv9c-fcpr-29jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv9c-fcpr-29jv", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21375" + ], + "details": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21375" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pw45-vmfj-8r3j/GHSA-pw45-vmfj-8r3j.json b/advisories/unreviewed/2025/02/GHSA-pw45-vmfj-8r3j/GHSA-pw45-vmfj-8r3j.json new file mode 100644 index 00000000000..35a2d2ea085 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pw45-vmfj-8r3j/GHSA-pw45-vmfj-8r3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw45-vmfj-8r3j", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21407" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21407" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21407" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pwj5-gqjx-3gmw/GHSA-pwj5-gqjx-3gmw.json b/advisories/unreviewed/2025/02/GHSA-pwj5-gqjx-3gmw/GHSA-pwj5-gqjx-3gmw.json new file mode 100644 index 00000000000..296a5658fed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pwj5-gqjx-3gmw/GHSA-pwj5-gqjx-3gmw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwj5-gqjx-3gmw", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21387" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21387" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q2q4-vx5m-7xc9/GHSA-q2q4-vx5m-7xc9.json b/advisories/unreviewed/2025/02/GHSA-q2q4-vx5m-7xc9/GHSA-q2q4-vx5m-7xc9.json new file mode 100644 index 00000000000..e4e88c1e665 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q2q4-vx5m-7xc9/GHSA-q2q4-vx5m-7xc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2q4-vx5m-7xc9", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21156" + ], + "details": "InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21156" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/incopy/apsb25-10.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q4gc-pf54-76jm/GHSA-q4gc-pf54-76jm.json b/advisories/unreviewed/2025/02/GHSA-q4gc-pf54-76jm/GHSA-q4gc-pf54-76jm.json new file mode 100644 index 00000000000..932227c335b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q4gc-pf54-76jm/GHSA-q4gc-pf54-76jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4gc-pf54-76jm", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21410" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21410" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q799-96gw-fjvp/GHSA-q799-96gw-fjvp.json b/advisories/unreviewed/2025/02/GHSA-q799-96gw-fjvp/GHSA-q799-96gw-fjvp.json new file mode 100644 index 00000000000..d6afc518a61 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q799-96gw-fjvp/GHSA-q799-96gw-fjvp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q799-96gw-fjvp", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2019-15002" + ], + "details": "An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15002" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/JRASERVER-67979" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qr28-8qqx-q5pp/GHSA-qr28-8qqx-q5pp.json b/advisories/unreviewed/2025/02/GHSA-qr28-8qqx-q5pp/GHSA-qr28-8qqx-q5pp.json new file mode 100644 index 00000000000..a3f5ebbcbdb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qr28-8qqx-q5pp/GHSA-qr28-8qqx-q5pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr28-8qqx-q5pp", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21371" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21371" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qrh7-h2p9-g6jx/GHSA-qrh7-h2p9-g6jx.json b/advisories/unreviewed/2025/02/GHSA-qrh7-h2p9-g6jx/GHSA-qrh7-h2p9-g6jx.json new file mode 100644 index 00000000000..f1eebf6731b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qrh7-h2p9-g6jx/GHSA-qrh7-h2p9-g6jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrh7-h2p9-g6jx", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21392" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21392" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r5g9-gp44-29h8/GHSA-r5g9-gp44-29h8.json b/advisories/unreviewed/2025/02/GHSA-r5g9-gp44-29h8/GHSA-r5g9-gp44-29h8.json new file mode 100644 index 00000000000..0d2bc08da1e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r5g9-gp44-29h8/GHSA-r5g9-gp44-29h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5g9-gp44-29h8", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-27780" + ], + "details": "Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27780" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-324" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r7mf-p426-hpwr/GHSA-r7mf-p426-hpwr.json b/advisories/unreviewed/2025/02/GHSA-r7mf-p426-hpwr/GHSA-r7mf-p426-hpwr.json new file mode 100644 index 