{"seed":"2026-09-05b","drawnAt":"2026-09-05T19:05:35.383236+00:00","population":365,"n":30,"reviewer":"agent-2026-09-05b","classes":["clean","clean_same_day","clean_bulk","hard_fp","ambiguous"],"rows":[{"cveId":"CVE-2024-8404","cna":"PaperCut","vendor":"papercut","product":"papercut ng, papercut mf","branch":"0","before":"23.0.9","after":"24.1.7","opBefore":"lt","opAfter":"lt","published":"2024-09-26T01:42:49.400Z","correctedAt":"2025-05-13T02:16:36+00:00","lagDays":229.0,"sameDay":false,"bulkCommit":false,"bulkSize":1,"states":{"first":{"commit":"0603286bb605","state":"PUBLISHED","dateUpdated":"2024-09-26T01:42:49.400Z","versions":[{"version":"0","lessThan":"23.0.9","status":"affected","versionType":"custom","changes":[{"at":"23.0.9","status":"unaffected"}]}],"description":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nNote: \n\nThis CVE has been split from CVE-2024-3037.","solutions":null},"parent":{"commit":"c817c257b8a8","state":"PUBLISHED","dateUpdated":"2024-09-26T15:01:21.951Z","versions":[{"version":"0","lessThan":"23.0.9","status":"affected","versionType":"custom","changes":[{"at":"23.0.9","status":"unaffected"}]}],"description":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nNote: \n\nThis CVE has been split from CVE-2024-3037.","solutions":null},"located":{"commit":"152ec025e83b","state":"PUBLISHED","dateUpdated":"2025-05-13T01:39:33.742Z","versions":[{"version":"0","lessThan":"24.1.7","status":"affected","versionType":"custom","changes":[{"at":"24.1.7","status":"unaffected"}]}],"description":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nUpdate:\n\nThis CVE has been updated in May 2025 to update the fixed version and fix ","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-05-13T01:39:33.742Z","versions":[{"version":"0","lessThan":"24.1.7","status":"affected","versionType":"custom","changes":[{"at":"24.1.7","status":"unaffected"}]}],"description":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nUpdate:\n\nThis CVE has been updated in May 2025 to update the fixed version and fix ","solutions":null}},"classification":"clean","notes":"0603286bb60 <23.0.9 (+changes[] unaffected 23.0.9); 152ec025e83 (2025-05-13) <24.1.7 with changes[] 24.1.7. 229 d. True by record. Now one row (was two: lt and changes[] spellings)."},{"cveId":"CVE-2026-50525","cna":"microsoft","vendor":"microsoft","product":".net 10.0","branch":"10.0.0","before":"10.0.6","after":"10.0.10","opBefore":"lt","opAfter":"lt","published":"2026-07-14T19:29:54.357Z","correctedAt":"2026-07-22T20:52:23+00:00","lagDays":8.1,"sameDay":false,"bulkCommit":false,"bulkSize":8,"states":{"first":{"commit":"b629eea96564","state":"PUBLISHED","dateUpdated":"2026-07-14T19:30:01.286Z","versions":[{"version":"10.0.0","lessThan":"10.0.6","status":"affected","versionType":"custom"}],"description":"Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.","solutions":null},"parent":{"commit":"f660ca50782a","state":"PUBLISHED","dateUpdated":"2026-07-22T15:34:26.327Z","versions":[{"version":"10.0.0","lessThan":"10.0.6","status":"affected","versionType":"custom"}],"description":"Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.","solutions":null},"located":{"commit":"27eee309d10a","state":"PUBLISHED","dateUpdated":"2026-07-22T20:32:41.671Z","versions":[{"version":"10.0.0","lessThan":"10.0.10","status":"affected","versionType":"custom"}],"description":"Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-09-04T22:15:20.147Z","versions":[{"version":"10.0.0","lessThan":"10.0.10","status":"affected","versionType":"custom"}],"description":"Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.","solutions":null}},"classification":"clean","notes":"b629eea9656 <10.0.6; 27eee309d10 (2026-07-22) <10.0.10. 8.1 d, 3 components so corrected_to_shipped_build cannot apply. Same event as the 2026-09-05 sample's .NET 10 rows. True by record."