From fc3d13e60197f5240127a009a23c4e5dee95ac51 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 14 Jan 2025 15:32:42 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-28vw-4prm-5q55.json | 4 +- .../GHSA-hwr9-3qwm-5crv.json | 4 +- .../GHSA-m4g6-4f6c-9h4c.json | 4 +- .../GHSA-2xq7-g234-6858.json | 3 +- .../GHSA-57gr-x8mp-q54m.json | 3 +- .../GHSA-5c3h-74f7-rvqq.json | 3 +- .../GHSA-5rgv-86c3-c67f.json | 3 +- .../GHSA-ffvh-g6f4-8c4v.json | 3 +- .../GHSA-g25p-mggp-qqcf.json | 3 +- .../GHSA-g524-49q8-vhcm.json | 3 +- .../GHSA-j642-rp5q-w8w9.json | 15 +++++-- .../GHSA-pfh4-6f3v-4mwm.json | 15 +++++-- .../GHSA-ph55-5xqf-59r7.json | 15 +++++-- .../GHSA-qgf6-wc2f-vhf3.json | 3 +- .../GHSA-w379-4m9h-6p6h.json | 3 +- .../GHSA-528f-9jjm-wrc2.json | 15 +++++-- .../GHSA-559c-j26r-95qc.json | 15 +++++-- .../GHSA-63c9-q9c6-qgqh.json | 15 +++++-- .../GHSA-6r45-w96c-v9jx.json | 15 +++++-- .../GHSA-9889-pmmf-cvr8.json | 15 +++++-- .../GHSA-9jpw-f586-mqqf.json | 15 +++++-- .../GHSA-9rc8-c76x-36m2.json | 15 +++++-- .../GHSA-h6wr-63v9-2m6h.json | 15 +++++-- .../GHSA-jg7c-h6xh-f8hr.json | 15 +++++-- .../GHSA-qvjm-pcpv-593p.json | 15 +++++-- .../GHSA-rv79-7m3p-hx2p.json | 15 +++++-- .../GHSA-w6pp-7vhg-w878.json | 15 +++++-- .../GHSA-w7cg-566v-rm5v.json | 15 +++++-- .../GHSA-w82p-p27g-2qgq.json | 15 +++++-- .../GHSA-xgx4-jvp8-p2h2.json | 15 +++++-- .../GHSA-6264-3hhv-77hg.json | 15 +++++-- .../GHSA-97fh-3x83-fvh6.json | 15 +++++-- .../GHSA-m253-3j38-482h.json | 15 +++++-- .../GHSA-mvq3-v998-w43f.json | 15 +++++-- .../GHSA-p6xg-jwxf-89ch.json | 15 +++++-- .../GHSA-phc9-mf56-r5f6.json | 15 +++++-- .../GHSA-qh82-7chj-9876.json | 15 +++++-- .../GHSA-qpg3-72fq-2rqh.json | 15 +++++-- .../GHSA-w29x-26qv-fmmq.json | 15 +++++-- .../GHSA-x846-9rxh-mcv9.json | 15 +++++-- .../GHSA-7f25-p8gc-hxqh.json | 6 ++- .../GHSA-3747-237p-gqq2.json | 15 +++++-- .../GHSA-3h24-5m24-pxvw.json | 15 +++++-- .../GHSA-875c-9gcv-8c6h.json | 6 ++- .../GHSA-8g4q-j62f-4359.json | 15 +++++-- .../GHSA-98rc-vgv3-572h.json | 15 +++++-- .../GHSA-9jgq-4mjq-qcc9.json | 6 ++- .../GHSA-9xj5-r9g9-xvp9.json | 15 +++++-- .../GHSA-cqv3-q8h5-83r5.json | 15 +++++-- .../GHSA-hjcm-xj34-6q2q.json | 15 +++++-- .../GHSA-mxwc-7773-pqqc.json | 15 +++++-- .../GHSA-q73c-hqqp-jcp7.json | 15 +++++-- .../GHSA-qc69-73cr-g9fg.json | 15 +++++-- .../GHSA-279f-qp3q-j675.json | 15 +++++-- .../GHSA-2945-84q7-684p.json | 15 +++++-- .../GHSA-295c-qxg5-g88q.json | 36 +++++++++++++++ .../GHSA-2998-9vr3-8cqh.json | 36 +++++++++++++++ .../GHSA-2jpw-fpqf-qc7g.json | 36 +++++++++++++++ .../GHSA-2jw2-w8hc-jqch.json | 36 +++++++++++++++ .../GHSA-2mpq-2g57-j8ww.json | 36 +++++++++++++++ .../GHSA-2q3h-pxc2-8gqg.json | 36 +++++++++++++++ .../GHSA-2rg6-2x33-4cjj.json | 36 +++++++++++++++ .../GHSA-32qp-fj94-7jhx.json | 15 +++++-- .../GHSA-33pw-8v2f-85mj.json | 36 +++++++++++++++ .../GHSA-39p7-78c9-m48f.json | 36 +++++++++++++++ .../GHSA-3cww-g5m8-59q4.json | 36 +++++++++++++++ .../GHSA-3g8p-fgh4-3vvq.json | 36 +++++++++++++++ .../GHSA-3hjv-6fp6-9qj9.json | 36 +++++++++++++++ .../GHSA-3qqr-ch4p-vc36.json | 36 +++++++++++++++ .../GHSA-43p5-738g-gr8j.json | 11 +++-- .../GHSA-453m-fcx3-j43g.json | 36 +++++++++++++++ .../GHSA-45gf-27xm-h64q.json | 36 +++++++++++++++ .../GHSA-49vq-r69w-8m53.json | 36 +++++++++++++++ .../GHSA-4fjp-2975-mx8w.json | 36 +++++++++++++++ .../GHSA-4jf3-hxmq-5r2f.json | 36 +++++++++++++++ .../GHSA-4pvm-5x6h-f3qp.json | 36 +++++++++++++++ .../GHSA-4wxp-6xr4-5pvw.json | 36 +++++++++++++++ .../GHSA-53h9-qp9v-954c.json | 36 +++++++++++++++ .../GHSA-53rm-p3f5-vx5c.json | 36 +++++++++++++++ .../GHSA-54qm-4vvg-ch55.json | 36 +++++++++++++++ .../GHSA-5c5x-jw5q-2wpw.json | 11 +++-- .../GHSA-5f5r-cv84-3xjr.json | 36 +++++++++++++++ .../GHSA-5gj5-pjhv-qqc6.json | 15 +++++-- .../GHSA-5gx2-mcv7-59f4.json | 36 +++++++++++++++ .../GHSA-5qf3-cvj3-r534.json | 36 +++++++++++++++ .../GHSA-5wmq-f28x-ggg6.json | 36 +++++++++++++++ .../GHSA-5xxp-3j63-qv9w.json | 37 +++++++++++++++ .../GHSA-65gf-8mmg-g56g.json | 36 +++++++++++++++ .../GHSA-65xx-qhj3-cvp8.json | 36 +++++++++++++++ .../GHSA-6956-r7m5-cgq5.json | 36 +++++++++++++++ .../GHSA-69mj-v9gr-ph5p.json | 36 +++++++++++++++ .../GHSA-6gj7-68vj-fvp7.json | 36 +++++++++++++++ .../GHSA-6r9m-h6rv-42cg.json | 36 +++++++++++++++ .../GHSA-6v4c-pj8v-6wqm.json | 36 +++++++++++++++ .../GHSA-79x5-vf8c-7456.json | 36 +++++++++++++++ .../GHSA-7p4j-prhq-8ffm.json | 36 +++++++++++++++ .../GHSA-7p64-5x2j-p5qx.json | 36 +++++++++++++++ .../GHSA-7rgq-53c3-wvm6.json | 36 +++++++++++++++ .../GHSA-7xfj-4r7x-3733.json | 45 +++++++++++++++++++ .../GHSA-88gg-54r4-rj2g.json | 36 +++++++++++++++ .../GHSA-8f65-h57m-hqw8.json | 36 +++++++++++++++ .../GHSA-8jwr-jm4q-89xr.json | 36 +++++++++++++++ .../GHSA-8m5m-vgwc-v2rv.json | 31 +++++++++++++ .../GHSA-8qhx-f4vg-5h4h.json | 36 +++++++++++++++ .../GHSA-8qrq-rh6g-rh3h.json | 36 +++++++++++++++ .../GHSA-8rvm-5wfm-cww4.json | 36 +++++++++++++++ .../GHSA-9268-6mh2-4xfg.json | 36 +++++++++++++++ .../GHSA-94wj-p6vq-75pv.json | 36 +++++++++++++++ .../GHSA-9953-68f2-mpwf.json | 36 +++++++++++++++ .../GHSA-9ch8-4327-g6cw.json | 36 +++++++++++++++ .../GHSA-9cmh-g466-3ph3.json | 31 +++++++++++++ .../GHSA-9f95-94rj-c9f5.json | 36 +++++++++++++++ .../GHSA-9rjp-q43g-3644.json | 36 +++++++++++++++ .../GHSA-c22h-m2p9-c6w3.json | 36 +++++++++++++++ .../GHSA-ch76-hx2m-rf3m.json | 36 +++++++++++++++ .../GHSA-cphf-r7wp-hq92.json | 36 +++++++++++++++ .../GHSA-cv67-v84q-6c9x.json | 36 +++++++++++++++ .../GHSA-fggw-c44p-x7gg.json | 29 ++++++++++++ .../GHSA-fh6c-p6q9-8m5f.json | 6 ++- .../GHSA-fr2h-74vh-mp7c.json | 11 +++-- .../GHSA-g23p-hhrc-qr97.json | 36 +++++++++++++++ .../GHSA-g347-74q4-mp7w.json | 36 +++++++++++++++ .../GHSA-g58r-fcx4-mv8r.json | 36 +++++++++++++++ .../GHSA-g5cp-69v7-5p9h.json | 36 +++++++++++++++ .../GHSA-g72p-5f8c-rcj2.json | 36 +++++++++++++++ .../GHSA-g8fx-pvg9-8mm8.json | 37 +++++++++++++++ .../GHSA-gc47-55jm-w6mg.json | 36 +++++++++++++++ .../GHSA-gpr9-gqg8-xj7v.json | 36 +++++++++++++++ .../GHSA-gqrr-9m6w-6qhc.json | 36 +++++++++++++++ .../GHSA-gx3h-wj7q-54q9.json | 36 +++++++++++++++ .../GHSA-gxgh-8p3v-3jvv.json | 36 +++++++++++++++ .../GHSA-h695-gj7p-pjhj.json | 15 +++++-- .../GHSA-hfjp-2wj6-97ww.json | 36 +++++++++++++++ .../GHSA-hhjp-322f-hh5x.json | 36 +++++++++++++++ .../GHSA-hpf7-2hg3-3g3h.json | 36 +++++++++++++++ .../GHSA-hw72-fmxv-278r.json | 36 +++++++++++++++ .../GHSA-hw79-cp29-3x6c.json | 15 +++++-- .../GHSA-jc45-7g3m-f786.json | 36 +++++++++++++++ .../GHSA-jfmv-87hc-q689.json | 36 +++++++++++++++ .../GHSA-jhvv-hwq8-7rx2.json | 36 +++++++++++++++ .../GHSA-jw4w-2rjj-x8jv.json | 36 +++++++++++++++ .../GHSA-m343-65m6-2r6j.json | 36 +++++++++++++++ .../GHSA-m477-ghq9-m3j8.json | 36 +++++++++++++++ .../GHSA-mcpf-9j38-2vmq.json | 36 +++++++++++++++ .../GHSA-mphf-cc86-chgh.json | 36 +++++++++++++++ .../GHSA-p2ch-mj9p-73pg.json | 36 +++++++++++++++ .../GHSA-p469-jgv4-q322.json | 36 +++++++++++++++ .../GHSA-pp4g-pjj7-f6rj.json | 36 +++++++++++++++ .../GHSA-px43-x9c5-2gjv.json | 36 +++++++++++++++ .../GHSA-q35w-cr5p-7qc3.json | 36 +++++++++++++++ .../GHSA-q642-7m4r-pmj6.json | 36 +++++++++++++++ .../GHSA-q6h8-qgxm-m9pc.json | 36 +++++++++++++++ .../GHSA-qhwf-jg9m-cq9f.json | 36 +++++++++++++++ .../GHSA-qxh2-8jw8-hx7g.json | 36 +++++++++++++++ .../GHSA-qxxc-5wx2-mh2q.json | 36 +++++++++++++++ .../GHSA-r39f-vq75-r7mj.json | 36 +++++++++++++++ .../GHSA-r3rj-4mrf-v5mf.json | 36 +++++++++++++++ .../GHSA-r9wr-68hr-qxpc.json | 36 +++++++++++++++ .../GHSA-rcr8-43mg-v238.json | 15 +++++-- .../GHSA-rhvx-9vr4-vmg9.json | 36 +++++++++++++++ .../GHSA-rp6x-j4c5-4rvc.json | 36 +++++++++++++++ .../GHSA-rrmg-hr5x-6w4q.json | 15 +++++-- .../GHSA-v34h-7f4q-76h6.json | 36 +++++++++++++++ .../GHSA-v4mr-pqhx-vpm2.json | 36 +++++++++++++++ .../GHSA-v729-w778-vqwm.json | 36 +++++++++++++++ .../GHSA-v8p8-w9q2-q67j.json | 36 +++++++++++++++ .../GHSA-w29f-xpw3-353w.json | 36 +++++++++++++++ .../GHSA-w9pq-h9mh-jm92.json | 36 +++++++++++++++ .../GHSA-wcfj-9wq6-7h82.json | 15 +++++-- .../GHSA-wcvc-h2qg-4xqg.json | 36 +++++++++++++++ .../GHSA-wh2c-vg4v-4q9m.json | 36 +++++++++++++++ .../GHSA-wj4g-3v6m-x76m.json | 11 +++-- .../GHSA-wp3h-cvvj-q2gw.json | 36 +++++++++++++++ .../GHSA-wrf4-8gjw-vgxw.json | 15 +++++-- .../GHSA-x5wr-hg6v-9cj3.json | 11 +++-- .../GHSA-x6vp-5v5h-8v6q.json | 36 +++++++++++++++ .../GHSA-xpch-9h27-3hpf.json | 36 +++++++++++++++ .../GHSA-xx9m-2fc7-mhx8.json | 36 +++++++++++++++ 178 files changed, 4532 insertions(+), 224 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-295c-qxg5-g88q/GHSA-295c-qxg5-g88q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2998-9vr3-8cqh/GHSA-2998-9vr3-8cqh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2mpq-2g57-j8ww/GHSA-2mpq-2g57-j8ww.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2q3h-pxc2-8gqg/GHSA-2q3h-pxc2-8gqg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2rg6-2x33-4cjj/GHSA-2rg6-2x33-4cjj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-39p7-78c9-m48f/GHSA-39p7-78c9-m48f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3cww-g5m8-59q4/GHSA-3cww-g5m8-59q4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3g8p-fgh4-3vvq/GHSA-3g8p-fgh4-3vvq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3hjv-6fp6-9qj9/GHSA-3hjv-6fp6-9qj9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3qqr-ch4p-vc36/GHSA-3qqr-ch4p-vc36.json create mode 100644 advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-45gf-27xm-h64q/GHSA-45gf-27xm-h64q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4fjp-2975-mx8w/GHSA-4fjp-2975-mx8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4jf3-hxmq-5r2f/GHSA-4jf3-hxmq-5r2f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4pvm-5x6h-f3qp/GHSA-4pvm-5x6h-f3qp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4wxp-6xr4-5pvw/GHSA-4wxp-6xr4-5pvw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-53h9-qp9v-954c/GHSA-53h9-qp9v-954c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-54qm-4vvg-ch55/GHSA-54qm-4vvg-ch55.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5f5r-cv84-3xjr/GHSA-5f5r-cv84-3xjr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5gx2-mcv7-59f4/GHSA-5gx2-mcv7-59f4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5qf3-cvj3-r534/GHSA-5qf3-cvj3-r534.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5wmq-f28x-ggg6/GHSA-5wmq-f28x-ggg6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5xxp-3j63-qv9w/GHSA-5xxp-3j63-qv9w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-65xx-qhj3-cvp8/GHSA-65xx-qhj3-cvp8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6956-r7m5-cgq5/GHSA-6956-r7m5-cgq5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-69mj-v9gr-ph5p/GHSA-69mj-v9gr-ph5p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6gj7-68vj-fvp7/GHSA-6gj7-68vj-fvp7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6v4c-pj8v-6wqm/GHSA-6v4c-pj8v-6wqm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7p64-5x2j-p5qx/GHSA-7p64-5x2j-p5qx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json create mode 100644 advisories/unreviewed/2025/01/GHSA-88gg-54r4-rj2g/GHSA-88gg-54r4-rj2g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8jwr-jm4q-89xr/GHSA-8jwr-jm4q-89xr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8qhx-f4vg-5h4h/GHSA-8qhx-f4vg-5h4h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8qrq-rh6g-rh3h/GHSA-8qrq-rh6g-rh3h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8rvm-5wfm-cww4/GHSA-8rvm-5wfm-cww4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9f95-94rj-c9f5/GHSA-9f95-94rj-c9f5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c22h-m2p9-c6w3/GHSA-c22h-m2p9-c6w3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-ch76-hx2m-rf3m/GHSA-ch76-hx2m-rf3m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cphf-r7wp-hq92/GHSA-cphf-r7wp-hq92.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g347-74q4-mp7w/GHSA-g347-74q4-mp7w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g58r-fcx4-mv8r/GHSA-g58r-fcx4-mv8r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g72p-5f8c-rcj2/GHSA-g72p-5f8c-rcj2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g8fx-pvg9-8mm8/GHSA-g8fx-pvg9-8mm8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gc47-55jm-w6mg/GHSA-gc47-55jm-w6mg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gpr9-gqg8-xj7v/GHSA-gpr9-gqg8-xj7v.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gxgh-8p3v-3jvv/GHSA-gxgh-8p3v-3jvv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hfjp-2wj6-97ww/GHSA-hfjp-2wj6-97ww.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hw72-fmxv-278r/GHSA-hw72-fmxv-278r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jc45-7g3m-f786/GHSA-jc45-7g3m-f786.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m343-65m6-2r6j/GHSA-m343-65m6-2r6j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mphf-cc86-chgh/GHSA-mphf-cc86-chgh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p2ch-mj9p-73pg/GHSA-p2ch-mj9p-73pg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p469-jgv4-q322/GHSA-p469-jgv4-q322.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q35w-cr5p-7qc3/GHSA-q35w-cr5p-7qc3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q642-7m4r-pmj6/GHSA-q642-7m4r-pmj6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q6h8-qgxm-m9pc/GHSA-q6h8-qgxm-m9pc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qhwf-jg9m-cq9f/GHSA-qhwf-jg9m-cq9f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qxh2-8jw8-hx7g/GHSA-qxh2-8jw8-hx7g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qxxc-5wx2-mh2q/GHSA-qxxc-5wx2-mh2q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r39f-vq75-r7mj/GHSA-r39f-vq75-r7mj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r3rj-4mrf-v5mf/GHSA-r3rj-4mrf-v5mf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r9wr-68hr-qxpc/GHSA-r9wr-68hr-qxpc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rhvx-9vr4-vmg9/GHSA-rhvx-9vr4-vmg9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rp6x-j4c5-4rvc/GHSA-rp6x-j4c5-4rvc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v34h-7f4q-76h6/GHSA-v34h-7f4q-76h6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v4mr-pqhx-vpm2/GHSA-v4mr-pqhx-vpm2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v729-w778-vqwm/GHSA-v729-w778-vqwm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v8p8-w9q2-q67j/GHSA-v8p8-w9q2-q67j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w29f-xpw3-353w/GHSA-w29f-xpw3-353w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wh2c-vg4v-4q9m/GHSA-wh2c-vg4v-4q9m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wp3h-cvvj-q2gw/GHSA-wp3h-cvvj-q2gw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x6vp-5v5h-8v6q/GHSA-x6vp-5v5h-8v6q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xpch-9h27-3hpf/GHSA-xpch-9h27-3hpf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xx9m-2fc7-mhx8/GHSA-xx9m-2fc7-mhx8.json diff --git a/advisories/unreviewed/2023/05/GHSA-28vw-4prm-5q55/GHSA-28vw-4prm-5q55.json b/advisories/unreviewed/2023/05/GHSA-28vw-4prm-5q55/GHSA-28vw-4prm-5q55.json index 7c1afa23c20..f9ee9998c79 100644 --- a/advisories/unreviewed/2023/05/GHSA-28vw-4prm-5q55/GHSA-28vw-4prm-5q55.json +++ b/advisories/unreviewed/2023/05/GHSA-28vw-4prm-5q55/GHSA-28vw-4prm-5q55.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-hwr9-3qwm-5crv/GHSA-hwr9-3qwm-5crv.json b/advisories/unreviewed/2023/05/GHSA-hwr9-3qwm-5crv/GHSA-hwr9-3qwm-5crv.json index f455a0fa0d4..592960e59f7 100644 --- a/advisories/unreviewed/2023/05/GHSA-hwr9-3qwm-5crv/GHSA-hwr9-3qwm-5crv.json +++ b/advisories/unreviewed/2023/05/GHSA-hwr9-3qwm-5crv/GHSA-hwr9-3qwm-5crv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-m4g6-4f6c-9h4c/GHSA-m4g6-4f6c-9h4c.json b/advisories/unreviewed/2023/05/GHSA-m4g6-4f6c-9h4c/GHSA-m4g6-4f6c-9h4c.json index 4307a14c21e..10411e8da27 100644 --- a/advisories/unreviewed/2023/05/GHSA-m4g6-4f6c-9h4c/GHSA-m4g6-4f6c-9h4c.json +++ b/advisories/unreviewed/2023/05/GHSA-m4g6-4f6c-9h4c/GHSA-m4g6-4f6c-9h4c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2xq7-g234-6858/GHSA-2xq7-g234-6858.json b/advisories/unreviewed/2024/03/GHSA-2xq7-g234-6858/GHSA-2xq7-g234-6858.json index ad5a926f577..40df0f4e788 100644 --- a/advisories/unreviewed/2024/03/GHSA-2xq7-g234-6858/GHSA-2xq7-g234-6858.json +++ b/advisories/unreviewed/2024/03/GHSA-2xq7-g234-6858/GHSA-2xq7-g234-6858.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-57gr-x8mp-q54m/GHSA-57gr-x8mp-q54m.json b/advisories/unreviewed/2024/03/GHSA-57gr-x8mp-q54m/GHSA-57gr-x8mp-q54m.json index 48110bc609a..c52c71b5d06 100644 --- a/advisories/unreviewed/2024/03/GHSA-57gr-x8mp-q54m/GHSA-57gr-x8mp-q54m.json +++ b/advisories/unreviewed/2024/03/GHSA-57gr-x8mp-q54m/GHSA-57gr-x8mp-q54m.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5c3h-74f7-rvqq/GHSA-5c3h-74f7-rvqq.json b/advisories/unreviewed/2024/03/GHSA-5c3h-74f7-rvqq/GHSA-5c3h-74f7-rvqq.json index bb7d60c9da9..04179cd81f5 100644 --- a/advisories/unreviewed/2024/03/GHSA-5c3h-74f7-rvqq/GHSA-5c3h-74f7-rvqq.json +++ b/advisories/unreviewed/2024/03/GHSA-5c3h-74f7-rvqq/GHSA-5c3h-74f7-rvqq.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5rgv-86c3-c67f/GHSA-5rgv-86c3-c67f.json b/advisories/unreviewed/2024/03/GHSA-5rgv-86c3-c67f/GHSA-5rgv-86c3-c67f.json index 5af5fdca29d..44ebd66442d 100644 --- a/advisories/unreviewed/2024/03/GHSA-5rgv-86c3-c67f/GHSA-5rgv-86c3-c67f.json +++ b/advisories/unreviewed/2024/03/GHSA-5rgv-86c3-c67f/GHSA-5rgv-86c3-c67f.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-ffvh-g6f4-8c4v/GHSA-ffvh-g6f4-8c4v.json b/advisories/unreviewed/2024/03/GHSA-ffvh-g6f4-8c4v/GHSA-ffvh-g6f4-8c4v.json index ffdbc5e1873..2e866d6504e 100644 --- a/advisories/unreviewed/2024/03/GHSA-ffvh-g6f4-8c4v/GHSA-ffvh-g6f4-8c4v.json +++ b/advisories/unreviewed/2024/03/GHSA-ffvh-g6f4-8c4v/GHSA-ffvh-g6f4-8c4v.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g25p-mggp-qqcf/GHSA-g25p-mggp-qqcf.json b/advisories/unreviewed/2024/03/GHSA-g25p-mggp-qqcf/GHSA-g25p-mggp-qqcf.json index c5f09b0fba2..db771b856b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-g25p-mggp-qqcf/GHSA-g25p-mggp-qqcf.json +++ b/advisories/unreviewed/2024/03/GHSA-g25p-mggp-qqcf/GHSA-g25p-mggp-qqcf.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g524-49q8-vhcm/GHSA-g524-49q8-vhcm.json b/advisories/unreviewed/2024/03/GHSA-g524-49q8-vhcm/GHSA-g524-49q8-vhcm.json index bc8beedbe26..4524126684c 100644 --- a/advisories/unreviewed/2024/03/GHSA-g524-49q8-vhcm/GHSA-g524-49q8-vhcm.json +++ b/advisories/unreviewed/2024/03/GHSA-g524-49q8-vhcm/GHSA-g524-49q8-vhcm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-j642-rp5q-w8w9/GHSA-j642-rp5q-w8w9.json b/advisories/unreviewed/2024/03/GHSA-j642-rp5q-w8w9/GHSA-j642-rp5q-w8w9.json index b6e0b78cc3c..335f5b2c43c 100644 --- a/advisories/unreviewed/2024/03/GHSA-j642-rp5q-w8w9/GHSA-j642-rp5q-w8w9.json +++ b/advisories/unreviewed/2024/03/GHSA-j642-rp5q-w8w9/GHSA-j642-rp5q-w8w9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j642-rp5q-w8w9", - "modified": "2024-03-15T21:30:44Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-03-15T21:30:44Z", "aliases": [ "CVE-2021-47123" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix ltout double free on completion race\n\nAlways remove linked timeout on io_link_timeout_fn() from the master\nrequest link list, otherwise we may get use-after-free when first\nio_link_timeout_fn() puts linked timeout in the fail path, and then\nwill be found and put on master's free.