diff --git a/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json b/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json index e33659a1915..8eee40d5c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json +++ b/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-782f-h7v4-m7wc", - "modified": "2022-05-13T01:32:10Z", + "modified": "2025-01-28T00:32:06Z", "published": "2022-05-13T01:32:10Z", "aliases": [ "CVE-2018-5430" diff --git a/advisories/unreviewed/2022/05/GHSA-cmgc-v5fc-wx68/GHSA-cmgc-v5fc-wx68.json b/advisories/unreviewed/2022/05/GHSA-cmgc-v5fc-wx68/GHSA-cmgc-v5fc-wx68.json index 974b758e9cc..667e0ba3951 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmgc-v5fc-wx68/GHSA-cmgc-v5fc-wx68.json +++ b/advisories/unreviewed/2022/05/GHSA-cmgc-v5fc-wx68/GHSA-cmgc-v5fc-wx68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmgc-v5fc-wx68", - "modified": "2022-05-14T03:09:02Z", + "modified": "2025-01-28T00:32:06Z", "published": "2022-05-14T03:09:02Z", "aliases": [ "CVE-2016-9079" diff --git a/advisories/unreviewed/2022/05/GHSA-cw7c-4r65-xf9h/GHSA-cw7c-4r65-xf9h.json b/advisories/unreviewed/2022/05/GHSA-cw7c-4r65-xf9h/GHSA-cw7c-4r65-xf9h.json index da31e5a8042..bffd2dec50c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw7c-4r65-xf9h/GHSA-cw7c-4r65-xf9h.json +++ b/advisories/unreviewed/2022/05/GHSA-cw7c-4r65-xf9h/GHSA-cw7c-4r65-xf9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw7c-4r65-xf9h", - "modified": "2022-05-13T01:20:24Z", + "modified": "2025-01-28T00:32:07Z", "published": "2022-05-13T01:20:24Z", "aliases": [ "CVE-2018-6065" @@ -50,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-h2mj-pqgp-xmmj/GHSA-h2mj-pqgp-xmmj.json b/advisories/unreviewed/2022/05/GHSA-h2mj-pqgp-xmmj/GHSA-h2mj-pqgp-xmmj.json index bed4ff435ce..d02fe9b6c31 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2mj-pqgp-xmmj/GHSA-h2mj-pqgp-xmmj.json +++ b/advisories/unreviewed/2022/05/GHSA-h2mj-pqgp-xmmj/GHSA-h2mj-pqgp-xmmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2mj-pqgp-xmmj", - "modified": "2022-05-13T01:17:37Z", + "modified": "2025-01-28T00:32:06Z", "published": "2022-05-13T01:17:37Z", "aliases": [ "CVE-2018-0296" diff --git a/advisories/unreviewed/2022/05/GHSA-rvjq-qp5f-gvx6/GHSA-rvjq-qp5f-gvx6.json b/advisories/unreviewed/2022/05/GHSA-rvjq-qp5f-gvx6/GHSA-rvjq-qp5f-gvx6.json index 7cd8177e493..98d58104db7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvjq-qp5f-gvx6/GHSA-rvjq-qp5f-gvx6.json +++ b/advisories/unreviewed/2022/05/GHSA-rvjq-qp5f-gvx6/GHSA-rvjq-qp5f-gvx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvjq-qp5f-gvx6", - "modified": "2022-05-13T01:53:14Z", + "modified": "2025-01-28T00:32:06Z", "published": "2022-05-13T01:53:14Z", "aliases": [ "CVE-2018-6961" diff --git a/advisories/unreviewed/2023/10/GHSA-9h42-3pgf-qjc8/GHSA-9h42-3pgf-qjc8.json b/advisories/unreviewed/2023/10/GHSA-9h42-3pgf-qjc8/GHSA-9h42-3pgf-qjc8.json index 2d6bd813bc2..0634499ec5f 100644 --- a/advisories/unreviewed/2023/10/GHSA-9h42-3pgf-qjc8/GHSA-9h42-3pgf-qjc8.json +++ b/advisories/unreviewed/2023/10/GHSA-9h42-3pgf-qjc8/GHSA-9h42-3pgf-qjc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h42-3pgf-qjc8", - "modified": "2023-11-16T03:30:20Z", + "modified": "2025-01-28T00:32:08Z", "published": "2023-10-26T21:30:22Z", "aliases": [ "CVE-2023-46748" diff --git a/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json b/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json index 26569916d3e..26836d4ebaa 100644 --- a/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json +++ b/advisories/unreviewed/2023/10/GHSA-pq6p-fc96-wc5w/GHSA-pq6p-fc96-wc5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq6p-fc96-wc5w", - "modified": "2024-02-01T03:30:22Z", + "modified": "2025-01-28T00:32:08Z", "published": "2023-10-26T21:30:22Z", "aliases": [ "CVE-2023-46747" diff --git a/advisories/unreviewed/2023/10/GHSA-qf8f-27cp-gw76/GHSA-qf8f-27cp-gw76.json b/advisories/unreviewed/2023/10/GHSA-qf8f-27cp-gw76/GHSA-qf8f-27cp-gw76.json index 12ee6aff1bd..459dd8ad44d 100644 --- a/advisories/unreviewed/2023/10/GHSA-qf8f-27cp-gw76/GHSA-qf8f-27cp-gw76.json +++ b/advisories/unreviewed/2023/10/GHSA-qf8f-27cp-gw76/GHSA-qf8f-27cp-gw76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf8f-27cp-gw76", - "modified": "2023-11-01T06:30:20Z", + "modified": "2025-01-28T00:32:07Z", "published": "2023-10-18T15:30:24Z", "aliases": [ "CVE-2023-5631" diff --git a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json index 7611316b04a..a4e0016e591 100644 --- a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json +++ b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3c85-mx4x-435c", - "modified": "2024-05-05T15:30:28Z", + "modified": "2025-01-28T00:32:12Z", "published": "2023-12-25T00:30:17Z", "aliases": [ "CVE-2023-7101" diff --git a/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json b/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json index 2b71ca962e4..700fc3aa4e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json +++ b/advisories/unreviewed/2024/05/GHSA-cw5c-xm7f-wx63/GHSA-cw5c-xm7f-wx63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw5c-xm7f-wx63", - "modified": "2024-06-07T18:30:37Z", + "modified": "2025-01-28T00:32:12Z", "published": "2024-05-31T12:30:49Z", "aliases": [ "CVE-2024-23692" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://vulncheck.com/advisories/rejetto-unauth-rce" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/unauthenticated-rce-flaw-in-rejetto-http-file-server-cve-2024-23692" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-wf54-f8v9-v72v/GHSA-wf54-f8v9-v72v.json b/advisories/unreviewed/2024/05/GHSA-wf54-f8v9-v72v/GHSA-wf54-f8v9-v72v.json index 06e414d481a..c187a5cfacd 100644 --- a/advisories/unreviewed/2024/05/GHSA-wf54-f8v9-v72v/GHSA-wf54-f8v9-v72v.json +++ b/advisories/unreviewed/2024/05/GHSA-wf54-f8v9-v72v/GHSA-wf54-f8v9-v72v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf54-f8v9-v72v", - "modified": "2024-05-23T03:30:41Z", + "modified": "2025-01-28T00:32:12Z", "published": "2024-05-23T03:30:41Z", "aliases": [ "CVE-2024-4978" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -22,11 +26,20 @@ { "type": "WEB", "url": "https://twitter.com/2RunJack2/status/1775052981966377148" + }, + { + "type": "WEB", + "url": "https://www.javs.com/downloads" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack" } ], "database_specific": { "cwe_ids": [ - "CWE-502" + "CWE-502", + "CWE-506" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json b/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json index e62960fbd32..39ae2e3992c 100644 --- a/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json +++ b/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78v4-hxhf-xqqv", - "modified": "2024-09-10T18:30:45Z", + "modified": "2025-01-28T00:32:12Z", "published": "2024-09-10T18:30:45Z", "aliases": [ "CVE-2024-38217" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/security-labs/dismantling-smart-app-control" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json index fe739b98f10..ae2a5c8b283 100644 --- a/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json +++ b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvx5-3q3c-pr6w", - "modified": "2024-09-10T18:30:45Z", + "modified": "2025-01-28T00:32:12Z", "published": "2024-09-10T18:30:45Z", "aliases": [ "CVE-2024-38014" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Sep/43" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json b/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json new file mode 100644 index 00000000000..90a8870459a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23h2-xx79-4xwr", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24145" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. An app may be able to view a contact's phone number in system logs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24145" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json new file mode 100644 index 00000000000..15bf3ea0e4b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23h9-xj7q-3m7r", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24143" + ], + "details": "The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24143" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json b/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json new file mode 100644 index 00000000000..217e0c9b862 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-25gv-4h88-97v2/GHSA-25gv-4h88-97v2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25gv-4h88-97v2", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54520" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54520" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json b/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json index 6b2fd9289bf..8d00edc8f57 100644 --- a/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json +++ b/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2f5q-2vvh-mm3g", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T00:32:13Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37011" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json new file mode 100644 index 00000000000..677f84a3668 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f87-7wqp-6j6j", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24127" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24127" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json b/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json new file mode 100644 index 00000000000..ca3fea67e88 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gv2-58w9-6q94/GHSA-2gv2-58w9-6q94.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gv2-58w9-6q94", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24149" + ], + "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to disclosure of user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24149" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json b/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json new file mode 100644 index 00000000000..94e844cd4d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mcv-q3q8-h36j/GHSA-2mcv-q3q8-h36j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mcv-q3q8-h36j", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24139" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24139" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json b/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json new file mode 100644 index 00000000000..0939f83be3c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qww-mx2p-2v4m", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54507" + ], + "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An attacker with user privileges may be able to read kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54507" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json b/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json new file mode 100644 index 00000000000..4bdb2006454 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2r3p-xw5g-5q9x/GHSA-2r3p-xw5g-5q9x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r3p-xw5g-5q9x", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-54728" + ], + "details": "Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54728" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xu-yanbo202000460009/00dacd7bfede713a0f052a531da4fabd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json new file mode 100644 index 00000000000..f7deddeb599 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w2w-c8f9-2jq3", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24109" + ], + "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24109" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json new file mode 100644 index 00000000000..15454a7ef49 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wm4-qgw2-r6ff", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24096" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24096" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json b/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json new file mode 100644 index 00000000000..2f8b9ca05de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xvj-j4wx-pf4c", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54541" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54541" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json b/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json new file mode 100644 index 00000000000..73a39e157ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3cjj-grfr-qr35/GHSA-3cjj-grfr-qr35.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cjj-grfr-qr35", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24122" + ], + "details": "A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24122" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json b/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json new file mode 100644 index 00000000000..3229c0ec968 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3fr9-m4cp-5gr8/GHSA-3fr9-m4cp-5gr8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fr9-m4cp-5gr8", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24101" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json b/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json new file mode 100644 index 00000000000..e0347a014f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q6v-mwhw-45h2", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24153" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24153" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json b/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json new file mode 100644 index 00000000000..5cb2dfb7f5d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3vgp-qmq6-gqh6/GHSA-3vgp-qmq6-gqh6.