},{"cveId":"CVE-2023-38171","cna":"microsoft","vendor":"microsoft","product":"microsoft visual studio 2022 version 17.6","branch":"17.6.0","before":"17.6.8","after":"17.6.9","opBefore":"lt","opAfter":"lt","published":"2023-10-10T17:07:23.843Z","correctedAt":"2024-12-10T18:16:51+00:00","lagDays":427.0,"sameDay":false,"bulkCommit":false,"bulkSize":6,"states":{"first":{"commit":"c1414369ab3b","state":"PUBLISHED","dateUpdated":"2023-10-10T17:07:23.843Z","versions":[{"version":"17.6.0","lessThan":"17.6.8","status":"affected","versionType":"custom"}],"description":"Microsoft QUIC Denial of Service Vulnerability","solutions":null},"parent":{"commit":"690fa66ea84d","state":"PUBLISHED","dateUpdated":"2024-08-02T17:30:14.169Z","versions":[{"version":"17.6.0","lessThan":"17.6.8","status":"affected","versionType":"custom"}],"description":"Microsoft QUIC Denial of Service Vulnerability","solutions":null},"located":{"commit":"d991ed2d692f","state":"PUBLISHED","dateUpdated":"2024-12-10T18:13:15.150Z","versions":[{"version":"17.6.0","lessThan":"17.6.9","status":"affected","versionType":"custom"}],"description":"Microsoft QUIC Denial of Service Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-04-14T22:45:47.105Z","versions":[{"version":"17.6.0","lessThan":"17.6.9","status":"affected","versionType":"custom"}],"description":"Microsoft QUIC Denial of Service Vulnerability","solutions":null}},"classification":"ambiguous","notes":"c1414369ab3 <17.6.8; d991ed2d692 (2024-12-10, the 107-record cpeApplicability rewrite with every VS/.NET boundary uniformly +1 patch). 427 d. Literally true; reads as a re-encoding, not a fix that moved (same verdict as the 17.4 row of this record in the 2026-09-05 sample)."},{"cveId":"CVE-2026-45501","cna":"microsoft","vendor":"microsoft","product":"microsoft exchange server subscription edition rtm","branch":"15.02.0.0","before":"15.02.2562.043","after":"15.02.2562.045","opBefore":"lt","opAfter":"lt","published":"2026-06-09T17:04:45.533Z","correctedAt":"2026-07-28T22:39:39+00:00","lagDays":49.2,"sameDay":false,"bulkCommit":false,"bulkSize":28,"states":{"first":{"commit":"5837007300b4","state":"PUBLISHED","dateUpdated":"2026-06-09T17:04:45.533Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.043","status":"affected","versionType":"custom"}],"description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","solutions":null},"parent":{"commit":"f58982f85f82","state":"PUBLISHED","dateUpdated":"2026-07-15T20:09:11.215Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.043","status":"affected","versionType":"custom"}],"description":"Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.","solutions":null},"located":{"commit":"0e5597791d19","state":"PUBLISHED","dateUpdated":"2026-07-28T22:18:38.869Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.045","status":"affected","versionType":"custom"}],"description":"Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-25T22:43:09.889Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.045","status":"affected","versionType":"custom"}],"description":"Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.","solutions":null}},"classification":"clean","notes":"5837007300b <15.02.2562.043; 0e5597791d1 (2026-07-28, 28 counted rows) <15.02.2562.045. 49 d, revision-only but outside the 14 d window. True by record (Exchange SU re-release)."},{"cveId":"CVE-2024-29059","cna":"microsoft","vendor":"microsoft","product":"microsoft .net framework 3.5 and 4.8","branch":"4.8.0","before":"4.8.4682.0","after":"4.8.04690.02","opBefore":"lt","opAfter":"lt","published":"2024-03-22T23:09:05.745Z","correctedAt":"2024-12-31T19:16:48+00:00","lagDays":47.0,"sameDay":false,"bulkCommit":false,"bulkSize":2,"states":{"first":{"commit":"d0c621cea47b","state":"PUBLISHED","dateUpdated":"2024-03-22T23:09:05.745Z","versions":[{"version":"4.8.0","lessThan":"4.8.4682.0","status":"affected","versionType":"custom"}],"description":".NET Framework Information Disclosure Vulnerability","solutions":null},"parent":{"commit":"d08302facb0f","state":"PUBLISHED","dateUpdated":"2024-08-12T17:38:51.372Z","versions":[{"version":"4.8.0","lessThan":"4.8.04690.02","status":"affected","versionType":"custom"},{"version":"4.8.0","lessThan":"4.8.09214.01","status":"affected","versionType":"custom"}],"description":".NET