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T21:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pfh4-6f3v-4mwm/GHSA-pfh4-6f3v-4mwm.json b/advisories/unreviewed/2024/03/GHSA-pfh4-6f3v-4mwm/GHSA-pfh4-6f3v-4mwm.json index 5ac43c0f1e4..02fd2f39fd8 100644 --- a/advisories/unreviewed/2024/03/GHSA-pfh4-6f3v-4mwm/GHSA-pfh4-6f3v-4mwm.json +++ b/advisories/unreviewed/2024/03/GHSA-pfh4-6f3v-4mwm/GHSA-pfh4-6f3v-4mwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pfh4-6f3v-4mwm", - "modified": "2024-03-04T18:30:36Z", + "modified": "2025-01-14T15:30:47Z", "published": "2024-03-04T18:30:36Z", "aliases": [ "CVE-2021-47082" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntun: avoid double free in tun_free_netdev\n\nAvoid double free in tun_free_netdev() by moving the\ndev->tstats and tun->security allocs to a new ndo_init routine\n(tun_net_init()) that will be called by register_netdevice().\nndo_init is paired with the desctructor (tun_free_netdev()),\nso if there's an error in register_netdevice() the destructor\nwill handle the frees.\n\nBUG: KASAN: double-free or invalid-free in selinux_tun_dev_free_security+0x1a/0x20 security/selinux/hooks.c:5605\n\nCPU: 0 PID: 25750 Comm: syz-executor416 Not tainted 5.16.0-rc2-syzk #1\nHardware name: Red Hat KVM, BIOS\nCall Trace:\n\n__dump_stack lib/dump_stack.c:88 [inline]\ndump_stack_lvl+0x89/0xb5 lib/dump_stack.c:106\nprint_address_description.constprop.9+0x28/0x160 mm/kasan/report.c:247\nkasan_report_invalid_free+0x55/0x80 mm/kasan/report.c:372\n____kasan_slab_free mm/kasan/common.c:346 [inline]\n__kasan_slab_free+0x107/0x120 mm/kasan/common.c:374\nkasan_slab_free include/linux/kasan.h:235 [inline]\nslab_free_hook mm/slub.c:1723 [inline]\nslab_free_freelist_hook mm/slub.c:1749 [inline]\nslab_free mm/slub.c:3513 [inline]\nkfree+0xac/0x2d0 mm/slub.c:4561\nselinux_tun_dev_free_security+0x1a/0x20 security/selinux/hooks.c:5605\nsecurity_tun_dev_free_security+0x4f/0x90 security/security.c:2342\ntun_free_netdev+0xe6/0x150 drivers/net/tun.c:2215\nnetdev_run_todo+0x4df/0x840 net/core/dev.c:10627\nrtnl_unlock+0x13/0x20 net/core/rtnetlink.c:112\n__tun_chr_ioctl+0x80c/0x2870 drivers/net/tun.c:3302\ntun_chr_ioctl+0x2f/0x40 drivers/net/tun.c:3311\nvfs_ioctl fs/ioctl.c:51 [inline]\n__do_sys_ioctl fs/ioctl.c:874 [inline]\n__se_sys_ioctl fs/ioctl.c:860 [inline]\n__x64_sys_ioctl+0x19d/0x220 fs/ioctl.c:860\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x3a/0x80 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x44/0xae", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ph55-5xqf-59r7/GHSA-ph55-5xqf-59r7.json b/advisories/unreviewed/2024/03/GHSA-ph55-5xqf-59r7/GHSA-ph55-5xqf-59r7.json index 56ef80a9137..0e38871c4c9 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph55-5xqf-59r7/GHSA-ph55-5xqf-59r7.json +++ b/advisories/unreviewed/2024/03/GHSA-ph55-5xqf-59r7/GHSA-ph55-5xqf-59r7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ph55-5xqf-59r7", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-01-14T15:30:47Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2023-52486" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: Don't unref the same fb many times by mistake due to deadlock handling\n\nIf we get a deadlock after the fb lookup in drm_mode_page_flip_ioctl()\nwe proceed to unref the fb and then retry the whole thing from the top.\nBut we forget to reset the fb pointer back to NULL, and so if we then\nget another error during the retry, before the fb lookup, we proceed\nthe unref the same fb again without having gotten another reference.\nThe end result is that the fb will (eventually) end up being freed\nwhile it's still in use.\n\nReset fb to NULL once we've unreffed it to avoid doing it again\nuntil we've done another fb lookup.\n\nThis turned out to be pretty easy to hit on a DG2 when doing async\nflips (and CONFIG_DEBUG_WW_MUTEX_SLOWPATH=y). The first symptom I\nsaw that drm_closefb() simply got stuck in a busy loop while walking\nthe framebuffer list. Fortunately I was able to convince it to oops\ninstead, and from there it was easier to track down the culprit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qgf6-wc2f-vhf3/GHSA-qgf6-wc2f-vhf3.json b/advisories/unreviewed/2024/03/GHSA-qgf6-wc2f-vhf3/GHSA-qgf6-wc2f-vhf3.json index cb098e72ea5..23f12bdfd67 100644 --- a/advisories/unreviewed/2024/03/GHSA-qgf6-wc2f-vhf3/GHSA-qgf6-wc2f-vhf3.json +++ b/advisories/unreviewed/2024/03/GHSA-qgf6-wc2f-vhf3/GHSA-qgf6-wc2f-vhf3.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-w379-4m9h-6p6h/GHSA-w379-4m9h-6p6h.json b/advisories/unreviewed/2024/03/GHSA-w379-4m9h-6p6h/GHSA-w379-4m9h-6p6h.json index 7db856a41ae..56e4fc36d8e 100644 --- a/advisories/unreviewed/2024/03/GHSA-w379-4m9h-6p6h/GHSA-w379-4m9h-6p6h.json +++ b/advisories/unreviewed/2024/03/GHSA-w379-4m9h-6p6h/GHSA-w379-4m9h-6p6h.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-528f-9jjm-wrc2/GHSA-528f-9jjm-wrc2.json b/advisories/unreviewed/2024/04/GHSA-528f-9jjm-wrc2/GHSA-528f-9jjm-wrc2.json index 41b738beb7a..015d785cc06 100644 --- a/advisories/unreviewed/2024/04/GHSA-528f-9jjm-wrc2/GHSA-528f-9jjm-wrc2.json +++ b/advisories/unreviewed/2024/04/GHSA-528f-9jjm-wrc2/GHSA-528f-9jjm-wrc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-528f-9jjm-wrc2", - "modified": "2024-04-17T12:32:03Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-17T12:32:03Z", "aliases": [ "CVE-2024-26829" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ir_toy: fix a memleak in irtoy_tx\n\nWhen irtoy_command fails, buf should be freed since it is allocated by\nirtoy_tx, or there is a memleak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-559c-j26r-95qc/GHSA-559c-j26r-95qc.json b/advisories/unreviewed/2024/04/GHSA-559c-j26r-95qc/GHSA-559c-j26r-95qc.json index 51ab4167864..addbdcec9f6 100644 --- a/advisories/unreviewed/2024/04/GHSA-559c-j26r-95qc/GHSA-559c-j26r-95qc.json +++ b/advisories/unreviewed/2024/04/GHSA-559c-j26r-95qc/GHSA-559c-j26r-95qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-559c-j26r-95qc", - "modified": "2024-04-28T15:30:29Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48648" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: fix null pointer dereference in efx_hard_start_xmit\n\nTrying to get the channel from the tx_queue variable here is wrong\nbecause we can only be here if tx_queue is NULL, so we shouldn't\ndereference it. As the above comment in the code says, this is very\nunlikely to happen, but it's wrong anyway so let's fix it.\n\nI hit this issue because of a different bug that caused tx_queue to be\nNULL. If that happens, this is the error message that we get here:\n BUG: unable to handle kernel NULL pointer dereference at 0000000000000020\n [...]\n RIP: 0010:efx_hard_start_xmit+0x153/0x170 [sfc]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-63c9-q9c6-qgqh/GHSA-63c9-q9c6-qgqh.json b/advisories/unreviewed/2024/04/GHSA-63c9-q9c6-qgqh/GHSA-63c9-q9c6-qgqh.json index 5cc3005d863..671eb3ce745 100644 --- a/advisories/unreviewed/2024/04/GHSA-63c9-q9c6-qgqh/GHSA-63c9-q9c6-qgqh.json +++ b/advisories/unreviewed/2024/04/GHSA-63c9-q9c6-qgqh/GHSA-63c9-q9c6-qgqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63c9-q9c6-qgqh", - "modified": "2024-04-17T12:32:04Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26871" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix NULL pointer dereference in f2fs_submit_page_write()\n\nBUG: kernel NULL pointer dereference, address: 0000000000000014\nRIP: 0010:f2fs_submit_page_write+0x6cf/0x780 [f2fs]\nCall Trace:\n\n? show_regs+0x6e/0x80\n? __die+0x29/0x70\n? page_fault_oops+0x154/0x4a0\n? prb_read_valid+0x20/0x30\n? __irq_work_queue_local+0x39/0xd0\n? irq_work_queue+0x36/0x70\n? do_user_addr_fault+0x314/0x6c0\n? exc_page_fault+0x7d/0x190\n? asm_exc_page_fault+0x2b/0x30\n? f2fs_submit_page_write+0x6cf/0x780 [f2fs]\n? f2fs_submit_page_write+0x736/0x780 [f2fs]\ndo_write_page+0x50/0x170 [f2fs]\nf2fs_outplace_write_data+0x61/0xb0 [f2fs]\nf2fs_do_write_data_page+0x3f8/0x660 [f2fs]\nf2fs_write_single_data_page+0x5bb/0x7a0 [f2fs]\nf2fs_write_cache_pages+0x3da/0xbe0 [f2fs]\n...\nIt is possible that other threads have added this fio to io->bio\nand submitted the io->bio before entering f2fs_submit_page_write().\nAt this point io->bio = NULL.\nIf is_end_zone_blkaddr(sbi, fio->new_blkaddr) of this fio is true,\nthen an NULL pointer dereference error occurs at bio_get(io->bio).\nThe original code for determining zone end was after \"out:\",\nwhich would have missed some fio who is zone end. I've moved\n this code before \"skip:\" to make sure it's done for each fio.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json b/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json index 42ce77144d0..e8eab5b05bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json +++ b/advisories/unreviewed/2024/04/GHSA-6r45-w96c-v9jx/GHSA-6r45-w96c-v9jx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6r45-w96c-v9jx", - "modified": "2024-06-26T00:31:37Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26895" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces\n\nwilc_netdev_cleanup currently triggers a KASAN warning, which can be\nobserved on interface registration error path, or simply by\nremoving the module/unbinding device from driver:\n\necho spi0.1 > /sys/bus/spi/drivers/wilc1000_spi/unbind\n\n==================================================================\nBUG: KASAN: slab-use-after-free in wilc_netdev_cleanup+0x508/0x5cc\nRead of size 4 at addr c54d1ce8 by task sh/86\n\nCPU: 0 PID: 86 Comm: sh Not tainted 6.8.0-rc1+ #117\nHardware name: Atmel SAMA5\n unwind_backtrace from show_stack+0x18/0x1c\n show_stack from dump_stack_lvl+0x34/0x58\n dump_stack_lvl from print_report+0x154/0x500\n print_report from kasan_report+0xac/0xd8\n kasan_report from wilc_netdev_cleanup+0x508/0x5cc\n wilc_netdev_cleanup from wilc_bus_remove+0xc8/0xec\n wilc_bus_remove from spi_remove+0x8c/0xac\n spi_remove from device_release_driver_internal+0x434/0x5f8\n device_release_driver_internal from unbind_store+0xbc/0x108\n unbind_store from kernfs_fop_write_iter+0x398/0x584\n kernfs_fop_write_iter from vfs_write+0x728/0xf88\n vfs_write from ksys_write+0x110/0x1e4\n ksys_write from ret_fast_syscall+0x0/0x1c\n\n[...]\n\nAllocated by task 1:\n kasan_save_track+0x30/0x5c\n __kasan_kmalloc+0x8c/0x94\n __kmalloc_node+0x1cc/0x3e4\n kvmalloc_node+0x48/0x180\n alloc_netdev_mqs+0x68/0x11dc\n alloc_etherdev_mqs+0x28/0x34\n wilc_netdev_ifc_init+0x34/0x8ec\n wilc_cfg80211_init+0x690/0x910\n wilc_bus_probe+0xe0/0x4a0\n spi_probe+0x158/0x1b0\n really_probe+0x270/0xdf4\n __driver_probe_device+0x1dc/0x580\n driver_probe_device+0x60/0x140\n __driver_attach+0x228/0x5d4\n bus_for_each_dev+0x13c/0x1a8\n bus_add_driver+0x2a0/0x608\n driver_register+0x24c/0x578\n do_one_initcall+0x180/0x310\n kernel_init_freeable+0x424/0x484\n kernel_init+0x20/0x148\n ret_from_fork+0x14/0x28\n\nFreed by task 86:\n kasan_save_track+0x30/0x5c\n kasan_save_free_info+0x38/0x58\n __kasan_slab_free+0xe4/0x140\n kfree+0xb0/0x238\n device_release+0xc0/0x2a8\n kobject_put+0x1d4/0x46c\n netdev_run_todo+0x8fc/0x11d0\n wilc_netdev_cleanup+0x1e4/0x5cc\n wilc_bus_remove+0xc8/0xec\n spi_remove+0x8c/0xac\n device_release_driver_internal+0x434/0x5f8\n unbind_store+0xbc/0x108\n kernfs_fop_write_iter+0x398/0x584\n vfs_write+0x728/0xf88\n ksys_write+0x110/0x1e4\n ret_fast_syscall+0x0/0x1c\n [...]\n\nDavid Mosberger-Tan initial investigation [1] showed that this\nuse-after-free is due to netdevice unregistration during vif list\ntraversal. When unregistering a net device, since the needs_free_netdev has\nbeen set to true during registration, the netdevice object is also freed,\nand as a consequence, the corresponding vif object too, since it is\nattached to it as private netdevice data. The next occurrence of the loop\nthen tries to access freed vif pointer to the list to move forward in the\nlist.\n\nFix this use-after-free thanks to two mechanisms:\n- navigate in the list with list_for_each_entry_safe, which allows to\n safely modify the list as we go through each element. For each element,\n remove it from the list with list_del_rcu\n- make sure to wait for RCU grace period end after each vif removal to make\n sure it is safe to free the corresponding vif too (through\n unregister_netdev)\n\nSince we are in a RCU \"modifier\" path (not a \"reader\" path), and because\nsuch path is expected not to be concurrent to any other modifier (we are\nusing the vif_mutex lock), we do not need to use RCU list API, that's why\nwe can benefit from list_for_each_entry_safe.\n\n[1] https://lore.kernel.org/linux-wireless/ab077dbe58b1ea5de0a3b2ca21f275a07af967d2.camel@egauge.net/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9889-pmmf-cvr8/GHSA-9889-pmmf-cvr8.json b/advisories/unreviewed/2024/04/GHSA-9889-pmmf-cvr8/GHSA-9889-pmmf-cvr8.json index 1daa293a9ab..eecfa85f311 100644 --- a/advisories/unreviewed/2024/04/GHSA-9889-pmmf-cvr8/GHSA-9889-pmmf-cvr8.json +++ b/advisories/unreviewed/2024/04/GHSA-9889-pmmf-cvr8/GHSA-9889-pmmf-cvr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9889-pmmf-cvr8", - "modified": "2024-04-17T12:32:05Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26892" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921e: fix use-after-free in free_irq()\n\nFrom commit a304e1b82808 (\"[PATCH] Debug shared irqs\"), there is a test\nto make sure the shared irq handler should be able to handle the unexpected\nevent after deregistration. For this case, let's apply MT76_REMOVED flag to\nindicate the device was removed and do not run into the resource access\nanymore.\n\nBUG: KASAN: use-after-free in mt7921_irq_handler+0xd8/0x100 [mt7921e]\nRead of size 8 at addr ffff88824a7d3b78 by task rmmod/11115\nCPU: 28 PID: 11115 Comm: rmmod Tainted: G W L 5.17.0 #10\nHardware name: Micro-Star International Co., Ltd. MS-7D73/MPG B650I\nEDGE WIFI (MS-7D73), BIOS 1.81 01/05/2024\nCall Trace:\n \n dump_stack_lvl+0x6f/0xa0\n print_address_description.constprop.0+0x1f/0x190\n ? mt7921_irq_handler+0xd8/0x100 [mt7921e]\n ? mt7921_irq_handler+0xd8/0x100 [mt7921e]\n kasan_report.cold+0x7f/0x11b\n ? mt7921_irq_handler+0xd8/0x100 [mt7921e]\n mt7921_irq_handler+0xd8/0x100 [mt7921e]\n free_irq+0x627/0xaa0\n devm_free_irq+0x94/0xd0\n ? devm_request_any_context_irq+0x160/0x160\n ? kobject_put+0x18d/0x4a0\n mt7921_pci_remove+0x153/0x190 [mt7921e]\n pci_device_remove+0xa2/0x1d0\n __device_release_driver+0x346/0x6e0\n driver_detach+0x1ef/0x2c0\n bus_remove_driver+0xe7/0x2d0\n ? __check_object_size+0x57/0x310\n pci_unregister_driver+0x26/0x250\n __do_sys_delete_module+0x307/0x510\n ? free_module+0x6a0/0x6a0\n ? fpregs_assert_state_consistent+0x4b/0xb0\n ? rcu_read_lock_sched_held+0x10/0x70\n ? syscall_enter_from_user_mode+0x20/0x70\n ? trace_hardirqs_on+0x1c/0x130\n do_syscall_64+0x5c/0x80\n ? trace_hardirqs_on_prepare+0x72/0x160\n ? do_syscall_64+0x68/0x80\n ? trace_hardirqs_on_prepare+0x72/0x160\n entry_SYSCALL_64_after_hwframe+0x44/0xae", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9jpw-f586-mqqf/GHSA-9jpw-f586-mqqf.json b/advisories/unreviewed/2024/04/GHSA-9jpw-f586-mqqf/GHSA-9jpw-f586-mqqf.json index a731bac53ca..d018633ef3d 100644 --- a/advisories/unreviewed/2024/04/GHSA-9jpw-f586-mqqf/GHSA-9jpw-f586-mqqf.json +++ b/advisories/unreviewed/2024/04/GHSA-9jpw-f586-mqqf/GHSA-9jpw-f586-mqqf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9jpw-f586-mqqf", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47217" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/hyperv: Fix NULL deref in set_hv_tscchange_cb() if Hyper-V setup fails\n\nCheck for a valid hv_vp_index array prior to derefencing hv_vp_index when\nsetting Hyper-V's TSC change callback. If Hyper-V setup failed in\nhyperv_init(), the kernel will still report that it's running under\nHyper-V, but will have silently disabled nearly all functionality.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP\n CPU: 4 PID: 1 Comm: swapper/0 Not tainted 5.15.0-rc2+ #75\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n RIP: 0010:set_hv_tscchange_cb+0x15/0xa0\n Code: <8b> 04 82 8b 15 12 17 85 01 48 c1 e0 20 48 0d ee 00 01 00 f6 c6 08\n ...\n Call Trace:\n kvm_arch_init+0x17c/0x280\n kvm_init+0x31/0x330\n vmx_init+0xba/0x13a\n do_one_initcall+0x41/0x1c0\n kernel_init_freeable+0x1f2/0x23b\n kernel_init+0x16/0x120\n ret_from_fork+0x22/0x30", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9rc8-c76x-36m2/GHSA-9rc8-c76x-36m2.json b/advisories/unreviewed/2024/04/GHSA-9rc8-c76x-36m2/GHSA-9rc8-c76x-36m2.json index bcea88e10c3..019833968e9 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rc8-c76x-36m2/GHSA-9rc8-c76x-36m2.json +++ b/advisories/unreviewed/2024/04/GHSA-9rc8-c76x-36m2/GHSA-9rc8-c76x-36m2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rc8-c76x-36m2", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47204" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dpaa2-eth: fix use-after-free in dpaa2_eth_remove\n\nAccess to netdev after free_netdev() will cause use-after-free bug.\nMove debug log before free_netdev() call to avoid it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h6wr-63v9-2m6h/GHSA-h6wr-63v9-2m6h.json b/advisories/unreviewed/2024/04/GHSA-h6wr-63v9-2m6h/GHSA-h6wr-63v9-2m6h.json index 673342eb719..912ee03d7a9 100644 --- a/advisories/unreviewed/2024/04/GHSA-h6wr-63v9-2m6h/GHSA-h6wr-63v9-2m6h.json +++ b/advisories/unreviewed/2024/04/GHSA-h6wr-63v9-2m6h/GHSA-h6wr-63v9-2m6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6wr-63v9-2m6h", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47218" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix NULL-pointer dereference when hashtab allocation fails\n\nWhen the hash table slot array allocation fails in hashtab_init(),\nh->size is left initialized with a non-zero value, but the h->htable\npointer is NULL. This may then cause a NULL pointer dereference, since\nthe policydb code relies on the assumption that even after a failed\nhashtab_init(), hashtab_map() and hashtab_destroy() can be safely called\non it. Yet, these detect an empty hashtab only by looking at the size.\n\nFix this by making sure that hashtab_init() always leaves behind a valid\nempty hashtab when the allocation fails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json b/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json index 03c86ad59e8..6fa25b6e2a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json +++ b/advisories/unreviewed/2024/04/GHSA-jg7c-h6xh-f8hr/GHSA-jg7c-h6xh-f8hr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jg7c-h6xh-f8hr", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26878" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix potential NULL pointer dereference\n\nBelow race may cause NULL pointer dereference\n\nP1\t\t\t\t\tP2\ndquot_free_inode\t\t\tquota_off\n\t\t\t\t\t drop_dquot_ref\n\t\t\t\t\t remove_dquot_ref\n\t\t\t\t\t dquots = i_dquot(inode)\n dquots = i_dquot(inode)\n srcu_read_lock\n dquots[cnt]) != NULL (1)\n\t\t\t\t\t dquots[type] = NULL (2)\n spin_lock(&dquots[cnt]->dq_dqb_lock) (3)\n ....