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vgp-qmq6-gqh6", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54468" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54468" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json new file mode 100644 index 00000000000..435a7e07ad9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-429g-77c6-6p2v", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24174" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24174" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-463x-cx2r-cx32/GHSA-463x-cx2r-cx32.json b/advisories/unreviewed/2025/01/GHSA-463x-cx2r-cx32/GHSA-463x-cx2r-cx32.json new file mode 100644 index 00000000000..c0c84965f81 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-463x-cx2r-cx32/GHSA-463x-cx2r-cx32.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-463x-cx2r-cx32", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24113" + ], + "details": "The issue was addressed with improved UI. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. Visiting a malicious website may lead to user interface spoofing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24113" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json b/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json new file mode 100644 index 00000000000..29ca490fe81 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46f6-cwr6-vh3q", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54478" + ], + "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.4, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54478" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json b/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json new file mode 100644 index 00000000000..2c647e24a29 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-46pj-m82h-8px5/GHSA-46pj-m82h-8px5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46pj-m82h-8px5", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24120" + ], + "details": "This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An attacker may be able to cause unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24120" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json b/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json new file mode 100644 index 00000000000..646a4f3fe7a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47j8-qfh2-377q", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24087" + ], + "details": "The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24087" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json new file mode 100644 index 00000000000..b7e336177e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48xq-vmgv-hxqw", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24158" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24158" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json b/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json new file mode 100644 index 00000000000..5fa5ee3f3dc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cf6-q58x-cj63/GHSA-4cf6-q58x-cj63.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cf6-q58x-cj63", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57052" + ], + "details": "An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57052" + }, + { + "type": "WEB", + "url": "https://gist.github.com/yahaha9/720fb45bbebda62dc198568c8d275df8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json b/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json new file mode 100644 index 00000000000..b8bd30df7c2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4grh-x943-5h7q/GHSA-4grh-x943-5h7q.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4grh-x943-5h7q", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24123" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24123" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json b/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json new file mode 100644 index 00000000000..191dbd986f5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qxg-mfmj-r355", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24152" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24152" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json new file mode 100644 index 00000000000..e7e91274f82 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g74-fw23-w3jp", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54550" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An app may be able to view autocompleted contact information from Messages and Mail in system logs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54550" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json b/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json new file mode 100644 index 00000000000..780485d34f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gcp-9j5g-mj5x", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54522" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54522" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json new file mode 100644 index 00000000000..af70e14c0a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h7w-p832-4g53", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54519" + ], + "details": "The issue was resolved by sanitizing logging. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54519" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json b/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json new file mode 100644 index 00000000000..64c24fe08d5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5p4f-8x2w-47pr/GHSA-5p4f-8x2w-47pr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p4f-8x2w-47pr", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24176" + ], + "details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24176" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json b/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json new file mode 100644 index 00000000000..324d14db5c3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5r86-xcpg-678m/GHSA-5r86-xcpg-678m.