00000000000..5b6870efd96 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r7mf-p426-hpwr/GHSA-r7mf-p426-hpwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7mf-p426-hpwr", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21367" + ], + "details": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21367" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21367" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rg59-phq2-352q/GHSA-rg59-phq2-352q.json b/advisories/unreviewed/2025/02/GHSA-rg59-phq2-352q/GHSA-rg59-phq2-352q.json new file mode 100644 index 00000000000..5360b627c3e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rg59-phq2-352q/GHSA-rg59-phq2-352q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg59-phq2-352q", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21206" + ], + "details": "Visual Studio Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21206" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21206" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json b/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json new file mode 100644 index 00000000000..79b72db54b8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjjw-g6hw-7pc9", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24416" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24416" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rmg9-p599-jx65/GHSA-rmg9-p599-jx65.json b/advisories/unreviewed/2025/02/GHSA-rmg9-p599-jx65/GHSA-rmg9-p599-jx65.json new file mode 100644 index 00000000000..4b6d5039504 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rmg9-p599-jx65/GHSA-rmg9-p599-jx65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmg9-p599-jx65", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21179" + ], + "details": "DHCP Client Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21179" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rmvc-x4jp-8q6j/GHSA-rmvc-x4jp-8q6j.json b/advisories/unreviewed/2025/02/GHSA-rmvc-x4jp-8q6j/GHSA-rmvc-x4jp-8q6j.json new file mode 100644 index 00000000000..f550088e1d1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rmvc-x4jp-8q6j/GHSA-rmvc-x4jp-8q6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmvc-x4jp-8q6j", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21419" + ], + "details": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21419" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21419" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json b/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json new file mode 100644 index 00000000000..d6e8d1a3f0c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp3f-whm7-36hq", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-24472" + ], + "details": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24472" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-535" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rv23-p9fw-xgww/GHSA-rv23-p9fw-xgww.json b/advisories/unreviewed/2025/02/GHSA-rv23-p9fw-xgww/GHSA-rv23-p9fw-xgww.json new file mode 100644 index 00000000000..d2c8e2b3c07 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rv23-p9fw-xgww/GHSA-rv23-p9fw-xgww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv23-p9fw-xgww", + "modified": "2025-02-11T18:31:39Z", + "published": "2025-02-11T18:31:39Z", + "aliases": [ + "CVE-2025-21381" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21381" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21381" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rxc7-mfvv-r2xp/GHSA-rxc7-mfvv-r2xp.json b/advisories/unreviewed/2025/02/GHSA-rxc7-mfvv-r2xp/GHSA-rxc7-mfvv-r2xp.json new file mode 100644 index 00000000000..997cefb2985 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rxc7-mfvv-r2xp/GHSA-rxc7-mfvv-r2xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxc7-mfvv-r2xp", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21188" + ], + "details": "Azure Network Watcher VM Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21188" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v3hq-g424-5mgg/GHSA-v3hq-g424-5mgg.json b/advisories/unreviewed/2025/02/GHSA-v3hq-g424-5mgg/GHSA-v3hq-g424-5mgg.json new file mode 100644 index 00000000000..aeafb3fad47 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v3hq-g424-5mgg/GHSA-v3hq-g424-5mgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3hq-g424-5mgg", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24427" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24427" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v3vc-6qcv-4vrx/GHSA-v3vc-6qcv-4vrx.json b/advisories/unreviewed/2025/02/GHSA-v3vc-6qcv-4vrx/GHSA-v3vc-6qcv-4vrx.json new file mode 100644 index 00000000000..5e4431ff974 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v3vc-6qcv-4vrx/GHSA-v3vc-6qcv-4vrx.