\n\nIf dquot_free_inode(or other routines) checks inode's quota pointers (1)\nbefore quota_off sets it to NULL(2) and use it (3) after that, NULL pointer\ndereference will be triggered.\n\nSo let's fix it by using a temporary pointer to avoid this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json b/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json index 9551818f6ed..da00319d152 100644 --- a/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json +++ b/advisories/unreviewed/2024/04/GHSA-qvjm-pcpv-593p/GHSA-qvjm-pcpv-593p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvjm-pcpv-593p", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-04-17T12:32:03Z", "aliases": [ "CVE-2024-26839" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix a memleak in init_credit_return\n\nWhen dma_alloc_coherent fails to allocate dd->cr_base[i].va,\ninit_credit_return should deallocate dd->cr_base and\ndd->cr_base[i] that allocated before. Or those resources\nwould be never freed and a memleak is triggered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rv79-7m3p-hx2p/GHSA-rv79-7m3p-hx2p.json b/advisories/unreviewed/2024/04/GHSA-rv79-7m3p-hx2p/GHSA-rv79-7m3p-hx2p.json index 7ae64e2aefb..42e8e9b7075 100644 --- a/advisories/unreviewed/2024/04/GHSA-rv79-7m3p-hx2p/GHSA-rv79-7m3p-hx2p.json +++ b/advisories/unreviewed/2024/04/GHSA-rv79-7m3p-hx2p/GHSA-rv79-7m3p-hx2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rv79-7m3p-hx2p", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47211" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix null pointer dereference on pointer cs_desc\n\nThe pointer cs_desc return from snd_usb_find_clock_source could\nbe null, so there is a potential null pointer dereference issue.\nFix this by adding a null check before dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w6pp-7vhg-w878/GHSA-w6pp-7vhg-w878.json b/advisories/unreviewed/2024/04/GHSA-w6pp-7vhg-w878/GHSA-w6pp-7vhg-w878.json index 08109711558..cd046fdc95f 100644 --- a/advisories/unreviewed/2024/04/GHSA-w6pp-7vhg-w878/GHSA-w6pp-7vhg-w878.json +++ b/advisories/unreviewed/2024/04/GHSA-w6pp-7vhg-w878/GHSA-w6pp-7vhg-w878.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w6pp-7vhg-w878", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47202" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: Fix NULL pointer dereferences in of_thermal_ functions\n\nof_parse_thermal_zones() parses the thermal-zones node and registers a\nthermal_zone device for each subnode. However, if a thermal zone is\nconsuming a thermal sensor and that thermal sensor device hasn't probed\nyet, an attempt to set trip_point_*_temp for that thermal zone device\ncan cause a NULL pointer dereference. Fix it.\n\n console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp\n ...\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020\n ...\n Call trace:\n of_thermal_set_trip_temp+0x40/0xc4\n trip_point_temp_store+0xc0/0x1dc\n dev_attr_store+0x38/0x88\n sysfs_kf_write+0x64/0xc0\n kernfs_fop_write_iter+0x108/0x1d0\n vfs_write+0x2f4/0x368\n ksys_write+0x7c/0xec\n __arm64_sys_write+0x20/0x30\n el0_svc_common.llvm.7279915941325364641+0xbc/0x1bc\n do_el0_svc+0x28/0xa0\n el0_svc+0x14/0x24\n el0_sync_handler+0x88/0xec\n el0_sync+0x1c0/0x200\n\nWhile at it, fix the possible NULL pointer dereference in other\nfunctions as well: of_thermal_get_temp(), of_thermal_set_emul_temp(),\nof_thermal_get_trend().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w7cg-566v-rm5v/GHSA-w7cg-566v-rm5v.json b/advisories/unreviewed/2024/04/GHSA-w7cg-566v-rm5v/GHSA-w7cg-566v-rm5v.json index da9a4df20d7..1ab311d5ca2 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7cg-566v-rm5v/GHSA-w7cg-566v-rm5v.json +++ b/advisories/unreviewed/2024/04/GHSA-w7cg-566v-rm5v/GHSA-w7cg-566v-rm5v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7cg-566v-rm5v", - "modified": "2024-04-17T12:32:04Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26868" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: fix panic when nfs4_ff_layout_prepare_ds() fails\n\nWe've been seeing the following panic in production\n\nBUG: kernel NULL pointer dereference, address: 0000000000000065\nPGD 2f485f067 P4D 2f485f067 PUD 2cc5d8067 PMD 0\nRIP: 0010:ff_layout_cancel_io+0x3a/0x90 [nfs_layout_flexfiles]\nCall Trace:\n \n ? __die+0x78/0xc0\n ? page_fault_oops+0x286/0x380\n ? __rpc_execute+0x2c3/0x470 [sunrpc]\n ? rpc_new_task+0x42/0x1c0 [sunrpc]\n ? exc_page_fault+0x5d/0x110\n ? asm_exc_page_fault+0x22/0x30\n ? ff_layout_free_layoutreturn+0x110/0x110 [nfs_layout_flexfiles]\n ? ff_layout_cancel_io+0x3a/0x90 [nfs_layout_flexfiles]\n ? ff_layout_cancel_io+0x6f/0x90 [nfs_layout_flexfiles]\n pnfs_mark_matching_lsegs_return+0x1b0/0x360 [nfsv4]\n pnfs_error_mark_layout_for_return+0x9e/0x110 [nfsv4]\n ? ff_layout_send_layouterror+0x50/0x160 [nfs_layout_flexfiles]\n nfs4_ff_layout_prepare_ds+0x11f/0x290 [nfs_layout_flexfiles]\n ff_layout_pg_init_write+0xf0/0x1f0 [nfs_layout_flexfiles]\n __nfs_pageio_add_request+0x154/0x6c0 [nfs]\n nfs_pageio_add_request+0x26b/0x380 [nfs]\n nfs_do_writepage+0x111/0x1e0 [nfs]\n nfs_writepages_callback+0xf/0x30 [nfs]\n write_cache_pages+0x17f/0x380\n ? nfs_pageio_init_write+0x50/0x50 [nfs]\n ? nfs_writepages+0x6d/0x210 [nfs]\n ? nfs_writepages+0x6d/0x210 [nfs]\n nfs_writepages+0x125/0x210 [nfs]\n do_writepages+0x67/0x220\n ? generic_perform_write+0x14b/0x210\n filemap_fdatawrite_wbc+0x5b/0x80\n file_write_and_wait_range+0x6d/0xc0\n nfs_file_fsync+0x81/0x170 [nfs]\n ? nfs_file_mmap+0x60/0x60 [nfs]\n __x64_sys_fsync+0x53/0x90\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nInspecting the core with drgn I was able to pull this\n\n >>> prog.crashed_thread().stack_trace()[0]\n #0 at 0xffffffffa079657a (ff_layout_cancel_io+0x3a/0x84) in ff_layout_cancel_io at fs/nfs/flexfilelayout/flexfilelayout.c:2021:27\n >>> prog.crashed_thread().stack_trace()[0]['idx']\n (u32)1\n >>> prog.crashed_thread().stack_trace()[0]['flseg'].mirror_array[1].mirror_ds\n (struct nfs4_ff_layout_ds *)0xffffffffffffffed\n\nThis is clear from the stack trace, we call nfs4_ff_layout_prepare_ds()\nwhich could error out initializing the mirror_ds, and then we go to\nclean it all up and our check is only for if (!mirror->mirror_ds). This\nis inconsistent with the rest of the users of mirror_ds, which have\n\n if (IS_ERR_OR_NULL(mirror_ds))\n\nto keep from tripping over this exact scenario. Fix this up in\nff_layout_cancel_io() to make sure we don't panic when we get an error.\nI also spot checked all the other instances of checking mirror_ds and we\nappear to be doing the correct checks everywhere, only unconditionally\ndereferencing mirror_ds when we know it would be valid.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w82p-p27g-2qgq/GHSA-w82p-p27g-2qgq.json b/advisories/unreviewed/2024/04/GHSA-w82p-p27g-2qgq/GHSA-w82p-p27g-2qgq.json index 90e68cb5072..6db8c9a3a19 100644 --- a/advisories/unreviewed/2024/04/GHSA-w82p-p27g-2qgq/GHSA-w82p-p27g-2qgq.json +++ b/advisories/unreviewed/2024/04/GHSA-w82p-p27g-2qgq/GHSA-w82p-p27g-2qgq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w82p-p27g-2qgq", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-01-14T15:30:48Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2023-52643" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: core: fix memleak in iio_device_register_sysfs\n\nWhen iio_device_register_sysfs_group() fails, we should\nfree iio_dev_opaque->chan_attr_group.attrs to prevent\npotential memleak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xgx4-jvp8-p2h2/GHSA-xgx4-jvp8-p2h2.json b/advisories/unreviewed/2024/04/GHSA-xgx4-jvp8-p2h2/GHSA-xgx4-jvp8-p2h2.json index 80ad79192cd..487ddf63cde 100644 --- a/advisories/unreviewed/2024/04/GHSA-xgx4-jvp8-p2h2/GHSA-xgx4-jvp8-p2h2.json +++ b/advisories/unreviewed/2024/04/GHSA-xgx4-jvp8-p2h2/GHSA-xgx4-jvp8-p2h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgx4-jvp8-p2h2", - "modified": "2024-04-28T15:30:30Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-04-28T15:30:30Z", "aliases": [ "CVE-2022-48663" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mockup: fix NULL pointer dereference when removing debugfs\n\nWe now remove the device's debugfs entries when unbinding the driver.\nThis now causes a NULL-pointer dereference on module exit because the\nplatform devices are unregistered *after* the global debugfs directory\nhas been recursively removed. Fix it by unregistering the devices first.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6264-3hhv-77hg/GHSA-6264-3hhv-77hg.json b/advisories/unreviewed/2024/05/GHSA-6264-3hhv-77hg/GHSA-6264-3hhv-77hg.json index 4a787aea2f9..94f5308b4e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-6264-3hhv-77hg/GHSA-6264-3hhv-77hg.json +++ b/advisories/unreviewed/2024/05/GHSA-6264-3hhv-77hg/GHSA-6264-3hhv-77hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6264-3hhv-77hg", - "modified": "2024-06-27T15:30:39Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-17T15:31:10Z", "aliases": [ "CVE-2024-35828" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer()\n\nIn the for statement of lbs_allocate_cmd_buffer(), if the allocation of\ncmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to\nbe freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json b/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json index 0202c8bfdea..c10d25fd06c 100644 --- a/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json +++ b/advisories/unreviewed/2024/05/GHSA-97fh-3x83-fvh6/GHSA-97fh-3x83-fvh6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97fh-3x83-fvh6", - "modified": "2024-06-27T12:30:46Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27395" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: Fix Use-After-Free in ovs_ct_exit\n\nSince kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof ovs_ct_limit_exit, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:12:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m253-3j38-482h/GHSA-m253-3j38-482h.json b/advisories/unreviewed/2024/05/GHSA-m253-3j38-482h/GHSA-m253-3j38-482h.json index 73545963c3a..95f55dbc638 100644 --- a/advisories/unreviewed/2024/05/GHSA-m253-3j38-482h/GHSA-m253-3j38-482h.json +++ b/advisories/unreviewed/2024/05/GHSA-m253-3j38-482h/GHSA-m253-3j38-482h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m253-3j38-482h", - "modified": "2024-06-27T15:30:39Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-17T15:31:09Z", "aliases": [ "CVE-2024-35811" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach\n\nThis is the candidate patch of CVE-2023-47233 :\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-47233\n\nIn brcm80211 driver,it starts with the following invoking chain\nto start init a timeout worker:\n\n->brcmf_usb_probe\n ->brcmf_usb_probe_cb\n ->brcmf_attach\n ->brcmf_bus_started\n ->brcmf_cfg80211_attach\n ->wl_init_priv\n ->brcmf_init_escan\n ->INIT_WORK(&cfg->escan_timeout_work,\n\t\t brcmf_cfg80211_escan_timeout_worker);\n\nIf we disconnect the USB by hotplug, it will call\nbrcmf_usb_disconnect to make cleanup. The invoking chain is :\n\nbrcmf_usb_disconnect\n ->brcmf_usb_disconnect_cb\n ->brcmf_detach\n ->brcmf_cfg80211_detach\n ->kfree(cfg);\n\nWhile the timeout woker may still be running. This will cause\na use-after-free bug on cfg in brcmf_cfg80211_escan_timeout_worker.\n\nFix it by deleting the timer and canceling the worker in\nbrcmf_cfg80211_detach.\n\n[arend.vanspriel@broadcom.com: keep timer delete as is and cancel work just before free]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json b/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json index f085e2c9dc1..cbdf8b7769c 100644 --- a/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json +++ b/advisories/unreviewed/2024/05/GHSA-mvq3-v998-w43f/GHSA-mvq3-v998-w43f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mvq3-v998-w43f", - "modified": "2024-06-27T12:30:46Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27396" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gtp: Fix Use-After-Free in gtp_dellink\n\nSince call_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof gtp_dellink, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:12:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p6xg-jwxf-89ch/GHSA-p6xg-jwxf-89ch.json b/advisories/unreviewed/2024/05/GHSA-p6xg-jwxf-89ch/GHSA-p6xg-jwxf-89ch.json index d59cb5dca87..a724fcbd977 100644 --- a/advisories/unreviewed/2024/05/GHSA-p6xg-jwxf-89ch/GHSA-p6xg-jwxf-89ch.json +++ b/advisories/unreviewed/2024/05/GHSA-p6xg-jwxf-89ch/GHSA-p6xg-jwxf-89ch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6xg-jwxf-89ch", - "modified": "2024-05-20T12:30:28Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35968" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: Fix pdsc_check_pci_health function to use work thread\n\nWhen the driver notices fw_status == 0xff it tries to perform a PCI\nreset on itself via pci_reset_function() in the context of the driver's\nhealth thread. However, pdsc_reset_prepare calls\npdsc_stop_health_thread(), which attempts to stop/flush the health\nthread. This results in a deadlock because the stop/flush will never\ncomplete since the driver called pci_reset_function() from the health\nthread context. Fix by changing the pdsc_check_pci_health_function()\nto queue a newly introduced pdsc_pci_reset_thread() on the pdsc's\nwork queue.\n\nUnloading the driver in the fw_down/dead state uncovered another issue,\nwhich can be seen in the following trace:\n\nWARNING: CPU: 51 PID: 6914 at kernel/workqueue.c:1450 __queue_work+0x358/0x440\n[...]\nRIP: 0010:__queue_work+0x358/0x440\n[...]\nCall Trace:\n \n ? __warn+0x85/0x140\n ? __queue_work+0x358/0x440\n ? report_bug+0xfc/0x1e0\n ? handle_bug+0x3f/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? __queue_work+0x358/0x440\n queue_work_on+0x28/0x30\n pdsc_devcmd_locked+0x96/0xe0 [pds_core]\n pdsc_devcmd_reset+0x71/0xb0 [pds_core]\n pdsc_teardown+0x51/0xe0 [pds_core]\n pdsc_remove+0x106/0x200 [pds_core]\n pci_device_remove+0x37/0xc0\n device_release_driver_internal+0xae/0x140\n driver_detach+0x48/0x90\n bus_remove_driver+0x6d/0xf0\n pci_unregister_driver+0x2e/0xa0\n pdsc_cleanup_module+0x10/0x780 [pds_core]\n __x64_sys_delete_module+0x142/0x2b0\n ? syscall_trace_enter.isra.18+0x126/0x1a0\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\nRIP: 0033:0x7fbd9d03a14b\n[...]\n\nFix this by preventing the devcmd reset if the FW is not running.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-phc9-mf56-r5f6/GHSA-phc9-mf56-r5f6.json b/advisories/unreviewed/2024/05/GHSA-phc9-mf56-r5f6/GHSA-phc9-mf56-r5f6.json index 03ae5a7dc05..db64dbc0d58 100644 --- a/advisories/unreviewed/2024/05/GHSA-phc9-mf56-r5f6/GHSA-phc9-mf56-r5f6.json +++ b/advisories/unreviewed/2024/05/GHSA-phc9-mf56-r5f6/GHSA-phc9-mf56-r5f6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phc9-mf56-r5f6", - "modified": "2024-05-01T06:31:41Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-01T06:31:41Z", "aliases": [ "CVE-2024-26944" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix use-after-free in do_zone_finish()\n\nShinichiro reported the following use-after-free triggered by the device\nreplace operation in fstests btrfs/070.\n\n BTRFS info (device nullb1): scrub: finished on devid 1 with status: 0\n ==================================================================\n BUG: KASAN: slab-use-after-free in do_zone_finish+0x91a/0xb90 [btrfs]\n Read of size 8 at addr ffff8881543c8060 by task btrfs-cleaner/3494007\n\n CPU: 0 PID: 3494007 Comm: btrfs-cleaner Tainted: G W 6.8.0-rc5-kts #1\n Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020\n Call Trace:\n \n dump_stack_lvl+0x5b/0x90\n print_report+0xcf/0x670\n ? __virt_addr_valid+0x200/0x3e0\n kasan_report+0xd8/0x110\n ? do_zone_finish+0x91a/0xb90 [btrfs]\n ? do_zone_finish+0x91a/0xb90 [btrfs]\n do_zone_finish+0x91a/0xb90 [btrfs]\n btrfs_delete_unused_bgs+0x5e1/0x1750 [btrfs]\n ? __pfx_btrfs_delete_unused_bgs+0x10/0x10 [btrfs]\n ? btrfs_put_root+0x2d/0x220 [btrfs]\n ? btrfs_clean_one_deleted_snapshot+0x299/0x430 [btrfs]\n cleaner_kthread+0x21e/0x380 [btrfs]\n ? __pfx_cleaner_kthread+0x10/0x10 [btrfs]\n kthread+0x2e3/0x3c0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n\n Allocated by task 3493983:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n btrfs_alloc_device+0xb3/0x4e0 [btrfs]\n device_list_add.constprop.0+0x993/0x1630 [btrfs]\n btrfs_scan_one_device+0x219/0x3d0 [btrfs]\n btrfs_control_ioctl+0x26e/0x310 [btrfs]\n __x64_sys_ioctl+0x134/0x1b0\n do_syscall_64+0x99/0x190\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 3494056:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3f/0x60\n poison_slab_object+0x102/0x170\n __kasan_slab_free+0x32/0x70\n kfree+0x11b/0x320\n btrfs_rm_dev_replace_free_srcdev+0xca/0x280 [btrfs]\n btrfs_dev_replace_finishing+0xd7e/0x14f0 [btrfs]\n btrfs_dev_replace_by_ioctl+0x1286/0x25a0 [btrfs]\n btrfs_ioctl+0xb27/0x57d0 [btrfs]\n __x64_sys_ioctl+0x134/0x1b0\n do_syscall_64+0x99/0x190\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n The buggy address belongs to the object at ffff8881543c8000\n which belongs to the cache kmalloc-1k of size 1024\n The buggy address is located 96 bytes inside of\n freed 1024-byte region [ffff8881543c8000, ffff8881543c8400)\n\n The buggy address belongs to the physical page:\n page:00000000fe2c1285 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1543c8\n head:00000000fe2c1285 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n flags: 0x17ffffc0000840(slab|head|node=0|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0017ffffc0000840 ffff888100042dc0 ffffea0019e8f200 dead000000000002\n raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff8881543c7f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff8881543c7f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n >ffff8881543c8000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff8881543c8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff8881543c8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n\nThis UAF happens because we're accessing stale zone information of a\nalready removed btrfs_device in do_zone_finish().\n\nThe sequence of events is as follows:\n\nbtrfs_dev_replace_start\n btrfs_scrub_dev\n btrfs_dev_replace_finishing\n btrfs_dev_replace_update_device_in_mapping_tree <-- devices replaced\n btrfs_rm_dev_replace_free_srcdev\n btrfs_free_device <-- device freed\n\ncleaner_kthread\n btrfs_delete_unused_bgs\n btrfs_zone_finish\n do_zone_finish <-- refers the freed device\n\nThe reason for this is that we're using a\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qh82-7chj-9876/GHSA-qh82-7chj-9876.json b/advisories/unreviewed/2024/05/GHSA-qh82-7chj-9876/GHSA-qh82-7chj-9876.json index 27f7b545821..c715ed5dc42 100644 --- a/advisories/unreviewed/2024/05/GHSA-qh82-7chj-9876/GHSA-qh82-7chj-9876.json +++ b/advisories/unreviewed/2024/05/GHSA-qh82-7chj-9876/GHSA-qh82-7chj-9876.