Framework Information Disclosure Vulnerability","solutions":null},"located":{"commit":"7f6b2f9b9a38","state":"PUBLISHED","dateUpdated":"2024-12-31T19:08:18.659Z","versions":[{"version":"4.8.0","lessThan":"4.8.04690.02","status":"affected","versionType":"custom"}],"description":".NET Framework Information Disclosure Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-10-21T23:05:22.579Z","versions":[{"version":"4.8.0","lessThan":"4.8.04690.02","status":"affected","versionType":"custom"}],"description":".NET Framework Information Disclosure Vulnerability","solutions":null}},"classification":"clean","notes":"d0c621cea47 <4.8.4682.0; 4e6d9781bc3 (2024-05-08) <4.8.04690.02 (+ a 09214.01 entry); flip-flopped back on 2024-05-28 (313ed35f169) and forward again (240f9bfae93); 7f6b2f9b9a3 single 04690.02. 47 d. True by record (May 2024 .NET Framework re-release)."},{"cveId":"CVE-2026-35423","cna":"microsoft","vendor":"microsoft","product":"windows 10 version 22h2","branch":"10.0.19045.0","before":"10.0.19045.7291","after":"10.0.19045.7417","opBefore":"lt","opAfter":"lt","published":"2026-05-12T16:58:33.334Z","correctedAt":"2026-06-09T18:40:59+00:00","lagDays":28.1,"sameDay":false,"bulkCommit":true,"bulkSize":54,"states":{"first":{"commit":"9c68433765b3","state":"PUBLISHED","dateUpdated":"2026-05-12T16:58:33.334Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.","solutions":null},"parent":{"commit":"82ec24acf6dd","state":"PUBLISHED","dateUpdated":"2026-06-05T16:38:41.147Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.","solutions":null},"located":{"commit":"41e153aaa1d3","state":"PUBLISHED","dateUpdated":"2026-06-09T18:08:15.949Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-10T15:12:46.297Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.","solutions":null}},"classification":"clean_bulk","notes":"9c68433765b <10.0.19045.7291; 41e153aaa1d (2026-06-09, 54 counted rows) <10.0.19045.7417. 28 d. True by record."},{"cveId":"CVE-2025-62730","cna":"CERT-PL","vendor":"soplanning","product":"soplanning","branch":"0","before":"1.54","after":"1.55","opBefore":"lt","opAfter":"lt","published":"2025-11-20T15:44:09.430Z","correctedAt":"2025-11-20T15:58:06+00:00","lagDays":0.0,"sameDay":true,"bulkCommit":false,"bulkSize":8,"states":{"first":{"commit":"e43c5e864f06","state":"PUBLISHED","dateUpdated":"2025-11-20T15:46:36.128Z","versions":[{"version":"0","lessThan":"1.54","status":"affected","versionType":"semver"}],"description":"SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges.\n\nThis issue was fixed in version 1.54.","solutions":null},"parent":{"commit":"e43c5e864f06","state":"PUBLISHED","dateUpdated":"2025-11-20T15:46:36.128Z","versions":[{"version":"0","lessThan":"1.54","status":"affected","versionType":"semver"}],"description":"SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges.\n\nThis issue was fixed in version 1.54.","solutions":null},"located":{"commit":"a45610da5117","state":"PUBLISHED","dateUpdated":"2025-11-20T15:51:58.760Z","versions":[{"version":"0","lessThan":"1.55","status":"affected","versionType":"semver"}],"description":"SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges.\n\nThis issue was fixed in version 1.55.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-11-20T21:24:56.253Z","versions":[{"version":"0","lessThan":"1.55","status":"affected","versionType":"semver"}],"description":"SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges.\n\nThis issue was fixed in version 1.55.","solutions":null}},"classification":"clean_same_day","notes":"e43c5e864f0 <1.54; a45610da511 (+7 min) <1.55, description 'fixed in 1.55'. Same-day correction; same event as CVE-2025-62729 in the 2026-09-05 sample."