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r86-xcpg-678m", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54499" + ], + "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54499" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json b/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json new file mode 100644 index 00000000000..f025a20279b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-634j-pq2q-xq7j/GHSA-634j-pq2q-xq7j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-634j-pq2q-xq7j", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54537" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to read and write files outside of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54537" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json new file mode 100644 index 00000000000..5ce115dc3d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69r8-3jjv-g7rv", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24131" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker in a privileged position may be able to perform a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24131" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json b/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json new file mode 100644 index 00000000000..08341e3dfcf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6jw8-gwr2-hm7v/GHSA-6jw8-gwr2-hm7v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jw8-gwr2-hm7v", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24115" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read files outside of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24115" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json b/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json new file mode 100644 index 00000000000..b4a0f2d0f91 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6m9w-gxx9-4gqr/GHSA-6m9w-gxx9-4gqr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m9w-gxx9-4gqr", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57547" + ], + "details": "Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57547" + }, + { + "type": "WEB", + "url": "https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Remote%20Code%20Execution%20via%20backup%20file%20editing.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json b/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json new file mode 100644 index 00000000000..f040d3825e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v56-83j9-4gmj/GHSA-6v56-83j9-4gmj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v56-83j9-4gmj", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24138" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious application may be able to leak sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24138" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json new file mode 100644 index 00000000000..b38b23cf80f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xj4-vchf-pfcc", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54497" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing web content may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54497" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json b/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json new file mode 100644 index 00000000000..6c2bf4cd9a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7745-gvqx-6pp9/GHSA-7745-gvqx-6pp9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7745-gvqx-6pp9", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24128" + ], + "details": "The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24128" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json new file mode 100644 index 00000000000..f6bb018f8c5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7843-77v9-hw36", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54523" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54523" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json new file mode 100644 index 00000000000..8abed0c96b9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cw6-gq2v-qm88", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24114" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24114" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json b/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json new file mode 100644 index 00000000000..999398da5a8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7h23-57pg-3hwc/GHSA-7h23-57pg-3hwc.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h23-57pg-3hwc", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24085" + ], + "details": "A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24085" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json b/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json new file mode 100644 index 00000000000..ae78979e02b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7hx3-pw88-4928/GHSA-7hx3-pw88-4928.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hx3-pw88-4928", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24163" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24163" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json new file mode 100644 index 00000000000..a41a2e39045 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jj7-mxgf-79rv", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24162" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24162" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json b/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json new file mode 100644 index 00000000000..e4d4b68c5b0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-826g-p4h4-g7x3", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24151" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24151" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json b/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json new file mode 100644 index 00000000000..45443662f55 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86c2-r56g-p9g8", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24112" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24112" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89f4-8f7w-pp39/GHSA-89f4-8f7w-pp39.json b/advisories/unreviewed/2025/01/GHSA-89f4-8f7w-pp39/GHSA-89f4-8f7w-pp39.json new file mode 100644 index 00000000000..a2f3acfac2b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-89f4-8f7w-pp39/GHSA-89f4-8f7w-pp39.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89f4-8f7w-pp39", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24166" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24166" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json b/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json index 3a2ed8f58f6..626a0bb5040 100644 --- a/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json +++ b/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8ppx-rwm8-h7rp", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T00:32:13Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37010" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-94m6-39r7-r5v7/GHSA-94m6-39r7-r5v7.json b/advisories/unreviewed/2025/01/GHSA-94m6-39r7-r5v7/GHSA-94m6-39r7-r5v7.json new file mode 100644 index 00000000000..4f2ce6bad8c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-94m6-39r7-r5v7/GHSA-94m6-39r7-r5v7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94m6-39r7-r5v7", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2022-31749" + ], + "details": "An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31749" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2022/06/23/cve-2022-31749-watchguard-authenticated-arbitrary-file-read-write-fixed" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T00:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json b/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json new file mode 100644 index 00000000000..8f41c1d8955 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95qw-rmjg-8mx8", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54518" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54518" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json b/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json new file mode 100644 index 00000000000..ac29c5e3ee9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96fg-3259-537g/GHSA-96fg-3259-537g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96fg-3259-537g", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24118" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24118" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json b/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json new file mode 100644 index 00000000000..c5a5a68fbaa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-97mv-g3jg-wg68/GHSA-97mv-g3jg-wg68.