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qh82-7chj-9876", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-01T15:30:37Z", "aliases": [ "CVE-2024-27388" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix some memleaks in gssx_dec_option_array\n\nThe creds and oa->data need to be freed in the error-handling paths after\ntheir allocation. So this patch add these deallocations in the\ncorresponding paths.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qpg3-72fq-2rqh/GHSA-qpg3-72fq-2rqh.json b/advisories/unreviewed/2024/05/GHSA-qpg3-72fq-2rqh/GHSA-qpg3-72fq-2rqh.json index 36aae4f60d8..53caa53d280 100644 --- a/advisories/unreviewed/2024/05/GHSA-qpg3-72fq-2rqh/GHSA-qpg3-72fq-2rqh.json +++ b/advisories/unreviewed/2024/05/GHSA-qpg3-72fq-2rqh/GHSA-qpg3-72fq-2rqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qpg3-72fq-2rqh", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27059" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usb-storage: Prevent divide-by-0 error in isd200_ata_command\n\nThe isd200 sub-driver in usb-storage uses the HEADS and SECTORS values\nin the ATA ID information to calculate cylinder and head values when\ncreating a CDB for READ or WRITE commands. The calculation involves\ndivision and modulus operations, which will cause a crash if either of\nthese values is 0. While this never happens with a genuine device, it\ncould happen with a flawed or subversive emulation, as reported by the\nsyzbot fuzzer.\n\nProtect against this possibility by refusing to bind to the device if\neither the ATA_ID_HEADS or ATA_ID_SECTORS value in the device's ID\ninformation is 0. This requires isd200_Initialization() to return a\nnegative error code when initialization fails; currently it always\nreturns 0 (even when there is an error).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json b/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json index 5a10209893c..f22f1a7dba6 100644 --- a/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json +++ b/advisories/unreviewed/2024/05/GHSA-w29x-26qv-fmmq/GHSA-w29x-26qv-fmmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w29x-26qv-fmmq", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2023-52662" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node\n\nWhen ida_alloc_max fails, resources allocated before should be freed,\nincluding *res allocated by kmalloc and ttm_resource_init.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x846-9rxh-mcv9/GHSA-x846-9rxh-mcv9.json b/advisories/unreviewed/2024/05/GHSA-x846-9rxh-mcv9/GHSA-x846-9rxh-mcv9.json index e0da02fec50..0920ae3310c 100644 --- a/advisories/unreviewed/2024/05/GHSA-x846-9rxh-mcv9/GHSA-x846-9rxh-mcv9.json +++ b/advisories/unreviewed/2024/05/GHSA-x846-9rxh-mcv9/GHSA-x846-9rxh-mcv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x846-9rxh-mcv9", - "modified": "2024-05-01T06:31:41Z", + "modified": "2025-01-14T15:30:49Z", "published": "2024-05-01T06:31:41Z", "aliases": [ "CVE-2024-26941" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp: Fix divide-by-zero regression on DP MST unplug with nouveau\n\nFix a regression when using nouveau and unplugging a StarTech MSTDP122DP\nDisplayPort 1.2 MST hub (the same regression does not appear when using\na Cable Matters DisplayPort 1.4 MST hub). Trace:\n\n divide error: 0000 [#1] PREEMPT SMP PTI\n CPU: 7 PID: 2962 Comm: Xorg Not tainted 6.8.0-rc3+ #744\n Hardware name: Razer Blade/DANA_MB, BIOS 01.01 08/31/2018\n RIP: 0010:drm_dp_bw_overhead+0xb4/0x110 [drm_display_helper]\n Code: c6 b8 01 00 00 00 75 61 01 c6 41 0f af f3 41 0f af f1 c1 e1 04 48 63 c7 31 d2 89 ff 48 8b 5d f8 c9 48 0f af f1 48 8d 44 06 ff <48> f7 f7 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 45 31\n RSP: 0018:ffffb2c5c211fa30 EFLAGS: 00010206\n RAX: ffffffffffffffff RBX: 0000000000000000 RCX: 0000000000f59b00\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: ffffb2c5c211fa48 R08: 0000000000000001 R09: 0000000000000020\n R10: 0000000000000004 R11: 0000000000000000 R12: 0000000000023b4a\n R13: ffff91d37d165800 R14: ffff91d36fac6d80 R15: ffff91d34a764010\n FS: 00007f4a1ca3fa80(0000) GS:ffff91d6edbc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000559491d49000 CR3: 000000011d180002 CR4: 00000000003706f0\n Call Trace:\n \n ? show_regs+0x6d/0x80\n ? die+0x37/0xa0\n ? do_trap+0xd4/0xf0\n ? do_error_trap+0x71/0xb0\n ? drm_dp_bw_overhead+0xb4/0x110 [drm_display_helper]\n ? exc_divide_error+0x3a/0x70\n ? drm_dp_bw_overhead+0xb4/0x110 [drm_display_helper]\n ? asm_exc_divide_error+0x1b/0x20\n ? drm_dp_bw_overhead+0xb4/0x110 [drm_display_helper]\n ? drm_dp_calc_pbn_mode+0x2e/0x70 [drm_display_helper]\n nv50_msto_atomic_check+0xda/0x120 [nouveau]\n drm_atomic_helper_check_modeset+0xa87/0xdf0 [drm_kms_helper]\n drm_atomic_helper_check+0x19/0xa0 [drm_kms_helper]\n nv50_disp_atomic_check+0x13f/0x2f0 [nouveau]\n drm_atomic_check_only+0x668/0xb20 [drm]\n ? drm_connector_list_iter_next+0x86/0xc0 [drm]\n drm_atomic_commit+0x58/0xd0 [drm]\n ? __pfx___drm_printfn_info+0x10/0x10 [drm]\n drm_atomic_connector_commit_dpms+0xd7/0x100 [drm]\n drm_mode_obj_set_property_ioctl+0x1c5/0x450 [drm]\n ? __pfx_drm_connector_property_set_ioctl+0x10/0x10 [drm]\n drm_connector_property_set_ioctl+0x3b/0x60 [drm]\n drm_ioctl_kernel+0xb9/0x120 [drm]\n drm_ioctl+0x2d0/0x550 [drm]\n ? __pfx_drm_connector_property_set_ioctl+0x10/0x10 [drm]\n nouveau_drm_ioctl+0x61/0xc0 [nouveau]\n __x64_sys_ioctl+0xa0/0xf0\n do_syscall_64+0x76/0x140\n ? do_syscall_64+0x85/0x140\n ? do_syscall_64+0x85/0x140\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n RIP: 0033:0x7f4a1cd1a94f\n Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <41> 89 c0 3d 00 f0 ff ff 77 1f 48 8b 44 24 18 64 48 2b 04 25 28 00\n RSP: 002b:00007ffd2f1df520 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 00007ffd2f1df5b0 RCX: 00007f4a1cd1a94f\n RDX: 00007ffd2f1df5b0 RSI: 00000000c01064ab RDI: 000000000000000f\n RBP: 00000000c01064ab R08: 000056347932deb8 R09: 000056347a7d99c0\n R10: 0000000000000000 R11: 0000000000000246 R12: 000056347938a220\n R13: 000000000000000f R14: 0000563479d9f3f0 R15: 0000000000000000\n \n Modules linked in: rfcomm xt_conntrack nft_chain_nat xt_MASQUERADE nf_nat nf_conntrack_netlink nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xfrm_user xfrm_algo xt_addrtype nft_compat nf_tables nfnetlink br_netfilter bridge stp llc ccm cmac algif_hash overlay algif_skcipher af_alg bnep binfmt_misc snd_sof_pci_intel_cnl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_pci snd_sof_xtensa_dsp snd_sof_intel_hda snd_sof snd_sof_utils snd_soc_acpi_intel_match snd_soc_acpi snd_soc_core snd_compress snd_sof_intel_hda_mlink snd_hda_ext_core iwlmvm intel_rapl_msr intel_rapl_common intel_tcc_cooling x86_pkg_temp_thermal intel_powerclamp mac80211 coretemp kvm_intel snd_hda_codec_hdmi kvm snd_hda_\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7f25-p8gc-hxqh/GHSA-7f25-p8gc-hxqh.json b/advisories/unreviewed/2024/10/GHSA-7f25-p8gc-hxqh/GHSA-7f25-p8gc-hxqh.json index 9856ce9a03a..9b149bad7a4 100644 --- a/advisories/unreviewed/2024/10/GHSA-7f25-p8gc-hxqh/GHSA-7f25-p8gc-hxqh.json +++ b/advisories/unreviewed/2024/10/GHSA-7f25-p8gc-hxqh/GHSA-7f25-p8gc-hxqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f25-p8gc-hxqh", - "modified": "2024-10-22T18:32:11Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-10-22T18:32:11Z", "aliases": [ "CVE-2024-50312" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/openshift/console/pull/14409/files" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0115" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-50312" diff --git a/advisories/unreviewed/2024/12/GHSA-3747-237p-gqq2/GHSA-3747-237p-gqq2.json b/advisories/unreviewed/2024/12/GHSA-3747-237p-gqq2/GHSA-3747-237p-gqq2.json index 9db4c6857d5..03252864d41 100644 --- a/advisories/unreviewed/2024/12/GHSA-3747-237p-gqq2/GHSA-3747-237p-gqq2.json +++ b/advisories/unreviewed/2024/12/GHSA-3747-237p-gqq2/GHSA-3747-237p-gqq2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3747-237p-gqq2", - "modified": "2025-01-09T18:32:13Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56582" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free in btrfs_encoded_read_endio()\n\nShinichiro reported the following use-after free that sometimes is\nhappening in our CI system when running fstests' btrfs/284 on a TCMU\nrunner device:\n\n BUG: KASAN: slab-use-after-free in lock_release+0x708/0x780\n Read of size 8 at addr ffff888106a83f18 by task kworker/u80:6/219\n\n CPU: 8 UID: 0 PID: 219 Comm: kworker/u80:6 Not tainted 6.12.0-rc6-kts+ #15\n Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020\n Workqueue: btrfs-endio btrfs_end_bio_work [btrfs]\n Call Trace:\n \n dump_stack_lvl+0x6e/0xa0\n ? lock_release+0x708/0x780\n print_report+0x174/0x505\n ? lock_release+0x708/0x780\n ? __virt_addr_valid+0x224/0x410\n ? lock_release+0x708/0x780\n kasan_report+0xda/0x1b0\n ? lock_release+0x708/0x780\n ? __wake_up+0x44/0x60\n lock_release+0x708/0x780\n ? __pfx_lock_release+0x10/0x10\n ? __pfx_do_raw_spin_lock+0x10/0x10\n ? lock_is_held_type+0x9a/0x110\n _raw_spin_unlock_irqrestore+0x1f/0x60\n __wake_up+0x44/0x60\n btrfs_encoded_read_endio+0x14b/0x190 [btrfs]\n btrfs_check_read_bio+0x8d9/0x1360 [btrfs]\n ? lock_release+0x1b0/0x780\n ? trace_lock_acquire+0x12f/0x1a0\n ? __pfx_btrfs_check_read_bio+0x10/0x10 [btrfs]\n ? process_one_work+0x7e3/0x1460\n ? lock_acquire+0x31/0xc0\n ? process_one_work+0x7e3/0x1460\n process_one_work+0x85c/0x1460\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x16c/0x240\n worker_thread+0x5e6/0xfc0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x2c3/0x3a0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\n Allocated by task 3661:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n btrfs_encoded_read_regular_fill_pages+0x16c/0x6d0 [btrfs]\n send_extent_data+0xf0f/0x24a0 [btrfs]\n process_extent+0x48a/0x1830 [btrfs]\n changed_cb+0x178b/0x2ea0 [btrfs]\n btrfs_ioctl_send+0x3bf9/0x5c20 [btrfs]\n _btrfs_ioctl_send+0x117/0x330 [btrfs]\n btrfs_ioctl+0x184a/0x60a0 [btrfs]\n __x64_sys_ioctl+0x12e/0x1a0\n do_syscall_64+0x95/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 3661:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x70\n __kasan_slab_free+0x4f/0x70\n kfree+0x143/0x490\n btrfs_encoded_read_regular_fill_pages+0x531/0x6d0 [btrfs]\n send_extent_data+0xf0f/0x24a0 [btrfs]\n process_extent+0x48a/0x1830 [btrfs]\n changed_cb+0x178b/0x2ea0 [btrfs]\n btrfs_ioctl_send+0x3bf9/0x5c20 [btrfs]\n _btrfs_ioctl_send+0x117/0x330 [btrfs]\n btrfs_ioctl+0x184a/0x60a0 [btrfs]\n __x64_sys_ioctl+0x12e/0x1a0\n do_syscall_64+0x95/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff888106a83f00\n which belongs to the cache kmalloc-rnd-07-96 of size 96\n The buggy address is located 24 bytes inside of\n freed 96-byte region [ffff888106a83f00, ffff888106a83f60)\n\n The buggy address belongs to the physical page:\n page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888106a83800 pfn:0x106a83\n flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff)\n page_type: f5(slab)\n raw: 0017ffffc0000000 ffff888100053680 ffffea0004917200 0000000000000004\n raw: ffff888106a83800 0000000080200019 00000001f5000000 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888106a83e00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff888106a83e80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n >ffff888106a83f00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ^\n ffff888106a83f80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff888106a84000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ==================================================================\n\nFurther analyzing the trace and \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3h24-5m24-pxvw/GHSA-3h24-5m24-pxvw.json b/advisories/unreviewed/2024/12/GHSA-3h24-5m24-pxvw/GHSA-3h24-5m24-pxvw.json index 34a68b2446b..70b5785dcd0 100644 --- a/advisories/unreviewed/2024/12/GHSA-3h24-5m24-pxvw/GHSA-3h24-5m24-pxvw.json +++ b/advisories/unreviewed/2024/12/GHSA-3h24-5m24-pxvw/GHSA-3h24-5m24-pxvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3h24-5m24-pxvw", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56604" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()\n\nbt_sock_alloc() attaches allocated sk object to the provided sock object.\nIf rfcomm_dlc_alloc() fails, we release the sk object, but leave the\ndangling pointer in the sock object, which may cause use-after-free.\n\nFix this by swapping calls to bt_sock_alloc() and rfcomm_dlc_alloc().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json b/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json index fa3dd152084..2657e5aea2d 100644 --- a/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json +++ b/advisories/unreviewed/2024/12/GHSA-875c-9gcv-8c6h/GHSA-875c-9gcv-8c6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-875c-9gcv-8c6h", - "modified": "2024-12-04T18:32:37Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-04T18:32:37Z", "aliases": [ "CVE-2024-12147" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://www.netgear.com" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/eos" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-8g4q-j62f-4359/GHSA-8g4q-j62f-4359.json b/advisories/unreviewed/2024/12/GHSA-8g4q-j62f-4359/GHSA-8g4q-j62f-4359.json index ca60dbec4e2..4af4b9e1ea5 100644 --- a/advisories/unreviewed/2024/12/GHSA-8g4q-j62f-4359/GHSA-8g4q-j62f-4359.json +++ b/advisories/unreviewed/2024/12/GHSA-8g4q-j62f-4359/GHSA-8g4q-j62f-4359.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8g4q-j62f-4359", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56605" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()\n\nbt_sock_alloc() allocates the sk object and attaches it to the provided\nsock object. On error l2cap_sock_alloc() frees the sk object, but the\ndangling pointer is still attached to the sock object, which may create\nuse-after-free in other code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-98rc-vgv3-572h/GHSA-98rc-vgv3-572h.json b/advisories/unreviewed/2024/12/GHSA-98rc-vgv3-572h/GHSA-98rc-vgv3-572h.json index 437df3981a8..5be81ddebd7 100644 --- a/advisories/unreviewed/2024/12/GHSA-98rc-vgv3-572h/GHSA-98rc-vgv3-572h.json +++ b/advisories/unreviewed/2024/12/GHSA-98rc-vgv3-572h/GHSA-98rc-vgv3-572h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98rc-vgv3-572h", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56603" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_can: do not leave a dangling sk pointer in can_create()\n\nOn error can_create() frees the allocated sk object, but sock_init_data()\nhas already attached it to the provided sock object. This will leave a\ndangling sk pointer in the sock object and may cause use-after-free later.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json b/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json index 58ea4cee09d..fba49dffa3e 100644 --- a/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json +++ b/advisories/unreviewed/2024/12/GHSA-9jgq-4mjq-qcc9/GHSA-9jgq-4mjq-qcc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jgq-4mjq-qcc9", - "modified": "2024-12-27T18:30:26Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T18:30:26Z", "aliases": [ "CVE-2024-12988" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://www.netgear.com" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/eos" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-9xj5-r9g9-xvp9/GHSA-9xj5-r9g9-xvp9.json b/advisories/unreviewed/2024/12/GHSA-9xj5-r9g9-xvp9/GHSA-9xj5-r9g9-xvp9.json index 8f06f53cfa7..eec9bf0fc47 100644 --- a/advisories/unreviewed/2024/12/GHSA-9xj5-r9g9-xvp9/GHSA-9xj5-r9g9-xvp9.json +++ b/advisories/unreviewed/2024/12/GHSA-9xj5-r9g9-xvp9/GHSA-9xj5-r9g9-xvp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9xj5-r9g9-xvp9", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56581" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: ref-verify: fix use-after-free after invalid ref action\n\nAt btrfs_ref_tree_mod() after we successfully inserted the new ref entry\n(local variable 'ref') into the respective block entry's rbtree (local\nvariable 'be'), if we find an unexpected action of BTRFS_DROP_DELAYED_REF,\nwe error out and free the ref entry without removing it from the block\nentry's rbtree. Then in the error path of btrfs_ref_tree_mod() we call\nbtrfs_free_ref_cache(), which iterates over all block entries and then\ncalls free_block_entry() for each one, and there we will trigger a\nuse-after-free when we are called against the block entry to which we\nadded the freed ref entry to its rbtree, since the rbtree still points\nto the block entry, as we didn't remove it from the rbtree before freeing\nit in the error path at btrfs_ref_tree_mod(). Fix this by removing the\nnew ref entry from the rbtree before freeing it.\n\nSyzbot report this with the following stack traces:\n\n BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615\n __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523\n update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_insert_empty_items+0x9c/0x1a0 fs/btrfs/ctree.c:4314\n btrfs_insert_empty_item fs/btrfs/ctree.h:669 [inline]\n btrfs_insert_orphan_item+0x1f1/0x320 fs/btrfs/orphan.c:23\n btrfs_orphan_add+0x6d/0x1a0 fs/btrfs/inode.c:3482\n btrfs_unlink+0x267/0x350 fs/btrfs/inode.c:4293\n vfs_unlink+0x365/0x650 fs/namei.c:4469\n do_unlinkat+0x4ae/0x830 fs/namei.c:4533\n __do_sys_unlinkat fs/namei.c:4576 [inline]\n __se_sys_unlinkat fs/namei.c:4569 [inline]\n __x64_sys_unlinkat+0xcc/0xf0 fs/namei.c:4569\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n BTRFS error (device loop0 state EA): Ref action 1, root 5, ref_root 5, parent 0, owner 260, offset 0, num_refs 1\n __btrfs_mod_ref+0x76b/0xac0 fs/btrfs/extent-tree.c:2521\n update_ref_for_cow+0x96a/0x11f0\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411\n __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030\n btrfs_update_delayed_inode fs/btrfs/delayed-inode.c:1114 [inline]\n __btrfs_commit_inode_delayed_items+0x2318/0x24a0 fs/btrfs/delayed-inode.c:1137\n __btrfs_run_delayed_items+0x213/0x490 fs/btrfs/delayed-inode.c:1171\n btrfs_commit_transaction+0x8a8/0x3740 fs/btrfs/transaction.c:2313\n prepare_to_relocate+0x3c4/0x4c0 fs/btrfs/relocation.c:3586\n relocate_block_group+0x16c/0xd40 fs/btrfs/relocation.c:3611\n btrfs_relocate_block_group+0x77d/0xd90 fs/btrfs/relocation.c:4081\n btrfs_relocate_chunk+0x12c/0x3b0 fs/btrfs/volumes.c:3377\n __btrfs_balance+0x1b0f/0x26b0 fs/btrfs/volumes.c:4161\n btrfs_balance+0xbdc/0x10c0 fs/btrfs/volumes.c:4538\n BTRFS error (device loop0 state EA): Ref action 2, root 5, ref_root 0, parent 8564736, owner 0, offset 0, num_refs 18446744073709551615\n __btrfs_mod_ref+0x7dd/0xac0 fs/btrfs/extent-tree.c:2523\n update_ref_for_cow+0x9cd/0x11f0 fs/btrfs/ctree.c:512\n btrfs_force_cow_block+0x9f6/0x1da0 fs/btrfs/ctree.c:594\n btrfs_cow_block+0x35e/0xa40 fs/btrfs/ctree.c:754\n btrfs_search_slot+0xbdd/0x30d0 fs/btrfs/ctree.c:2116\n btrfs_lookup_inode+0xdc/0x480 fs/btrfs/inode-item.c:411\n __btrfs_update_delayed_inode+0x1e7/0xb90 fs/btrfs/delayed-inode.c:1030\n btrfs_update_delayed_i\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cqv3-q8h5-83r5/GHSA-cqv3-q8h5-83r5.json b/advisories/unreviewed/2024/12/GHSA-cqv3-q8h5-83r5/GHSA-cqv3-q8h5-83r5.json index 9481223184d..4f15fbe8712 100644 --- a/advisories/unreviewed/2024/12/GHSA-cqv3-q8h5-83r5/GHSA-cqv3-q8h5-83r5.json +++ b/advisories/unreviewed/2024/12/GHSA-cqv3-q8h5-83r5/GHSA-cqv3-q8h5-83r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqv3-q8h5-83r5", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56602" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ieee802154: do not leave a dangling sk pointer in ieee802154_create()\n\nsock_init_data() attaches the allocated sk object to the provided sock\nobject. If ieee802154_create() fails later, the allocated sk object is\nfreed, but the dangling pointer remains in the provided sock object, which\nmay allow use-after-free.