Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-06-05 15:33:02 +00:00
parent d88a0850fb
commit fe57b45025
70 changed files with 873 additions and 84 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7v25-cx6v-gf9w",
"modified": "2022-05-14T01:48:06Z",
"modified": "2025-06-05T15:31:16Z",
"published": "2022-05-14T01:48:06Z",
"aliases": [
"CVE-2018-18760"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -31,6 +31,7 @@
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-121",
"CWE-787"
],
"severity": "CRITICAL",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxgc-qp86-4mg6",
"modified": "2024-05-15T00:30:38Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2024-05-15T00:30:38Z",
"aliases": [
"CVE-2024-31483"
],
"details": "An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.\n\n",
"details": "An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,22 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhph-75hg-j96m",
"modified": "2024-05-21T12:30:53Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2024-05-21T12:30:53Z",
"aliases": [
"CVE-2024-4420"
],
"details": "There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.  * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for example a number or an array. This will crash as Tink just assumes any valid JSON input will contain an object.\n\n\n * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input containing many nested JSON objects. This may result in a stack overflow.\n\n\nWe recommend upgrading to version 2.1.3 or above",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:D/RE:L/U:Green"
}
],
"affected": [],
"references": [
{
@@ -23,7 +32,7 @@
"cwe_ids": [
"CWE-116"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T12:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6999-6m26-m9xx",
"modified": "2024-11-19T18:31:06Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2024-11-19T18:31:06Z",
"aliases": [
"CVE-2024-48069"
],
"details": "A remote code execution (RCE) vulnerability in the component /inventory/doCptimpoptInventory of Weaver Ecology v9.* allows attackers to execute arbitrary code via injecting a crafted payload into the name of an uploaded file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-362"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-19T18:15:21Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rf66-cpg6-q99p",
"modified": "2024-11-19T18:31:06Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2024-11-19T18:31:06Z",
"aliases": [
"CVE-2024-48072"
],
"details": "Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-19T18:15:21Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvcg-crx7-qcjv",
"modified": "2024-11-19T18:31:06Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2024-11-19T18:31:06Z",
"aliases": [
"CVE-2024-48070"
],
"details": "Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-19T18:15:21Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85qx-mfpj-cvj4",
"modified": "2025-04-03T18:30:53Z",
"modified": "2025-06-05T15:31:21Z",
"published": "2025-01-26T06:30:48Z",
"aliases": [
"CVE-2024-10628"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7jq-35x5-2p74",
"modified": "2025-01-09T12:30:56Z",
"modified": "2025-06-05T15:31:20Z",
"published": "2025-01-09T12:30:56Z",
"aliases": [
"CVE-2024-6155"
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-862"
],
"severity": "MODERATE",
@@ -38,7 +38,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-23"
"CWE-23",
"CWE-704"
],
"severity": "LOW",
"github_reviewed": false,
@@ -54,7 +54,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g6q-j56q-qw54",
"modified": "2025-05-08T09:30:23Z",
"modified": "2025-06-05T15:31:22Z",
"published": "2025-05-08T09:30:23Z",
"aliases": [
"CVE-2025-37800"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: fix potential NULL pointer dereference in dev_uevent()\n\nIf userspace reads \"uevent\" device attribute at the same time as another\nthreads unbinds the device from its driver, change to dev->driver from a\nvalid pointer to NULL may result in crash. Fix this by using READ_ONCE()\nwhen fetching the pointer, and take bus' drivers klist lock to make sure\ndriver instance will not disappear while we access it.\n\nUse WRITE_ONCE() when setting the driver pointer to ensure there is no\ntearing.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-08T07:15:50Z"
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285"
"CWE-285",
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j4j-xg7r-jh7c",
"modified": "2025-05-08T09:30:25Z",
"modified": "2025-06-05T15:31:23Z",
"published": "2025-05-08T09:30:25Z",
"aliases": [
"CVE-2025-1253"
],
"details": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 4.5 before 6.1.2.23.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More