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97mv-g3jg-wg68", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-56178" + ], + "details": "An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56178" + }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json new file mode 100644 index 00000000000..5039f29bc21 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cmh-qh3j-rrp8", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24161" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24161" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json b/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json new file mode 100644 index 00000000000..f58994dd068 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mj5-43v3-x7pj", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54517" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54517" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json b/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json new file mode 100644 index 00000000000..d6257bc4cf6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mwc-354m-hg9c", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24094" + ], + "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24094" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json new file mode 100644 index 00000000000..d1268c1fa47 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9hp-6vqm-w35v", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24116" + ], + "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24116" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json b/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json new file mode 100644 index 00000000000..6eedf7ed987 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccj6-hxrm-3g5p", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24130" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24130" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json new file mode 100644 index 00000000000..a14544a4866 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chv5-gcx2-vw99", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54475" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to determine a user’s current location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54475" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json b/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json new file mode 100644 index 00000000000..e2eb4670dcd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cj6v-hrvw-6rqm/GHSA-cj6v-hrvw-6rqm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj6v-hrvw-6rqm", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54547" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54547" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json b/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json new file mode 100644 index 00000000000..c34a9e2d394 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cjpm-qgq4-2252/GHSA-cjpm-qgq4-2252.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjpm-qgq4-2252", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24092" + ], + "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24092" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json b/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json new file mode 100644 index 00000000000..46fe9d95eaf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crm9-rr9p-qwr6", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54516" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to approve a launch daemon without user consent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54516" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json b/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json new file mode 100644 index 00000000000..e84e883e309 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f725-67x4-3v5h/GHSA-f725-67x4-3v5h.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f725-67x4-3v5h", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24124" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24124" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json b/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json new file mode 100644 index 00000000000..b222a6981b3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp5g-p2fh-5344", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54549" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54549" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fxj3-q2xx-v66g/GHSA-fxj3-q2xx-v66g.json b/advisories/unreviewed/2025/01/GHSA-fxj3-q2xx-v66g/GHSA-fxj3-q2xx-v66g.json new file mode 100644 index 00000000000..caf54568b79 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fxj3-q2xx-v66g/GHSA-fxj3-q2xx-v66g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxj3-q2xx-v66g", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-28786" + ], + "details": "IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28786" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7173420" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T00:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json b/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json new file mode 100644 index 00000000000..d00229f6ff2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggjg-gjpc-93cx", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24146" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Deleting a conversation in Messages may expose user contact information in system logging.