\n\nClear the sk pointer in the sock object on error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hjcm-xj34-6q2q/GHSA-hjcm-xj34-6q2q.json b/advisories/unreviewed/2024/12/GHSA-hjcm-xj34-6q2q/GHSA-hjcm-xj34-6q2q.json index 7de65347cc0..e177a4873af 100644 --- a/advisories/unreviewed/2024/12/GHSA-hjcm-xj34-6q2q/GHSA-hjcm-xj34-6q2q.json +++ b/advisories/unreviewed/2024/12/GHSA-hjcm-xj34-6q2q/GHSA-hjcm-xj34-6q2q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjcm-xj34-6q2q", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56601" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: inet: do not leave a dangling sk pointer in inet_create()\n\nsock_init_data() attaches the allocated sk object to the provided sock\nobject. If inet_create() fails later, the sk object is freed, but the\nsock object retains the dangling pointer, which may create use-after-free\nlater.\n\nClear the sk pointer in the sock object on error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mxwc-7773-pqqc/GHSA-mxwc-7773-pqqc.json b/advisories/unreviewed/2024/12/GHSA-mxwc-7773-pqqc/GHSA-mxwc-7773-pqqc.json index 7d937838a88..08a857f691f 100644 --- a/advisories/unreviewed/2024/12/GHSA-mxwc-7773-pqqc/GHSA-mxwc-7773-pqqc.json +++ b/advisories/unreviewed/2024/12/GHSA-mxwc-7773-pqqc/GHSA-mxwc-7773-pqqc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mxwc-7773-pqqc", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56640" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix LGR and link use-after-free issue\n\nWe encountered a LGR/link use-after-free issue, which manifested as\nthe LGR/link refcnt reaching 0 early and entering the clear process,\nmaking resource access unsafe.\n\n refcount_t: addition on 0; use-after-free.\n WARNING: CPU: 14 PID: 107447 at lib/refcount.c:25 refcount_warn_saturate+0x9c/0x140\n Workqueue: events smc_lgr_terminate_work [smc]\n Call trace:\n refcount_warn_saturate+0x9c/0x140\n __smc_lgr_terminate.part.45+0x2a8/0x370 [smc]\n smc_lgr_terminate_work+0x28/0x30 [smc]\n process_one_work+0x1b8/0x420\n worker_thread+0x158/0x510\n kthread+0x114/0x118\n\nor\n\n refcount_t: underflow; use-after-free.\n WARNING: CPU: 6 PID: 93140 at lib/refcount.c:28 refcount_warn_saturate+0xf0/0x140\n Workqueue: smc_hs_wq smc_listen_work [smc]\n Call trace:\n refcount_warn_saturate+0xf0/0x140\n smcr_link_put+0x1cc/0x1d8 [smc]\n smc_conn_free+0x110/0x1b0 [smc]\n smc_conn_abort+0x50/0x60 [smc]\n smc_listen_find_device+0x75c/0x790 [smc]\n smc_listen_work+0x368/0x8a0 [smc]\n process_one_work+0x1b8/0x420\n worker_thread+0x158/0x510\n kthread+0x114/0x118\n\nIt is caused by repeated release of LGR/link refcnt. One suspect is that\nsmc_conn_free() is called repeatedly because some smc_conn_free() from\nserver listening path are not protected by sock lock.\n\ne.g.\n\nCalls under socklock | smc_listen_work\n-------------------------------------------------------\nlock_sock(sk) | smc_conn_abort\nsmc_conn_free | \\- smc_conn_free\n\\- smcr_link_put | \\- smcr_link_put (duplicated)\nrelease_sock(sk)\n\nSo here add sock lock protection in smc_listen_work() path, making it\nexclusive with other connection operations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q73c-hqqp-jcp7/GHSA-q73c-hqqp-jcp7.json b/advisories/unreviewed/2024/12/GHSA-q73c-hqqp-jcp7/GHSA-q73c-hqqp-jcp7.json index 2b807d7197e..d77021848db 100644 --- a/advisories/unreviewed/2024/12/GHSA-q73c-hqqp-jcp7/GHSA-q73c-hqqp-jcp7.json +++ b/advisories/unreviewed/2024/12/GHSA-q73c-hqqp-jcp7/GHSA-q73c-hqqp-jcp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q73c-hqqp-jcp7", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56561" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()\n\npci_epc_destroy() invokes pci_bus_release_domain_nr() to release the PCI\ndomain ID, but there are two issues:\n\n - 'epc->dev' is passed to pci_bus_release_domain_nr() which was already\n freed by device_unregister(), leading to a use-after-free issue.\n\n - Domain ID corresponds to the EPC device parent, so passing 'epc->dev'\n is also wrong.\n\nFix these issues by passing 'epc->dev.parent' to\npci_bus_release_domain_nr() and also do it before device_unregister().\n\n[mani: reworded subject and description]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qc69-73cr-g9fg/GHSA-qc69-73cr-g9fg.json b/advisories/unreviewed/2024/12/GHSA-qc69-73cr-g9fg/GHSA-qc69-73cr-g9fg.json index 0bcfdbaaef3..a8ab4fd7883 100644 --- a/advisories/unreviewed/2024/12/GHSA-qc69-73cr-g9fg/GHSA-qc69-73cr-g9fg.json +++ b/advisories/unreviewed/2024/12/GHSA-qc69-73cr-g9fg/GHSA-qc69-73cr-g9fg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qc69-73cr-g9fg", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-14T15:30:50Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56600" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: inet6: do not leave a dangling sk pointer in inet6_create()\n\nsock_init_data() attaches the allocated sk pointer to the provided sock\nobject. If inet6_create() fails later, the sk object is released, but the\nsock object retains the dangling sk pointer, which may cause use-after-free\nlater.\n\nClear the sock sk pointer on error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-279f-qp3q-j675/GHSA-279f-qp3q-j675.json b/advisories/unreviewed/2025/01/GHSA-279f-qp3q-j675/GHSA-279f-qp3q-j675.json index 5dfff62ee12..df940779356 100644 --- a/advisories/unreviewed/2025/01/GHSA-279f-qp3q-j675/GHSA-279f-qp3q-j675.json +++ b/advisories/unreviewed/2025/01/GHSA-279f-qp3q-j675/GHSA-279f-qp3q-j675.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-279f-qp3q-j675", - "modified": "2025-01-14T00:30:45Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:45Z", "aliases": [ "CVE-2023-42230" ], "details": "Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json b/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json index f214200348d..d8adb6e03f8 100644 --- a/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json +++ b/advisories/unreviewed/2025/01/GHSA-2945-84q7-684p/GHSA-2945-84q7-684p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2945-84q7-684p", - "modified": "2025-01-10T15:31:34Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T15:31:34Z", "aliases": [ "CVE-2025-22946" ], "details": "Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T15:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-295c-qxg5-g88q/GHSA-295c-qxg5-g88q.json b/advisories/unreviewed/2025/01/GHSA-295c-qxg5-g88q/GHSA-295c-qxg5-g88q.json new file mode 100644 index 00000000000..90ae403ce40 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-295c-qxg5-g88q/GHSA-295c-qxg5-g88q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-295c-qxg5-g88q", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39800" + ], + "details": "Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39800" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2998-9vr3-8cqh/GHSA-2998-9vr3-8cqh.json b/advisories/unreviewed/2025/01/GHSA-2998-9vr3-8cqh/GHSA-2998-9vr3-8cqh.json new file mode 100644 index 00000000000..81749e9a559 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2998-9vr3-8cqh/GHSA-2998-9vr3-8cqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2998-9vr3-8cqh", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39769" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the `cli_mac` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39769" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json b/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json new file mode 100644 index 00000000000..545e9e06c68 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2jpw-fpqf-qc7g/GHSA-2jpw-fpqf-qc7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jpw-fpqf-qc7g", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39370" + ], + "details": "An arbitrary code execution vulnerability exists in the adm.cgi set_MeshAp() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39370" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json b/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json new file mode 100644 index 00000000000..467c956dd97 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2jw2-w8hc-jqch/GHSA-2jw2-w8hc-jqch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jw2-w8hc-jqch", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-38666" + ], + "details": "An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38666" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2mpq-2g57-j8ww/GHSA-2mpq-2g57-j8ww.json b/advisories/unreviewed/2025/01/GHSA-2mpq-2g57-j8ww/GHSA-2mpq-2g57-j8ww.json new file mode 100644 index 00000000000..5a03f3a3d38 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mpq-2g57-j8ww/GHSA-2mpq-2g57-j8ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mpq-2g57-j8ww", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-48886" + ], + "details": "A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48886" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2q3h-pxc2-8gqg/GHSA-2q3h-pxc2-8gqg.json b/advisories/unreviewed/2025/01/GHSA-2q3h-pxc2-8gqg/GHSA-2q3h-pxc2-8gqg.json new file mode 100644 index 00000000000..852a8e207e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2q3h-pxc2-8gqg/GHSA-2q3h-pxc2-8gqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q3h-pxc2-8gqg", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2023-37936" + ], + "details": "A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37936" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2rg6-2x33-4cjj/GHSA-2rg6-2x33-4cjj.json b/advisories/unreviewed/2025/01/GHSA-2rg6-2x33-4cjj/GHSA-2rg6-2x33-4cjj.json new file mode 100644 index 00000000000..611cfcde9ff --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2rg6-2x33-4cjj/GHSA-2rg6-2x33-4cjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rg6-2x33-4cjj", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-52963" + ], + "details": "A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52963" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-32qp-fj94-7jhx/GHSA-32qp-fj94-7jhx.json b/advisories/unreviewed/2025/01/GHSA-32qp-fj94-7jhx/GHSA-32qp-fj94-7jhx.json index d0267a8e6ca..93dfa2a24ec 100644 --- a/advisories/unreviewed/2025/01/GHSA-32qp-fj94-7jhx/GHSA-32qp-fj94-7jhx.json +++ b/advisories/unreviewed/2025/01/GHSA-32qp-fj94-7jhx/GHSA-32qp-fj94-7jhx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-32qp-fj94-7jhx", - "modified": "2025-01-14T00:30:45Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:45Z", "aliases": [ "CVE-2023-42233" ], "details": "Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json b/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json new file mode 100644 index 00000000000..d150dada23f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-33pw-8v2f-85mj/GHSA-33pw-8v2f-85mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33pw-8v2f-85mj", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39280" + ], + "details": "An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39280" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-39p7-78c9-m48f/GHSA-39p7-78c9-m48f.json b/advisories/unreviewed/2025/01/GHSA-39p7-78c9-m48f/GHSA-39p7-78c9-m48f.json new file mode 100644 index 00000000000..477110c4757 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-39p7-78c9-m48f/GHSA-39p7-78c9-m48f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39p7-78c9-m48f", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39764" + ], + "details": "Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `dest` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39764" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3cww-g5m8-59q4/GHSA-3cww-g5m8-59q4.json b/advisories/unreviewed/2025/01/GHSA-3cww-g5m8-59q4/GHSA-3cww-g5m8-59q4.json new file mode 100644 index 00000000000..538fecf9418 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3cww-g5m8-59q4/GHSA-3cww-g5m8-59q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cww-g5m8-59q4", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39763" + ], + "details": "Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `gateway` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39763" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3g8p-fgh4-3vvq/GHSA-3g8p-fgh4-3vvq.json b/advisories/unreviewed/2025/01/GHSA-3g8p-fgh4-3vvq/GHSA-3g8p-fgh4-3vvq.json new file mode 100644 index 00000000000..54dba5b7415 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3g8p-fgh4-3vvq/GHSA-3g8p-fgh4-3vvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g8p-fgh4-3vvq", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39783" + ], + "details": "Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `restart_week` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39783" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3hjv-6fp6-9qj9/GHSA-3hjv-6fp6-9qj9.json b/advisories/unreviewed/2025/01/GHSA-3hjv-6fp6-9qj9/GHSA-3hjv-6fp6-9qj9.json new file mode 100644 index 00000000000..5ce98523f35 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3hjv-6fp6-9qj9/GHSA-3hjv-6fp6-9qj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hjv-6fp6-9qj9", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-45326" + ], + "details": "An Improper Access Control vulnerability [CWE-284] in FortiDeceptor version 6.0.0, version 5.3.3 and below, version 5.2.1 and below, version 5.1.0, version 5.0.0 may allow an authenticated attacker with none privileges to perform operations on the central management appliance via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45326" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3qqr-ch4p-vc36/GHSA-3qqr-ch4p-vc36.json b/advisories/unreviewed/2025/01/GHSA-3qqr-ch4p-vc36/GHSA-3qqr-ch4p-vc36.json new file mode 100644 index 00000000000..8cd011dd0c9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3qqr-ch4p-vc36/GHSA-3qqr-ch4p-vc36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qqr-ch4p-vc36", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39788" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_name` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39788" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json b/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json index 63147e4d793..e09431de9d3 100644 --- a/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json +++ b/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-43p5-738g-gr8j", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-29970" ], "details": "Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T16:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json b/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json new file mode 100644 index 00000000000..0b5cb20595c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-453m-fcx3-j43g/GHSA-453m-fcx3-j43g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-453m-fcx3-j43g", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39367" + ], + "details": "An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39367" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-45gf-27xm-h64q/GHSA-45gf-27xm-h64q.json b/advisories/unreviewed/2025/01/GHSA-45gf-27xm-h64q/GHSA-45gf-27xm-h64q.json new file mode 100644 index 00000000000..55d2822287b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-45gf-27xm-h64q/GHSA-45gf-27xm-h64q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45gf-27xm-h64q", + "modified": "2025-01-14T15:30:57Z", + "published": "2025-01-14T15:30:57Z", + "aliases": [ + "CVE-2024-42444" + ], + "details": "APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42444" + }, + { + "type": "WEB", + "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025001.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json b/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json new file mode 100644 index 00000000000..98609806b69 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-49vq-r69w-8m53/GHSA-49vq-r69w-8m53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49vq-r69w-8m53", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39603" + ], + "details": "A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39603" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4fjp-2975-mx8w/GHSA-4fjp-2975-mx8w.json b/advisories/unreviewed/2025/01/GHSA-4fjp-2975-mx8w/GHSA-4fjp-2975-mx8w.json new file mode 100644 index 00000000000..0e05e82bd14 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4fjp-2975-mx8w/GHSA-4fjp-2975-mx8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fjp-2975-mx8w", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-55593" + ], + "details": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55593" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-465" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4jf3-hxmq-5r2f/GHSA-4jf3-hxmq-5r2f.json b/advisories/unreviewed/2025/01/GHSA-4jf3-hxmq-5r2f/GHSA-4jf3-hxmq-5r2f.json new file mode 100644 index 00000000000..78852044a1d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4jf3-hxmq-5r2f/GHSA-4jf3-hxmq-5r2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jf3-hxmq-5r2f", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2024-11497" + ], + "details": "An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11497" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4pvm-5x6h-f3qp/GHSA-4pvm-5x6h-f3qp.json b/advisories/unreviewed/2025/01/GHSA-4pvm-5x6h-f3qp/GHSA-4pvm-5x6h-f3qp.json new file mode 100644 index 00000000000..e104073d6f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4pvm-5x6h-f3qp/GHSA-4pvm-5x6h-f3qp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pvm-5x6h-f3qp", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-50564" + ], + "details": "A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50564" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4wxp-6xr4-5pvw/GHSA-4wxp-6xr4-5pvw.json b/advisories/unreviewed/2025/01/GHSA-4wxp-6xr4-5pvw/GHSA-4wxp-6xr4-5pvw.json new file mode 100644 index 00000000000..b7c66f13210 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wxp-6xr4-5pvw/GHSA-4wxp-6xr4-5pvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wxp-6xr4-5pvw", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-48893" + ], + "details": "An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48893" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-53h9-qp9v-954c/GHSA-53h9-qp9v-954c.json b/advisories/unreviewed/2025/01/GHSA-53h9-qp9v-954c/GHSA-53h9-qp9v-954c.json new file mode 100644 index 00000000000..0ba3ca570ab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-53h9-qp9v-954c/GHSA-53h9-qp9v-954c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53h9-qp9v-954c", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-46666" + ], + "details": "An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests directed at specific endpoints.