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3vc-6qcv-4vrx", + "modified": "2025-02-11T18:31:20Z", + "published": "2025-02-11T18:31:20Z", + "aliases": [ + "CVE-2024-52067" + ], + "details": "Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context values may contain sensitive information depending on application flow configuration. Deployments of Apache NiFi with the default Logback configuration do not log Parameter Context values. Upgrading to Apache NiFi 2.0.0 or 1.28.1 is the recommendation mitigation, eliminating Parameter value logging from the flow synchronization process regardless of the Logback configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52067" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/9rz5rwn2zc7pfjq7ppqldqlc067tlcwd" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/20/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v6r2-425c-hfrr/GHSA-v6r2-425c-hfrr.json b/advisories/unreviewed/2025/02/GHSA-v6r2-425c-hfrr/GHSA-v6r2-425c-hfrr.json new file mode 100644 index 00000000000..0c3cfa2ded4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v6r2-425c-hfrr/GHSA-v6r2-425c-hfrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6r2-425c-hfrr", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24421" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24421" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vcgf-xx3m-26h2/GHSA-vcgf-xx3m-26h2.json b/advisories/unreviewed/2025/02/GHSA-vcgf-xx3m-26h2/GHSA-vcgf-xx3m-26h2.json new file mode 100644 index 00000000000..238151e4384 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vcgf-xx3m-26h2/GHSA-vcgf-xx3m-26h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcgf-xx3m-26h2", + "modified": "2025-02-11T18:31:34Z", + "published": "2025-02-11T18:31:34Z", + "aliases": [ + "CVE-2024-13830" + ], + "details": "Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13830" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vhgc-fh4x-7wpx/GHSA-vhgc-fh4x-7wpx.json b/advisories/unreviewed/2025/02/GHSA-vhgc-fh4x-7wpx/GHSA-vhgc-fh4x-7wpx.json new file mode 100644 index 00000000000..5403fb0bea5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vhgc-fh4x-7wpx/GHSA-vhgc-fh4x-7wpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhgc-fh4x-7wpx", + "modified": "2025-02-11T18:31:40Z", + "published": "2025-02-11T18:31:40Z", + "aliases": [ + "CVE-2025-21390" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21390" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vw47-79jv-3598/GHSA-vw47-79jv-3598.json b/advisories/unreviewed/2025/02/GHSA-vw47-79jv-3598/GHSA-vw47-79jv-3598.json new file mode 100644 index 00000000000..5685392e7e2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vw47-79jv-3598/GHSA-vw47-79jv-3598.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw47-79jv-3598", + "modified": "2025-02-11T18:31:41Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24409" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24409" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w484-vhrp-5qfc/GHSA-w484-vhrp-5qfc.json b/advisories/unreviewed/2025/02/GHSA-w484-vhrp-5qfc/GHSA-w484-vhrp-5qfc.json new file mode 100644 index 00000000000..4ff9b96a4d3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w484-vhrp-5qfc/GHSA-w484-vhrp-5qfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w484-vhrp-5qfc", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21124" + ], + "details": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21124" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wq6m-8j35-4r2x/GHSA-wq6m-8j35-4r2x.json b/advisories/unreviewed/2025/02/GHSA-wq6m-8j35-4r2x/GHSA-wq6m-8j35-4r2x.json new file mode 100644 index 00000000000..102f448aa28 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wq6m-8j35-4r2x/GHSA-wq6m-8j35-4r2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq6m-8j35-4r2x", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21194" + ], + "details": "Microsoft Surface Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21194" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21194" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wr7v-68p8-38hw/GHSA-wr7v-68p8-38hw.json b/advisories/unreviewed/2025/02/GHSA-wr7v-68p8-38hw/GHSA-wr7v-68p8-38hw.json new file mode 100644 index 00000000000..01eff5f3659 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wr7v-68p8-38hw/GHSA-wr7v-68p8-38hw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr7v-68p8-38hw", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-22399" + ], + "details": "Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22399" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x2mr-xj96-pc8h/GHSA-x2mr-xj96-pc8h.json