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24146" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json b/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json new file mode 100644 index 00000000000..fa58de164eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm6v-g6wg-rpvc", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54509" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54509" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json new file mode 100644 index 00000000000..729cee24be2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvc8-8jhg-7556", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57373" + ], + "details": "Cross Site Request Forgery vulnerability in LifestyleStore v.1.0 allows a remote attacker to execute arbitrary cod and obtain sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57373" + }, + { + "type": "WEB", + "url": "https://github.com/cypherdavy/CVE-2024-57373" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json new file mode 100644 index 00000000000..4b5cfae90ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2jv-m23f-7xfh", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-44172" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3, macOS Sequoia 15. An app may be able to access contacts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44172" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121238" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json b/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json new file mode 100644 index 00000000000..02ff6f85e9a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h45h-fpr9-hqvw/GHSA-h45h-fpr9-hqvw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h45h-fpr9-hqvw", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24135" + ], + "details": "This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24135" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json b/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json new file mode 100644 index 00000000000..b53c597fc2d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h4fw-wmp3-pv59/GHSA-h4fw-wmp3-pv59.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4fw-wmp3-pv59", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-48662" + ], + "details": "Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48662" + }, + { + "type": "WEB", + "url": "https://github.com/VuDuc09/vuln_research/tree/main/CVE-2024-48662" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json b/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json new file mode 100644 index 00000000000..d5a8053adf9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h5px-98xh-rpjj/GHSA-h5px-98xh-rpjj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5px-98xh-rpjj", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24156" + ], + "details": "An integer overflow was addressed through improved input validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to elevate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24156" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json b/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json new file mode 100644 index 00000000000..9c58897ca33 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h75c-q767-27j6/GHSA-h75c-q767-27j6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h75c-q767-27j6", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57546" + ], + "details": "An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57546" + }, + { + "type": "WEB", + "url": "https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Validate%20links%20SSRF.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json b/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json new file mode 100644 index 00000000000..8b2eaeefb99 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9j3-chpr-5rjg", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24169" + ], + "details": "A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24169" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json b/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json new file mode 100644 index 00000000000..729cfe957e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfq6-5gvf-hm89", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24177" + ], + "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. A remote attacker may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24177" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json b/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json new file mode 100644 index 00000000000..615f7492406 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hrpq-69mg-72v6/GHSA-hrpq-69mg-72v6.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrpq-69mg-72v6", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54530" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, visionOS 2.2, iOS 18.2 and iPadOS 18.2. Password autofill may fill in passwords after failing authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54530" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json b/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json new file mode 100644 index 00000000000..c5905959b99 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j23p-p7c9-5hm5", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54543" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.2, tvOS 18.2, Safari 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54543" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json b/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json new file mode 100644 index 00000000000..15896ec83e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3f4-fw9x-x9c7", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54536" + ], + "details": "The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.2. An app may be able to edit NVRAM variables.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54536" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json new file mode 100644 index 00000000000..209546dca98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhf5-fj8j-2h29", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24108" + ], + "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json b/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json new file mode 100644 index 00000000000..b4a1b447a71 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc69-xrvc-fghx", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24086" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing an image may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24086" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json new file mode 100644 index 00000000000..61a63e1f210 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh68-7cw5-7m9v", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24126" + ], + "details": "An input validation issue was addressed. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker on the local network may be able to cause unexpected system termination or corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24126" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json b/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json new file mode 100644 index 00000000000..f6f59708cb8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mjmw-w38h-7mcx/GHSA-mjmw-w38h-7mcx.