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46666" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json b/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json new file mode 100644 index 00000000000..671b3add01f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-53rm-p3f5-vx5c/GHSA-53rm-p3f5-vx5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53rm-p3f5-vx5c", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-34544" + ], + "details": "A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34544" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54qm-4vvg-ch55/GHSA-54qm-4vvg-ch55.json b/advisories/unreviewed/2025/01/GHSA-54qm-4vvg-ch55/GHSA-54qm-4vvg-ch55.json new file mode 100644 index 00000000000..c9b01bc6614 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54qm-4vvg-ch55/GHSA-54qm-4vvg-ch55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qm-4vvg-ch55", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-40587" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40587" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-304" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json b/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json index c824649c4fc..5464fd48584 100644 --- a/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json +++ b/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5c5x-jw5q-2wpw", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13300" ], "details": "Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5f5r-cv84-3xjr/GHSA-5f5r-cv84-3xjr.json b/advisories/unreviewed/2025/01/GHSA-5f5r-cv84-3xjr/GHSA-5f5r-cv84-3xjr.json new file mode 100644 index 00000000000..012f46bc13e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5f5r-cv84-3xjr/GHSA-5f5r-cv84-3xjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f5r-cv84-3xjr", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39762" + ], + "details": "Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `netmask` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39762" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5gj5-pjhv-qqc6/GHSA-5gj5-pjhv-qqc6.json b/advisories/unreviewed/2025/01/GHSA-5gj5-pjhv-qqc6/GHSA-5gj5-pjhv-qqc6.json index afd7f2b7420..ca785655c2c 100644 --- a/advisories/unreviewed/2025/01/GHSA-5gj5-pjhv-qqc6/GHSA-5gj5-pjhv-qqc6.json +++ b/advisories/unreviewed/2025/01/GHSA-5gj5-pjhv-qqc6/GHSA-5gj5-pjhv-qqc6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gj5-pjhv-qqc6", - "modified": "2025-01-14T00:30:46Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:46Z", "aliases": [ "CVE-2023-42249" ], "details": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5gx2-mcv7-59f4/GHSA-5gx2-mcv7-59f4.json b/advisories/unreviewed/2025/01/GHSA-5gx2-mcv7-59f4/GHSA-5gx2-mcv7-59f4.json new file mode 100644 index 00000000000..2acf605b045 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5gx2-mcv7-59f4/GHSA-5gx2-mcv7-59f4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gx2-mcv7-59f4", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39802" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `qos_dat` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39802" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5qf3-cvj3-r534/GHSA-5qf3-cvj3-r534.json b/advisories/unreviewed/2025/01/GHSA-5qf3-cvj3-r534/GHSA-5qf3-cvj3-r534.json new file mode 100644 index 00000000000..b36f0d012b4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5qf3-cvj3-r534/GHSA-5qf3-cvj3-r534.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qf3-cvj3-r534", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39781" + ], + "details": "Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `restart_hour` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39781" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5wmq-f28x-ggg6/GHSA-5wmq-f28x-ggg6.json b/advisories/unreviewed/2025/01/GHSA-5wmq-f28x-ggg6/GHSA-5wmq-f28x-ggg6.json new file mode 100644 index 00000000000..264720afa41 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5wmq-f28x-ggg6/GHSA-5wmq-f28x-ggg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wmq-f28x-ggg6", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39790" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_max_sessions` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39790" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5xxp-3j63-qv9w/GHSA-5xxp-3j63-qv9w.json b/advisories/unreviewed/2025/01/GHSA-5xxp-3j63-qv9w/GHSA-5xxp-3j63-qv9w.json new file mode 100644 index 00000000000..18fae732e37 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5xxp-3j63-qv9w/GHSA-5xxp-3j63-qv9w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xxp-3j63-qv9w", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-21758" + ], + "details": "A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21758" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120", + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json b/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json new file mode 100644 index 00000000000..e24c651af3f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-65gf-8mmg-g56g/GHSA-65gf-8mmg-g56g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65gf-8mmg-g56g", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-37184" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi rep_as_bridge() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37184" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-65xx-qhj3-cvp8/GHSA-65xx-qhj3-cvp8.json b/advisories/unreviewed/2025/01/GHSA-65xx-qhj3-cvp8/GHSA-65xx-qhj3-cvp8.json new file mode 100644 index 00000000000..4be2c4cf9ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-65xx-qhj3-cvp8/GHSA-65xx-qhj3-cvp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xx-qhj3-cvp8", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2023-46715" + ], + "details": "An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46715" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-407" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6956-r7m5-cgq5/GHSA-6956-r7m5-cgq5.json b/advisories/unreviewed/2025/01/GHSA-6956-r7m5-cgq5/GHSA-6956-r7m5-cgq5.json new file mode 100644 index 00000000000..3a6be9a2c9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6956-r7m5-cgq5/GHSA-6956-r7m5-cgq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6956-r7m5-cgq5", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2023-42786" + ], + "details": "A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42786" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-293" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-69mj-v9gr-ph5p/GHSA-69mj-v9gr-ph5p.json b/advisories/unreviewed/2025/01/GHSA-69mj-v9gr-ph5p/GHSA-69mj-v9gr-ph5p.json new file mode 100644 index 00000000000..f6b523d276d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-69mj-v9gr-ph5p/GHSA-69mj-v9gr-ph5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69mj-v9gr-ph5p", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39782" + ], + "details": "Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `restart_min` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39782" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6gj7-68vj-fvp7/GHSA-6gj7-68vj-fvp7.json b/advisories/unreviewed/2025/01/GHSA-6gj7-68vj-fvp7/GHSA-6gj7-68vj-fvp7.json new file mode 100644 index 00000000000..75a03c1826e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6gj7-68vj-fvp7/GHSA-6gj7-68vj-fvp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gj7-68vj-fvp7", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39785" + ], + "details": "Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the adddir_name POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39785" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json b/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json new file mode 100644 index 00000000000..efddd000ae7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6r9m-h6rv-42cg/GHSA-6r9m-h6rv-42cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r9m-h6rv-42cg", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-36258" + ], + "details": "A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36258" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6v4c-pj8v-6wqm/GHSA-6v4c-pj8v-6wqm.json b/advisories/unreviewed/2025/01/GHSA-6v4c-pj8v-6wqm/GHSA-6v4c-pj8v-6wqm.json new file mode 100644 index 00000000000..c7d4bf0a8d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v4c-pj8v-6wqm/GHSA-6v4c-pj8v-6wqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v4c-pj8v-6wqm", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-46665" + ], + "details": "An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46665" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-326" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json b/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json new file mode 100644 index 00000000000..e39bc3f869a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-79x5-vf8c-7456/GHSA-79x5-vf8c-7456.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79x5-vf8c-7456", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39604" + ], + "details": "A command execution vulnerability exists in the update_filter_url.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39604" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json b/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json new file mode 100644 index 00000000000..4badc52ade9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7p4j-prhq-8ffm/GHSA-7p4j-prhq-8ffm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p4j-prhq-8ffm", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-34166" + ], + "details": "An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34166" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7p64-5x2j-p5qx/GHSA-7p64-5x2j-p5qx.json b/advisories/unreviewed/2025/01/GHSA-7p64-5x2j-p5qx/GHSA-7p64-5x2j-p5qx.json new file mode 100644 index 00000000000..9b829d7716a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7p64-5x2j-p5qx/GHSA-7p64-5x2j-p5qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p64-5x2j-p5qx", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39761" + ], + "details": "Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the `restart_week_value` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39761" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json b/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json new file mode 100644 index 00000000000..5720cc68cd5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7rgq-53c3-wvm6/GHSA-7rgq-53c3-wvm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rgq-53c3-wvm6", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39363" + ], + "details": "A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39363" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json new file mode 100644 index 00000000000..23e551c1351 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xfj-4r7x-3733", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-7344" + ], + "details": "Howyar UEFI Application \"Reloader\" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7344" + }, + { + "type": "WEB", + "url": "https://uefi.org/revocationlistfile" + }, + { + "type": "WEB", + "url": "https://uefi.org/specs/UEFI/2.10/03_Boot_Manager.html" + }, + { + "type": "WEB", + "url": "https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html" + }, + { + "type": "WEB", + "url": "https://www.eset.com/blog/enterprise/preparing-for-uefi-bootkits-eset-discovery-shows-the-importance-of-cyber-intelligence" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/529659" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-88gg-54r4-rj2g/GHSA-88gg-54r4-rj2g.json b/advisories/unreviewed/2025/01/GHSA-88gg-54r4-rj2g/GHSA-88gg-54r4-rj2g.json new file mode 100644 index 00000000000..6703a0eafbe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-88gg-54r4-rj2g/GHSA-88gg-54r4-rj2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gg-54r4-rj2g", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2023-42785" + ], + "details": "A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42785" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-293" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json b/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json new file mode 100644 index 00000000000..1b805b6e458 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8f65-h57m-hqw8/GHSA-8f65-h57m-hqw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f65-h57m-hqw8", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-36290" + ], + "details": "A buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36290" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8jwr-jm4q-89xr/GHSA-8jwr-jm4q-89xr.json b/advisories/unreviewed/2025/01/GHSA-8jwr-jm4q-89xr/GHSA-8jwr-jm4q-89xr.json new file mode 100644 index 00000000000..524cde7fde3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8jwr-jm4q-89xr/GHSA-8jwr-jm4q-89xr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jwr-jm4q-89xr", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-48890" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48890" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-415" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json b/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json new file mode 100644 index 00000000000..7bebb8c4d66 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8m5m-vgwc-v2rv/GHSA-8m5m-vgwc-v2rv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m5m-vgwc-v2rv", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-11863" + ], + "details": "Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11863" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/SCP-Firmware%20Vulnerability%20CVE-2024-11863-11864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8qhx-f4vg-5h4h/GHSA-8qhx-f4vg-5h4h.json b/advisories/unreviewed/2025/01/GHSA-8qhx-f4vg-5h4h/GHSA-8qhx-f4vg-5h4h.json new file mode 100644 index 00000000000..2f09081edc9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8qhx-f4vg-5h4h/GHSA-8qhx-f4vg-5h4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qhx-f4vg-5h4h", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-56497" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56497" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8qrq-rh6g-rh3h/GHSA-8qrq-rh6g-rh3h.json b/advisories/unreviewed/2025/01/GHSA-8qrq-rh6g-rh3h/GHSA-8qrq-rh6g-rh3h.json new file mode 100644 index 00000000000..81cf0065df4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8qrq-rh6g-rh3h/GHSA-8qrq-rh6g-rh3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qrq-rh6g-rh3h", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39786" + ], + "details": "Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists within the `adddir_name` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39786" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8rvm-5wfm-cww4/GHSA-8rvm-5wfm-cww4.json b/advisories/unreviewed/2025/01/GHSA-8rvm-5wfm-cww4/GHSA-8rvm-5wfm-cww4.json new file mode 100644 index 00000000000..9b3052aca5e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8rvm-5wfm-cww4/GHSA-8rvm-5wfm-cww4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rvm-5wfm-cww4", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39794" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_port` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39794" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json b/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json new file mode 100644 index 00000000000..426f87d300a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9268-6mh2-4xfg/GHSA-9268-6mh2-4xfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9268-6mh2-4xfg", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39299" + ], + "details": "A buffer overflow vulnerability exists in the qos.cgi qos_sta_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39299" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json b/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json new file mode 100644 index 00000000000..1e567a93014 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-94wj-p6vq-75pv/GHSA-94wj-p6vq-75pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94wj-p6vq-75pv", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-36295" + ], + "details": "A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36295" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json b/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json new file mode 100644 index 00000000000..7abf3dc1450 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9953-68f2-mpwf/GHSA-9953-68f2-mpwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9953-68f2-mpwf", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39273" + ], + "details": "A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39273" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json b/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json new file mode 100644 index 00000000000..486e90051fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9ch8-4327-g6cw/GHSA-9ch8-4327-g6cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ch8-4327-g6cw", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39754" + ], + "details": "A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39754" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json b/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json new file mode 100644 index 00000000000..4e929131bb6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9cmh-g466-3ph3/GHSA-9cmh-g466-3ph3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cmh-g466-3ph3", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-11864" + ], + "details": "Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11864" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/SCP-Firmware%20Vulnerability%20CVE-2024-11863-11864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9f95-94rj-c9f5/GHSA-9f95-94rj-c9f5.json b/advisories/unreviewed/2025/01/GHSA-9f95-94rj-c9f5/GHSA-9f95-94rj-c9f5.json new file mode 100644 index 00000000000..e30d7984cc3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9f95-94rj-c9f5/GHSA-9f95-94rj-c9f5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f95-94rj-c9f5", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39760" + ], + "details": "Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the `restart_min_value` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39760" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json b/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json new file mode 100644 index 00000000000..013b907b577 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9rjp-q43g-3644/GHSA-9rjp-q43g-3644.