},{"cveId":"CVE-2025-24213","cna":"apple","vendor":"apple","product":"ios and ipados","branch":"0","before":"18.4","after":"18.5","opBefore":"lt","opAfter":"lt","published":"2025-03-31T22:23:48.296Z","correctedAt":"2025-05-13T16:37:12+00:00","lagDays":42.8,"sameDay":false,"bulkCommit":false,"bulkSize":4,"states":{"first":{"commit":"d05cbfff36ec","state":"PUBLISHED","dateUpdated":"2025-03-31T22:23:48.296Z","versions":[{"version":"unspecified","lessThan":"18.4","status":"affected","versionType":"custom"}],"description":"This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A type confusion issue could lead to memory corruption.","solutions":null},"parent":{"commit":"8e99ce67a7d9","state":"PUBLISHED","dateUpdated":"2025-04-03T17:46:55.488Z","versions":[{"version":"unspecified","lessThan":"18.4","status":"affected","versionType":"custom"}],"description":"This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A type confusion issue could lead to memory corruption.","solutions":null},"located":{"commit":"21fda8d8f011","state":"PUBLISHED","dateUpdated":"2025-05-13T16:29:10.048Z","versions":[{"version":"unspecified","lessThan":"18.5","status":"affected","versionType":"custom"}],"description":"This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.5, Safari 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, watchOS 11.5, visionOS 2.5. A type confusion issue could lead to memory corruption.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-04-02T18:22:16.158Z","versions":[{"version":"0","lessThan":"18.5","status":"affected","versionType":"custom"}],"description":"This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.","solutions":null}},"classification":"clean","notes":"d05cbfff36e <18.4 with 'fixed in iOS 18.4'; 21fda8d8f01 (2025-05-13) <18.5 with 'fixed in iOS 18.5' (description rewritten). 42.8 d. True by record: Apple re-listed the fix under 18.5."},{"cveId":"CVE-2026-69306","cna":"microsoft","vendor":"microsoft","product":"visual studio code","branch":"1.0.0","before":"1.132.1","after":"1.135","opBefore":"lt","opAfter":"lt","published":"2026-08-11T17:05:18.170Z","correctedAt":"2026-09-02T17:18:37+00:00","lagDays":17.1,"sameDay":false,"bulkCommit":false,"bulkSize":8,"states":{"first":{"commit":"b6d3470453ff","state":"PUBLISHED","dateUpdated":"2026-08-11T17:05:18.170Z","versions":[{"version":"1.0.0","lessThan":"1.132.1","status":"affected","versionType":"custom"}],"description":"Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.","solutions":null},"parent":{"commit":"56fd9f21b4ca","state":"PUBLISHED","dateUpdated":"2026-08-31T20:05:59.803Z","versions":[{"version":"1.0.0","lessThan":"2026.3.1","status":"affected","versionType":"custom"}],"description":"Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.","solutions":null},"located":{"commit":"d3bae727c054","state":"PUBLISHED","dateUpdated":"2026-09-02T17:09:53.283Z","versions":[{"version":"1.0.0","lessThan":"1.135","status":"affected","versionType":"custom"}],"description":"Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-09-03T21:24:00.261Z","versions":[{"version":"1.0.0","lessThan":"1.135","status":"affected","versionType":"custom"}],"description":"Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.","solutions":null}},"classification":"clean","notes":"b6d3470453f <1.132.1; 162f3fc4470 (2026-08-28) <2026.3.1 (calendar respelling, refused as version_scheme_changed at that commit); d3bae727c05 (2026-09-02) <1.135. 17.1 d to first replacement. True by record."},{"cveId":"CVE-2024-26885","cna":"Linux","vendor":"linux","product":"linux","branch":"5.10.*","before":"5.10.214","after":"5.10.227","opBefore":"unaffected_start","opAfter":"unaffected_start","published":"2024-04-17T10:27:40.300Z","correctedAt":"2025-01-24T16:09:00+00:00","lagDays":282.2,"sameDay":false,"bulkCommit":false,"bulkSize":2,"states":{"first":{"commit":"0967f2d0867f","state":"PUBLISHED","dateUpdated":"2024-04-17T10:27:40.300Z","versions":[{"version":"6f9d451ab1a3","lessThan":"225da02acdc9","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"c826502bed93","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"edf7990baa48","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"250051acc21f","