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmw-w38h-7mcx", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24154" + ], + "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An attacker may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24154" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json new file mode 100644 index 00000000000..ad708408480 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx5v-hjgf-32j4", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24102" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current location.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json b/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json new file mode 100644 index 00000000000..d20d126da6a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3qx-xphh-h4vv", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24100" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access information about a user's contacts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p52f-fg64-jqxw/GHSA-p52f-fg64-jqxw.json b/advisories/unreviewed/2025/01/GHSA-p52f-fg64-jqxw/GHSA-p52f-fg64-jqxw.json index 42aa50f9871..81c5b710817 100644 --- a/advisories/unreviewed/2025/01/GHSA-p52f-fg64-jqxw/GHSA-p52f-fg64-jqxw.json +++ b/advisories/unreviewed/2025/01/GHSA-p52f-fg64-jqxw/GHSA-p52f-fg64-jqxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p52f-fg64-jqxw", - "modified": "2025-01-09T18:32:15Z", + "modified": "2025-01-28T00:32:12Z", "published": "2025-01-09T18:32:15Z", "aliases": [ "CVE-2025-21600" diff --git a/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json new file mode 100644 index 00000000000..98c742d3121 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgq2-vhv9-8pr9", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54512" + ], + "details": "The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54512" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json new file mode 100644 index 00000000000..ad9116d92d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7g4-2c4x-wxxq", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54488" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sonoma 14.7.2, macOS Sequoia 15.2. Photos in the Hidden Photos Album may be viewed without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54488" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json b/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json new file mode 100644 index 00000000000..dbacbee5104 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q7qh-x2m6-6www/GHSA-q7qh-x2m6-6www.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7qh-x2m6-6www", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2025-24159" + ], + "details": "A validation issue was addressed with improved logic. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24159" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json b/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json new file mode 100644 index 00000000000..05b25471acd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q965-9jfq-2h9g", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54557" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An attacker may gain access to protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54557" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json b/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json new file mode 100644 index 00000000000..7b450d37d77 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qhxj-xhp5-9g9c/GHSA-qhxj-xhp5-9g9c.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhxj-xhp5-9g9c", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24160" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24160" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json b/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json new file mode 100644 index 00000000000..bf0bc668131 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmjg-q5x7-48p2", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24150" + ], + "details": "A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24150" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json b/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json new file mode 100644 index 00000000000..4faa44c540d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qx57-5369-xrr8/GHSA-qx57-5369-xrr8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx57-5369-xrr8", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57548" + ], + "details": "CMSimple 5.16 allows the user to edit log.php file via print page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57548" + }, + { + "type": "WEB", + "url": "https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Broken%20Access%20Control%20to%20log.php.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json b/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json new file mode 100644 index 00000000000..ca1cbd45576 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r2h5-cvfq-6cgj/GHSA-r2h5-cvfq-6cgj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2h5-cvfq-6cgj", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-57549" + ], + "details": "CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57549" + }, + { + "type": "WEB", + "url": "https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Sensitive%20information%20disclosure.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json b/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json new file mode 100644 index 00000000000..d7fd5262357 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r396-g535-84pc/GHSA-r396-g535-84pc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r396-g535-84pc", + "modified": "2025-01-28T00:32:15Z", + "published": "2025-01-28T00:32:15Z", + "aliases": [ + "CVE-2024-56316" + ], + "details": "In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of Service via crafted TR069 requests on TCP port 9675 or 7547. Rebooting does not resolve the permanent Denial of Service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56316" + }, + { + "type": "WEB", + "url": "https://www.y-security.de/news-en/axess-auto-configuration-server-denial-of-service-cve-2024-56316" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json b/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json index d1587c12a72..c58b6aff81e 100644 --- a/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json +++ b/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r492-f75w-fpq9", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-28T00:32:13Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2023-37009" ], "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json b/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json new file mode 100644 index 00000000000..a867eca3743 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr66-34m4-m7ww", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54539" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to capture keyboard events from the lock screen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54539" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121842" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json b/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json new file mode 100644 index 00000000000..5b80fdae530 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrg9-j69g-xfm7/GHSA-rrg9-j69g-xfm7.