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rjp-q43g-3644", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-37186" + ], + "details": "An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37186" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c22h-m2p9-c6w3/GHSA-c22h-m2p9-c6w3.json b/advisories/unreviewed/2025/01/GHSA-c22h-m2p9-c6w3/GHSA-c22h-m2p9-c6w3.json new file mode 100644 index 00000000000..28a0c2fc527 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c22h-m2p9-c6w3/GHSA-c22h-m2p9-c6w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c22h-m2p9-c6w3", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-52967" + ], + "details": "An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52967" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ch76-hx2m-rf3m/GHSA-ch76-hx2m-rf3m.json b/advisories/unreviewed/2025/01/GHSA-ch76-hx2m-rf3m/GHSA-ch76-hx2m-rf3m.json new file mode 100644 index 00000000000..56dba59b08b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ch76-hx2m-rf3m/GHSA-ch76-hx2m-rf3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch76-hx2m-rf3m", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39789" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_port` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39789" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cphf-r7wp-hq92/GHSA-cphf-r7wp-hq92.json b/advisories/unreviewed/2025/01/GHSA-cphf-r7wp-hq92/GHSA-cphf-r7wp-hq92.json new file mode 100644 index 00000000000..7b8d4d509f4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cphf-r7wp-hq92/GHSA-cphf-r7wp-hq92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cphf-r7wp-hq92", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39770" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the `en_enable` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39770" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json b/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json new file mode 100644 index 00000000000..719ddce1b0d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cv67-v84q-6c9x/GHSA-cv67-v84q-6c9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv67-v84q-6c9x", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39602" + ], + "details": "An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39602" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json b/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json new file mode 100644 index 00000000000..07fb0c00ea3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fggw-c44p-x7gg/GHSA-fggw-c44p-x7gg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fggw-c44p-x7gg", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-55000" + ], + "details": "Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55000" + }, + { + "type": "WEB", + "url": "https://github.com/tang-0717/VUL/blob/main/House%20Rental%20Management%20system%20-%20Storage%20XSS%20on%20%28rentalmanage_categories.php%29.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fh6c-p6q9-8m5f/GHSA-fh6c-p6q9-8m5f.json b/advisories/unreviewed/2025/01/GHSA-fh6c-p6q9-8m5f/GHSA-fh6c-p6q9-8m5f.json index a2fabb2e9ca..f84c58032d2 100644 --- a/advisories/unreviewed/2025/01/GHSA-fh6c-p6q9-8m5f/GHSA-fh6c-p6q9-8m5f.json +++ b/advisories/unreviewed/2025/01/GHSA-fh6c-p6q9-8m5f/GHSA-fh6c-p6q9-8m5f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fh6c-p6q9-8m5f", - "modified": "2025-01-10T21:31:28Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T21:31:28Z", "aliases": [ "CVE-2024-7095" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json b/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json index 4ecbf5b759b..826f4787ef8 100644 --- a/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json +++ b/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fr2h-74vh-mp7c", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-14T15:30:50Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13299" ], "details": "Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json b/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json new file mode 100644 index 00000000000..10b368278e8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g23p-hhrc-qr97/GHSA-g23p-hhrc-qr97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g23p-hhrc-qr97", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39774" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi set_sys_adm() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39774" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g347-74q4-mp7w/GHSA-g347-74q4-mp7w.json b/advisories/unreviewed/2025/01/GHSA-g347-74q4-mp7w/GHSA-g347-74q4-mp7w.json new file mode 100644 index 00000000000..adfc148d631 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g347-74q4-mp7w/GHSA-g347-74q4-mp7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g347-74q4-mp7w", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:51Z", + "aliases": [ + "CVE-2023-37937" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via the FortiSwitch CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37937" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-258" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g58r-fcx4-mv8r/GHSA-g58r-fcx4-mv8r.json b/advisories/unreviewed/2025/01/GHSA-g58r-fcx4-mv8r/GHSA-g58r-fcx4-mv8r.json new file mode 100644 index 00000000000..da4b7545de7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g58r-fcx4-mv8r/GHSA-g58r-fcx4-mv8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g58r-fcx4-mv8r", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-36510" + ], + "details": "An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36510" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json b/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json new file mode 100644 index 00000000000..f133318838b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5cp-69v7-5p9h/GHSA-g5cp-69v7-5p9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5cp-69v7-5p9h", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-36272" + ], + "details": "A buffer overflow vulnerability exists in the usbip.cgi set_info() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36272" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2045" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g72p-5f8c-rcj2/GHSA-g72p-5f8c-rcj2.json b/advisories/unreviewed/2025/01/GHSA-g72p-5f8c-rcj2/GHSA-g72p-5f8c-rcj2.json new file mode 100644 index 00000000000..ffd452233aa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g72p-5f8c-rcj2/GHSA-g72p-5f8c-rcj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g72p-5f8c-rcj2", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39765" + ], + "details": "Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `custom_interface` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39765" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g8fx-pvg9-8mm8/GHSA-g8fx-pvg9-8mm8.json b/advisories/unreviewed/2025/01/GHSA-g8fx-pvg9-8mm8/GHSA-g8fx-pvg9-8mm8.json new file mode 100644 index 00000000000..30e60beaa89 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g8fx-pvg9-8mm8/GHSA-g8fx-pvg9-8mm8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8fx-pvg9-8mm8", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-32115" + ], + "details": "A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32115" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22", + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gc47-55jm-w6mg/GHSA-gc47-55jm-w6mg.json b/advisories/unreviewed/2025/01/GHSA-gc47-55jm-w6mg/GHSA-gc47-55jm-w6mg.json new file mode 100644 index 00000000000..411c3303ba8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gc47-55jm-w6mg/GHSA-gc47-55jm-w6mg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc47-55jm-w6mg", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-35273" + ], + "details": "A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35273" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gpr9-gqg8-xj7v/GHSA-gpr9-gqg8-xj7v.json b/advisories/unreviewed/2025/01/GHSA-gpr9-gqg8-xj7v/GHSA-gpr9-gqg8-xj7v.json new file mode 100644 index 00000000000..d12ee46f918 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gpr9-gqg8-xj7v/GHSA-gpr9-gqg8-xj7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpr9-gqg8-xj7v", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-26012" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2 allow a local authenticated attacker to execute unauthorized code via the CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26012" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json b/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json new file mode 100644 index 00000000000..10356a41f65 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gqrr-9m6w-6qhc/GHSA-gqrr-9m6w-6qhc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqrr-9m6w-6qhc", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-37357" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37357" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json b/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json new file mode 100644 index 00000000000..36ca2c78e34 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gx3h-wj7q-54q9/GHSA-gx3h-wj7q-54q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx3h-wj7q-54q9", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39358" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi set_wzap() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39358" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gxgh-8p3v-3jvv/GHSA-gxgh-8p3v-3jvv.json b/advisories/unreviewed/2025/01/GHSA-gxgh-8p3v-3jvv/GHSA-gxgh-8p3v-3jvv.json new file mode 100644 index 00000000000..752ec121991 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gxgh-8p3v-3jvv/GHSA-gxgh-8p3v-3jvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgh-8p3v-3jvv", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-33502" + ], + "details": "An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33502" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-143" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h695-gj7p-pjhj/GHSA-h695-gj7p-pjhj.json b/advisories/unreviewed/2025/01/GHSA-h695-gj7p-pjhj/GHSA-h695-gj7p-pjhj.json index 36569094d9c..082e0d93154 100644 --- a/advisories/unreviewed/2025/01/GHSA-h695-gj7p-pjhj/GHSA-h695-gj7p-pjhj.json +++ b/advisories/unreviewed/2025/01/GHSA-h695-gj7p-pjhj/GHSA-h695-gj7p-pjhj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h695-gj7p-pjhj", - "modified": "2025-01-14T00:30:45Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:45Z", "aliases": [ "CVE-2023-42245" ], "details": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hfjp-2wj6-97ww/GHSA-hfjp-2wj6-97ww.json b/advisories/unreviewed/2025/01/GHSA-hfjp-2wj6-97ww/GHSA-hfjp-2wj6-97ww.json new file mode 100644 index 00000000000..35393498856 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hfjp-2wj6-97ww/GHSA-hfjp-2wj6-97ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfjp-2wj6-97ww", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39784" + ], + "details": "Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the disk_part POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39784" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json b/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json new file mode 100644 index 00000000000..8fae968455b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hhjp-322f-hh5x/GHSA-hhjp-322f-hh5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhjp-322f-hh5x", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39608" + ], + "details": "A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39608" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2036" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json b/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json new file mode 100644 index 00000000000..8a44a08466c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hpf7-2hg3-3g3h/GHSA-hpf7-2hg3-3g3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpf7-2hg3-3g3h", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-21797" + ], + "details": "A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21797" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hw72-fmxv-278r/GHSA-hw72-fmxv-278r.json b/advisories/unreviewed/2025/01/GHSA-hw72-fmxv-278r/GHSA-hw72-fmxv-278r.json new file mode 100644 index 00000000000..5f0d04a3c9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hw72-fmxv-278r/GHSA-hw72-fmxv-278r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw72-fmxv-278r", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-33503" + ], + "details": "A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33503" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json b/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json index 199f4cc1ddb..ae00854e623 100644 --- a/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json +++ b/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw79-cp29-3x6c", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2025-22949" ], "details": "Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T16:15:31Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jc45-7g3m-f786/GHSA-jc45-7g3m-f786.json b/advisories/unreviewed/2025/01/GHSA-jc45-7g3m-f786/GHSA-jc45-7g3m-f786.json new file mode 100644 index 00000000000..822603203de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jc45-7g3m-f786/GHSA-jc45-7g3m-f786.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc45-7g3m-f786", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-52969" + ], + "details": "An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version 6.4.4 and below Update/Create Case feature may allow an authenticated attacker to extract database information via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52969" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-417" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json b/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json new file mode 100644 index 00000000000..cd0113a53a0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jfmv-87hc-q689/GHSA-jfmv-87hc-q689.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfmv-87hc-q689", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39360" + ], + "details": "An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39360" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2054" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json b/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json new file mode 100644 index 00000000000..272287ceba4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jhvv-hwq8-7rx2/GHSA-jhvv-hwq8-7rx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhvv-hwq8-7rx2", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39756" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi rep_as_router() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39756" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json b/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json new file mode 100644 index 00000000000..ed32694ea29 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jw4w-2rjj-x8jv/GHSA-jw4w-2rjj-x8jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4w-2rjj-x8jv", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39757" + ], + "details": "A stack-based buffer overflow vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39757" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m343-65m6-2r6j/GHSA-m343-65m6-2r6j.json b/advisories/unreviewed/2025/01/GHSA-m343-65m6-2r6j/GHSA-m343-65m6-2r6j.json new file mode 100644 index 00000000000..1917f846598 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m343-65m6-2r6j/GHSA-m343-65m6-2r6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m343-65m6-2r6j", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-47566" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47566" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-401" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json b/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json new file mode 100644 index 00000000000..8b510ab411e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m477-ghq9-m3j8/GHSA-m477-ghq9-m3j8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m477-ghq9-m3j8", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39359" + ], + "details": "A stack-based buffer overflow vulnerability exists in the wireless.cgi DeleteMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39359" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2040" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json b/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json new file mode 100644 index 00000000000..de2c3c3d287 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mcpf-9j38-2vmq/GHSA-mcpf-9j38-2vmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcpf-9j38-2vmq", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39773" + ], + "details": "An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39773" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mphf-cc86-chgh/GHSA-mphf-cc86-chgh.json b/advisories/unreviewed/2025/01/GHSA-mphf-cc86-chgh/GHSA-mphf-cc86-chgh.json new file mode 100644 index 00000000000..bd8e7854035 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mphf-cc86-chgh/GHSA-mphf-cc86-chgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mphf-cc86-chgh", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-50566" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager versions 7.6.0 through 7.6.1, versions 7.4.5 through 7.4.0, and versions 7.2.1 through 7.2.8, FortiManager Cloud versions 7.6.0 through 7.6.1, versions 7.4.0 through 7.4.4, and versions 7.2.2 through 7.2.7 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50566" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p2ch-mj9p-73pg/GHSA-p2ch-mj9p-73pg.json b/advisories/unreviewed/2025/01/GHSA-p2ch-mj9p-73pg/GHSA-p2ch-mj9p-73pg.json new file mode 100644 index 00000000000..ab1b64a94eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p2ch-mj9p-73pg/GHSA-p2ch-mj9p-73pg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2ch-mj9p-73pg", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39759" + ], + "details": "Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the `restart_hour_value` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39759" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p469-jgv4-q322/GHSA-p469-jgv4-q322.json b/advisories/unreviewed/2025/01/GHSA-p469-jgv4-q322/GHSA-p469-jgv4-q322.json new file mode 100644 index 00000000000..4fed7d1c170 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p469-jgv4-q322/GHSA-p469-jgv4-q322.