b/advisories/unreviewed/2025/02/GHSA-x2mr-xj96-pc8h/GHSA-x2mr-xj96-pc8h.json new file mode 100644 index 00000000000..4dcd740813d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x2mr-xj96-pc8h/GHSA-x2mr-xj96-pc8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2mr-xj96-pc8h", + "modified": "2025-02-11T18:31:37Z", + "published": "2025-02-11T18:31:37Z", + "aliases": [ + "CVE-2025-21216" + ], + "details": "Internet Connection Sharing (ICS) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21216" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x3ph-6h66-2jm6/GHSA-x3ph-6h66-2jm6.json b/advisories/unreviewed/2025/02/GHSA-x3ph-6h66-2jm6/GHSA-x3ph-6h66-2jm6.json new file mode 100644 index 00000000000..11795a3fbbe --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x3ph-6h66-2jm6/GHSA-x3ph-6h66-2jm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3ph-6h66-2jm6", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21350" + ], + "details": "Windows Kerberos Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21350" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x4fg-9w66-gccf/GHSA-x4fg-9w66-gccf.json b/advisories/unreviewed/2025/02/GHSA-x4fg-9w66-gccf/GHSA-x4fg-9w66-gccf.json new file mode 100644 index 00000000000..b814a4f5652 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x4fg-9w66-gccf/GHSA-x4fg-9w66-gccf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4fg-9w66-gccf", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2025-21161" + ], + "details": "Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21161" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-12.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x763-rwjp-4g28/GHSA-x763-rwjp-4g28.json b/advisories/unreviewed/2025/02/GHSA-x763-rwjp-4g28/GHSA-x763-rwjp-4g28.json new file mode 100644 index 00000000000..fab418f8b40 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x763-rwjp-4g28/GHSA-x763-rwjp-4g28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x763-rwjp-4g28", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-40584" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40584" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x7j3-3mr3-jq5q/GHSA-x7j3-3mr3-jq5q.json b/advisories/unreviewed/2025/02/GHSA-x7j3-3mr3-jq5q/GHSA-x7j3-3mr3-jq5q.json new file mode 100644 index 00000000000..ecc80b45bcc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x7j3-3mr3-jq5q/GHSA-x7j3-3mr3-jq5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7j3-3mr3-jq5q", + "modified": "2025-02-11T18:31:35Z", + "published": "2025-02-11T18:31:35Z", + "aliases": [ + "CVE-2024-50569" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50569" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-438" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xh69-9jx5-xgph/GHSA-xh69-9jx5-xgph.json b/advisories/unreviewed/2025/02/GHSA-xh69-9jx5-xgph/GHSA-xh69-9jx5-xgph.json new file mode 100644 index 00000000000..7826a408921 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xh69-9jx5-xgph/GHSA-xh69-9jx5-xgph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh69-9jx5-xgph", + "modified": "2025-02-11T18:31:38Z", + "published": "2025-02-11T18:31:38Z", + "aliases": [ + "CVE-2025-21351" + ], + "details": "Windows Active Directory Domain Services API Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21351" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21351" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xm77-xqp2-qhcp/GHSA-xm77-xqp2-qhcp.json b/advisories/unreviewed/2025/02/GHSA-xm77-xqp2-qhcp/GHSA-xm77-xqp2-qhcp.json new file mode 100644 index 00000000000..8e5875fc23c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xm77-xqp2-qhcp/GHSA-xm77-xqp2-qhcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm77-xqp2-qhcp", + "modified": "2025-02-11T18:31:36Z", + "published": "2025-02-11T18:31:36Z", + "aliases": [ + "CVE-2025-21162" + ], + "details": "Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21162" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop_elements/apsb25-13.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-379" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json b/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json new file mode 100644 index 00000000000..68982bbb733 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwgx-8v72-4j5j", + "modified": "2025-02-11T18:31:42Z", + "published": "2025-02-11T18:31:41Z", + "aliases": [ + "CVE-2025-24413" + ], + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24413" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T18:15:42Z" + } +} \ No newline at end of file