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrg9-j69g-xfm7", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24137" + ], + "details": "A type confusion issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected application termination or arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24137" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json b/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json new file mode 100644 index 00000000000..b70ce9ca08a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4x5-wpx5-pqc5", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24107" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3 and iPadOS 18.3. A malicious app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json b/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json new file mode 100644 index 00000000000..f9509986760 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v87f-3m66-pc8x/GHSA-v87f-3m66-pc8x.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v87f-3m66-pc8x", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24129" + ], + "details": "A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24129" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json b/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json new file mode 100644 index 00000000000..bbd68ee427f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vv27-g57g-wgqp/GHSA-vv27-g57g-wgqp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv27-g57g-wgqp", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24134" + ], + "details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24134" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json b/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json new file mode 100644 index 00000000000..958c6b852e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vw88-wc28-c2h6/GHSA-vw88-wc28-c2h6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw88-wc28-c2h6", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2025-24093" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3. An app may be able to access removable volumes without user consent.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24093" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w553-92jc-9xp5/GHSA-w553-92jc-9xp5.json b/advisories/unreviewed/2025/01/GHSA-w553-92jc-9xp5/GHSA-w553-92jc-9xp5.json new file mode 100644 index 00000000000..23bbcdfe61f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w553-92jc-9xp5/GHSA-w553-92jc-9xp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w553-92jc-9xp5", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-37526" + ], + "details": "IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive information from objects published using Watson Query due to an improper data protection mechanism.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37526" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7173774" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json b/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json new file mode 100644 index 00000000000..2a08d6eb7a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5x6-r7f6-w3x6", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24140" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24140" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json b/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json new file mode 100644 index 00000000000..54f3ba96acd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc57-w9rc-p4g6", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24136" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious app may be able to create symlinks to protected regions of the disk.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24136" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json b/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json new file mode 100644 index 00000000000..db686643766 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjg3-gwjx-xwj5", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24104" + ], + "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in iPadOS 17.7.4, iOS 18.3 and iPadOS 18.3. Restoring a maliciously crafted backup file may lead to modification of protected system files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json new file mode 100644 index 00000000000..d6289089abd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjxf-6r8p-9pvp", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24103" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access protected user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json b/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json new file mode 100644 index 00000000000..a436014c276 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxw4-9hr6-3vw4", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24106" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json b/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json new file mode 100644 index 00000000000..e33fc1f3270 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7wf-f6c9-x89j", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24121" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24121" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json b/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json new file mode 100644 index 00000000000..2e784de2f2f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xh6m-fr4r-mqj3/GHSA-xh6m-fr4r-mqj3.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh6m-fr4r-mqj3", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24117" + ], + "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24117" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122067" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122071" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json new file mode 100644 index 00000000000..b45b0c22d0c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmpx-2mhf-xq2j", + "modified": "2025-01-28T00:32:14Z", + "published": "2025-01-28T00:32:14Z", + "aliases": [ + "CVE-2025-24141" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24141" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json new file mode 100644 index 00000000000..95c26d59370 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpjh-vmfm-8qmf", + "modified": "2025-01-28T00:32:13Z", + "published": "2025-01-28T00:32:13Z", + "aliases": [ + "CVE-2024-54542" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54542" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121846" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T22:15:14Z" + } +} \ No newline at end of file