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p469-jgv4-q322", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-35276" + ], + "details": "A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager Cloud versions 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.11, 6.4.1 through 6.4.7, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.11, 6.4.1 through 6.4.7 allows attacker to execute unauthorized code or commands via specially crafted packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35276" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json b/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json new file mode 100644 index 00000000000..5ce34c37b7d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pp4g-pjj7-f6rj/GHSA-pp4g-pjj7-f6rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp4g-pjj7-f6rj", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39288" + ], + "details": "A buffer overflow vulnerability exists in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39288" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json b/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json new file mode 100644 index 00000000000..2a4867f71ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-px43-x9c5-2gjv/GHSA-px43-x9c5-2gjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px43-x9c5-2gjv", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39294" + ], + "details": "A buffer overflow vulnerability exists in the adm.cgi set_wzdgw4G() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39294" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q35w-cr5p-7qc3/GHSA-q35w-cr5p-7qc3.json b/advisories/unreviewed/2025/01/GHSA-q35w-cr5p-7qc3/GHSA-q35w-cr5p-7qc3.json new file mode 100644 index 00000000000..f0a52ac17ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q35w-cr5p-7qc3/GHSA-q35w-cr5p-7qc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q35w-cr5p-7qc3", + "modified": "2025-01-14T15:30:52Z", + "published": "2025-01-14T15:30:52Z", + "aliases": [ + "CVE-2024-27778" + ], + "details": "An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 4.4.0 through 4.4.4, 4.2.0 through 4.2.6 and below 4.0.4 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27778" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q642-7m4r-pmj6/GHSA-q642-7m4r-pmj6.json b/advisories/unreviewed/2025/01/GHSA-q642-7m4r-pmj6/GHSA-q642-7m4r-pmj6.json new file mode 100644 index 00000000000..9cb15213ac6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q642-7m4r-pmj6/GHSA-q642-7m4r-pmj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q642-7m4r-pmj6", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39801" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `qos_bandwidth` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39801" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q6h8-qgxm-m9pc/GHSA-q6h8-qgxm-m9pc.json b/advisories/unreviewed/2025/01/GHSA-q6h8-qgxm-m9pc/GHSA-q6h8-qgxm-m9pc.json new file mode 100644 index 00000000000..a7c117c3396 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q6h8-qgxm-m9pc/GHSA-q6h8-qgxm-m9pc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6h8-qgxm-m9pc", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-36506" + ], + "details": "An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36506" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-078" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-940" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qhwf-jg9m-cq9f/GHSA-qhwf-jg9m-cq9f.json b/advisories/unreviewed/2025/01/GHSA-qhwf-jg9m-cq9f/GHSA-qhwf-jg9m-cq9f.json new file mode 100644 index 00000000000..3b427bc8a04 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qhwf-jg9m-cq9f/GHSA-qhwf-jg9m-cq9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhwf-jg9m-cq9f", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-48884" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy 7.4.0 through 7.4.5, 7.2.0 through 7.2.11, 7.0.0 through 7.0.18, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiVoice versions 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.0 through 6.0.12, FortiWeb 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10, 6.4.0 through 6.4.3 allows attacker to trigger an escalation of privilege via specially crafted packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48884" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qxh2-8jw8-hx7g/GHSA-qxh2-8jw8-hx7g.json b/advisories/unreviewed/2025/01/GHSA-qxh2-8jw8-hx7g/GHSA-qxh2-8jw8-hx7g.json new file mode 100644 index 00000000000..67180fc1b6c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qxh2-8jw8-hx7g/GHSA-qxh2-8jw8-hx7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxh2-8jw8-hx7g", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39795" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_max_sessions` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39795" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qxxc-5wx2-mh2q/GHSA-qxxc-5wx2-mh2q.json b/advisories/unreviewed/2025/01/GHSA-qxxc-5wx2-mh2q/GHSA-qxxc-5wx2-mh2q.json new file mode 100644 index 00000000000..b2bf9dbf6da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qxxc-5wx2-mh2q/GHSA-qxxc-5wx2-mh2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxxc-5wx2-mh2q", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39787" + ], + "details": "Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists within the `disk_part` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39787" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r39f-vq75-r7mj/GHSA-r39f-vq75-r7mj.json b/advisories/unreviewed/2025/01/GHSA-r39f-vq75-r7mj/GHSA-r39f-vq75-r7mj.json new file mode 100644 index 00000000000..169c1443eac --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r39f-vq75-r7mj/GHSA-r39f-vq75-r7mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r39f-vq75-r7mj", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-46669" + ], + "details": "An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46669" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-267" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r3rj-4mrf-v5mf/GHSA-r3rj-4mrf-v5mf.json b/advisories/unreviewed/2025/01/GHSA-r3rj-4mrf-v5mf/GHSA-r3rj-4mrf-v5mf.json new file mode 100644 index 00000000000..b0ebf23ecd3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r3rj-4mrf-v5mf/GHSA-r3rj-4mrf-v5mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3rj-4mrf-v5mf", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39799" + ], + "details": "Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_interface` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39799" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r9wr-68hr-qxpc/GHSA-r9wr-68hr-qxpc.json b/advisories/unreviewed/2025/01/GHSA-r9wr-68hr-qxpc/GHSA-r9wr-68hr-qxpc.json new file mode 100644 index 00000000000..dea792b835e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r9wr-68hr-qxpc/GHSA-r9wr-68hr-qxpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9wr-68hr-qxpc", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39803" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `sel_mode` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39803" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rcr8-43mg-v238/GHSA-rcr8-43mg-v238.json b/advisories/unreviewed/2025/01/GHSA-rcr8-43mg-v238/GHSA-rcr8-43mg-v238.json index b63f90d58f9..82dcb48763d 100644 --- a/advisories/unreviewed/2025/01/GHSA-rcr8-43mg-v238/GHSA-rcr8-43mg-v238.json +++ b/advisories/unreviewed/2025/01/GHSA-rcr8-43mg-v238/GHSA-rcr8-43mg-v238.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcr8-43mg-v238", - "modified": "2025-01-13T21:30:53Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-13T21:30:53Z", "aliases": [ "CVE-2024-44771" ], "details": "BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the \"Label\" field in the Report template function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T19:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rhvx-9vr4-vmg9/GHSA-rhvx-9vr4-vmg9.json b/advisories/unreviewed/2025/01/GHSA-rhvx-9vr4-vmg9/GHSA-rhvx-9vr4-vmg9.json new file mode 100644 index 00000000000..2825eb3afbe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rhvx-9vr4-vmg9/GHSA-rhvx-9vr4-vmg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhvx-9vr4-vmg9", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39798" + ], + "details": "Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_protocol` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39798" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rp6x-j4c5-4rvc/GHSA-rp6x-j4c5-4rvc.json b/advisories/unreviewed/2025/01/GHSA-rp6x-j4c5-4rvc/GHSA-rp6x-j4c5-4rvc.json new file mode 100644 index 00000000000..b3a523a6a98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rp6x-j4c5-4rvc/GHSA-rp6x-j4c5-4rvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6x-j4c5-4rvc", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-35275" + ], + "details": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35275" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rrmg-hr5x-6w4q/GHSA-rrmg-hr5x-6w4q.json b/advisories/unreviewed/2025/01/GHSA-rrmg-hr5x-6w4q/GHSA-rrmg-hr5x-6w4q.json index 9db204d48ab..12370d9cb07 100644 --- a/advisories/unreviewed/2025/01/GHSA-rrmg-hr5x-6w4q/GHSA-rrmg-hr5x-6w4q.json +++ b/advisories/unreviewed/2025/01/GHSA-rrmg-hr5x-6w4q/GHSA-rrmg-hr5x-6w4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rrmg-hr5x-6w4q", - "modified": "2025-01-14T00:30:45Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:45Z", "aliases": [ "CVE-2023-42246" ], "details": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v34h-7f4q-76h6/GHSA-v34h-7f4q-76h6.json b/advisories/unreviewed/2025/01/GHSA-v34h-7f4q-76h6/GHSA-v34h-7f4q-76h6.json new file mode 100644 index 00000000000..0c1cf284ee0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v34h-7f4q-76h6/GHSA-v34h-7f4q-76h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v34h-7f4q-76h6", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-46670" + ], + "details": "An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46670" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4mr-pqhx-vpm2/GHSA-v4mr-pqhx-vpm2.json b/advisories/unreviewed/2025/01/GHSA-v4mr-pqhx-vpm2/GHSA-v4mr-pqhx-vpm2.json new file mode 100644 index 00000000000..9f7845b82a6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v4mr-pqhx-vpm2/GHSA-v4mr-pqhx-vpm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4mr-pqhx-vpm2", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-55591" + ], + "details": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55591" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-535" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v729-w778-vqwm/GHSA-v729-w778-vqwm.json b/advisories/unreviewed/2025/01/GHSA-v729-w778-vqwm/GHSA-v729-w778-vqwm.json new file mode 100644 index 00000000000..3e35febfc96 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v729-w778-vqwm/GHSA-v729-w778-vqwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v729-w778-vqwm", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-35278" + ], + "details": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35278" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v8p8-w9q2-q67j/GHSA-v8p8-w9q2-q67j.json b/advisories/unreviewed/2025/01/GHSA-v8p8-w9q2-q67j/GHSA-v8p8-w9q2-q67j.json new file mode 100644 index 00000000000..cf2c6098c06 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v8p8-w9q2-q67j/GHSA-v8p8-w9q2-q67j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8p8-w9q2-q67j", + "modified": "2025-01-14T15:30:54Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-54021" + ], + "details": "An improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 allows attacker to execute unauthorized code or commands via crafted HTTP header.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54021" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-113" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w29f-xpw3-353w/GHSA-w29f-xpw3-353w.json b/advisories/unreviewed/2025/01/GHSA-w29f-xpw3-353w/GHSA-w29f-xpw3-353w.json new file mode 100644 index 00000000000..4f89f893dfe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w29f-xpw3-353w/GHSA-w29f-xpw3-353w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w29f-xpw3-353w", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-36512" + ], + "details": "An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36512" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-152" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json b/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json new file mode 100644 index 00000000000..9237c7710c0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w9pq-h9mh-jm92/GHSA-w9pq-h9mh-jm92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9pq-h9mh-jm92", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-36493" + ], + "details": "A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36493" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wcfj-9wq6-7h82/GHSA-wcfj-9wq6-7h82.json b/advisories/unreviewed/2025/01/GHSA-wcfj-9wq6-7h82/GHSA-wcfj-9wq6-7h82.json index b30a112ba2b..9dcdd9055fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-wcfj-9wq6-7h82/GHSA-wcfj-9wq6-7h82.json +++ b/advisories/unreviewed/2025/01/GHSA-wcfj-9wq6-7h82/GHSA-wcfj-9wq6-7h82.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wcfj-9wq6-7h82", - "modified": "2025-01-14T00:30:46Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:46Z", "aliases": [ "CVE-2023-42247" ], "details": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json b/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json new file mode 100644 index 00000000000..2add07ce194 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wcvc-h2qg-4xqg/GHSA-wcvc-h2qg-4xqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcvc-h2qg-4xqg", + "modified": "2025-01-14T15:30:55Z", + "published": "2025-01-14T15:30:55Z", + "aliases": [ + "CVE-2024-39357" + ], + "details": "A stack-based buffer overflow vulnerability exists in the wireless.cgi SetName() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39357" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wh2c-vg4v-4q9m/GHSA-wh2c-vg4v-4q9m.json b/advisories/unreviewed/2025/01/GHSA-wh2c-vg4v-4q9m/GHSA-wh2c-vg4v-4q9m.json new file mode 100644 index 00000000000..e5f662f18ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wh2c-vg4v-4q9m/GHSA-wh2c-vg4v-4q9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh2c-vg4v-4q9m", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39793" + ], + "details": "Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_name` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39793" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-15" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json b/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json index 62cde0ae43a..77ec2d4f339 100644 --- a/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json +++ b/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wj4g-3v6m-x76m", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-25371" ], "details": "Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T16:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wp3h-cvvj-q2gw/GHSA-wp3h-cvvj-q2gw.json b/advisories/unreviewed/2025/01/GHSA-wp3h-cvvj-q2gw/GHSA-wp3h-cvvj-q2gw.json new file mode 100644 index 00000000000..d862abdd0e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wp3h-cvvj-q2gw/GHSA-wp3h-cvvj-q2gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp3h-cvvj-q2gw", + "modified": "2025-01-14T15:30:56Z", + "published": "2025-01-14T15:30:56Z", + "aliases": [ + "CVE-2024-39768" + ], + "details": "Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the `cli_name` POST parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39768" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wrf4-8gjw-vgxw/GHSA-wrf4-8gjw-vgxw.json b/advisories/unreviewed/2025/01/GHSA-wrf4-8gjw-vgxw/GHSA-wrf4-8gjw-vgxw.json index e010f6d9a0a..22c77695b16 100644 --- a/advisories/unreviewed/2025/01/GHSA-wrf4-8gjw-vgxw/GHSA-wrf4-8gjw-vgxw.json +++ b/advisories/unreviewed/2025/01/GHSA-wrf4-8gjw-vgxw/GHSA-wrf4-8gjw-vgxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wrf4-8gjw-vgxw", - "modified": "2025-01-14T00:30:46Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-14T00:30:46Z", "aliases": [ "CVE-2023-42250" ], "details": "Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json b/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json index c7abf58d626..9580abc0f46 100644 --- a/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json +++ b/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5wr-hg6v-9cj3", - "modified": "2025-01-10T18:31:41Z", + "modified": "2025-01-14T15:30:51Z", "published": "2025-01-10T18:31:41Z", "aliases": [ "CVE-2024-29971" ], "details": "Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T16:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x6vp-5v5h-8v6q/GHSA-x6vp-5v5h-8v6q.json b/advisories/unreviewed/2025/01/GHSA-x6vp-5v5h-8v6q/GHSA-x6vp-5v5h-8v6q.json new file mode 100644 index 00000000000..6513e1c496c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x6vp-5v5h-8v6q/GHSA-x6vp-5v5h-8v6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6vp-5v5h-8v6q", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-35277" + ], + "details": "A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35277" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xpch-9h27-3hpf/GHSA-xpch-9h27-3hpf.json b/advisories/unreviewed/2025/01/GHSA-xpch-9h27-3hpf/GHSA-xpch-9h27-3hpf.json new file mode 100644 index 00000000000..ae4b96dbb5c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xpch-9h27-3hpf/GHSA-xpch-9h27-3hpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpch-9h27-3hpf", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-46668" + ], + "details": "An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46668" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xx9m-2fc7-mhx8/GHSA-xx9m-2fc7-mhx8.json b/advisories/unreviewed/2025/01/GHSA-xx9m-2fc7-mhx8/GHSA-xx9m-2fc7-mhx8.json new file mode 100644 index 00000000000..e338b9eacb7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xx9m-2fc7-mhx8/GHSA-xx9m-2fc7-mhx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx9m-2fc7-mhx8", + "modified": "2025-01-14T15:30:53Z", + "published": "2025-01-14T15:30:53Z", + "aliases": [ + "CVE-2024-46664" + ], + "details": "A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46664" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-310" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:31Z" + } +} \ No newline at end of file