Skip to content

Commit adb584b

Browse files
Advisory Database Sync
1 parent f71ad6f commit adb584b

File tree

85 files changed

+2850
-71
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

85 files changed

+2850
-71
lines changed

advisories/unreviewed/2024/03/GHSA-cxqp-32c8-ch8c/GHSA-cxqp-32c8-ch8c.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cxqp-32c8-ch8c",
4-
"modified": "2024-03-20T15:32:57Z",
4+
"modified": "2025-05-13T00:31:10Z",
55
"published": "2024-03-20T15:32:57Z",
66
"aliases": [
77
"CVE-2024-2721"
88
],
9-
"details": "Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.\n\n",
9+
"details": "Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",

advisories/unreviewed/2024/03/GHSA-r5xr-mfqp-qmrq/GHSA-r5xr-mfqp-qmrq.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,9 @@
2525
}
2626
],
2727
"database_specific": {
28-
"cwe_ids": [],
28+
"cwe_ids": [
29+
"CWE-79"
30+
],
2931
"severity": "MODERATE",
3032
"github_reviewed": false,
3133
"github_reviewed_at": null,

advisories/unreviewed/2025/05/GHSA-27f3-wjfj-399m/GHSA-27f3-wjfj-399m.json

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-27f3-wjfj-399m",
4-
"modified": "2025-05-12T18:31:46Z",
4+
"modified": "2025-05-13T00:31:12Z",
55
"published": "2025-05-12T18:31:46Z",
66
"aliases": [
77
"CVE-2025-45779"
88
],
99
"details": "Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -24,8 +29,10 @@
2429
}
2530
],
2631
"database_specific": {
27-
"cwe_ids": [],
28-
"severity": null,
32+
"cwe_ids": [
33+
"CWE-120"
34+
],
35+
"severity": "CRITICAL",
2936
"github_reviewed": false,
3037
"github_reviewed_at": null,
3138
"nvd_published_at": "2025-05-12T17:15:47Z"
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-289j-qjv7-62fr",
4+
"modified": "2025-05-13T00:31:15Z",
5+
"published": "2025-05-13T00:31:15Z",
6+
"aliases": [
7+
"CVE-2025-31257"
8+
],
9+
"details": "This issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31257"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122404"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122716"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122719"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://support.apple.com/en-us/122720"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://support.apple.com/en-us/122721"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://support.apple.com/en-us/122722"
40+
}
41+
],
42+
"database_specific": {
43+
"cwe_ids": [],
44+
"severity": null,
45+
"github_reviewed": false,
46+
"github_reviewed_at": null,
47+
"nvd_published_at": "2025-05-12T22:15:25Z"
48+
}
49+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2fgw-qh65-pxv5",
4+
"modified": "2025-05-13T00:31:13Z",
5+
"published": "2025-05-13T00:31:13Z",
6+
"aliases": [
7+
"CVE-2025-30442"
8+
],
9+
"details": "The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30442"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122373"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122717"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122718"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2025-05-12T22:15:21Z"
36+
}
37+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2xqw-mg48-p4j5",
4+
"modified": "2025-05-13T00:31:14Z",
5+
"published": "2025-05-13T00:31:14Z",
6+
"aliases": [
7+
"CVE-2025-31232"
8+
],
9+
"details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31232"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122716"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122717"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122718"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2025-05-12T22:15:23Z"
36+
}
37+
}
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3jpv-h4fh-v8h9",
4+
"modified": "2025-05-13T00:31:14Z",
5+
"published": "2025-05-13T00:31:14Z",
6+
"aliases": [
7+
"CVE-2025-31215"
8+
],
9+
"details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected process crash.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31215"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122404"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122405"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122716"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://support.apple.com/en-us/122719"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://support.apple.com/en-us/122720"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://support.apple.com/en-us/122721"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://support.apple.com/en-us/122722"
44+
}
45+
],
46+
"database_specific": {
47+
"cwe_ids": [],
48+
"severity": null,
49+
"github_reviewed": false,
50+
"github_reviewed_at": null,
51+
"nvd_published_at": "2025-05-12T22:15:22Z"
52+
}
53+
}
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-422f-7vrg-37qx",
4+
"modified": "2025-05-13T00:31:13Z",
5+
"published": "2025-05-13T00:31:13Z",
6+
"aliases": [
7+
"CVE-2025-30448"
8+
],
9+
"details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.6, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Ventura 13.7.6, macOS Sequoia 15.4. An attacker may be able to turn on sharing of an iCloud folder without authentication.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30448"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122373"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122404"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122405"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://support.apple.com/en-us/122717"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://support.apple.com/en-us/122718"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://support.apple.com/en-us/122721"
40+
}
41+
],
42+
"database_specific": {
43+
"cwe_ids": [],
44+
"severity": null,
45+
"github_reviewed": false,
46+
"github_reviewed_at": null,
47+
"nvd_published_at": "2025-05-12T22:15:21Z"
48+
}
49+
}
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-53gq-27mh-rqhg",
4+
"modified": "2025-05-13T00:31:14Z",
5+
"published": "2025-05-13T00:31:14Z",
6+
"aliases": [
7+
"CVE-2025-31222"
8+
],
9+
"details": "A correctness issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A user may be able to elevate privileges.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31222"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122404"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://support.apple.com/en-us/122716"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://support.apple.com/en-us/122717"
28+
},
29+
{
30+
"type": "WEB",
31+
"url": "https://support.apple.com/en-us/122718"
32+
},
33+
{
34+
"type": "WEB",
35+
"url": "https://support.apple.com/en-us/122720"
36+
},
37+
{
38+
"type": "WEB",
39+
"url": "https://support.apple.com/en-us/122721"
40+
},
41+
{
42+
"type": "WEB",
43+
"url": "https://support.apple.com/en-us/122722"
44+
}
45+
],
46+
"database_specific": {
47+
"cwe_ids": [],
48+
"severity": null,
49+
"github_reviewed": false,
50+
"github_reviewed_at": null,
51+
"nvd_published_at": "2025-05-12T22:15:22Z"
52+
}
53+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-53jv-fmw5-42vr",
4+
"modified": "2025-05-13T00:31:15Z",
5+
"published": "2025-05-13T00:31:15Z",
6+
"aliases": [
7+
"CVE-2025-31250"
8+
],
9+
"details": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31250"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://support.apple.com/en-us/122716"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2025-05-12T22:15:25Z"
28+
}
29+
}

0 commit comments

Comments
 (0)