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"22079b3a4233","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"e89386f62ce9","status":"affected","versionType":"git"},{"version":"6f9d451ab1a3","lessThan":"281d464a34f5","status":"affected","versionType":"git"},{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"custom"},{"version":"5.10.214","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"custom"},{"version":"5.15.153","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"custom"},{"version":"6.1.83","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"custom"},{"version":"6.6.23","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"custom"},{"version":"6.7.11","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"custom"},{"version":"6.8.2","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"custom"},{"version":"6.9-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix DEVMAP_HASH overflow check on 32-bit arches\n\nThe devmap code allocates a number hash buckets equal to the next power\nof two of the max_entries value provided when creating the map. When\nrounding up to the next power of two, the 32-bit variable storing the\nnumber of buckets can overflow, and the code checks for overflow by\nchecking if the truncated 32-bit value is equal to 0. However, on 32-bit\narches the rounding up itself can overflow mid-way through, because it\nends up doing a left-shift of 32 bits on an unsigned long value. If the\nsize of an unsigned long is four bytes, this is undefined behaviour, so\nthere is no guarantee that we'll end up with a nice and tidy 0-value at\nthe end.\n\nSyzbot managed to turn this ","solutions":null},"parent":{"commit":"ededfb997de7","state":"PUBLISHED","dateUpdated":"2024-12-19T08:49:29.194Z","versions":[{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"1f5e352b9088211fa5eb4e1639cd365f4f7d2f65","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"225da02acdc97af01b6bc6ce1a3e5362bf01d3fb","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"4b81a9f92b3676cb74b907a7a209b3d15bd9a7f9","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"c826502bed93970f2fd488918a7b8d5f1d30e2e3","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"edf7990baa48de5097daa9ac02e06cb4c798a737","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"250051acc21f9d4c5c595e4fcb55986ea08c4691","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"22079b3a423382335f47d9ed32114e6c9fe88d7c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"e89386f62ce9a9ab9a94835a9890883c23d9d52c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"281d464a34f540de166cee74b723e97ac2515ec3","status":"affected","versionType":"git"},{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.4.285","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.214","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.10.227","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.153","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.83","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.23","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.11","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8.2","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix DEVMAP_HASH overflow check on 32-bit arches\n\nThe devmap code allocates a number hash buckets equal to the next power\nof two of the max_entries value provided when creating the map. When\nrounding up to the next power of two, the 32-bit variable storing the\nnumber of buckets can overflow, and the code checks for overflow by\nchecking if the truncated 32-bit value is equal to 0. However, on 32-bit\narches the rounding up itself can overflow mid-way through, because it\nends up doing a left-shift of 32 bits on an unsigned long value. If the\nsize of an unsigned long is four bytes, this is undefined behaviour, so\nthere is no guarantee that we'll end up with a nice and tidy 0-value at\nthe end.\n\nSyzbot managed to turn this ","solutions":null},"located":{"commit":"6a6c4d448e30","state":"PUBLISHED","dateUpdated":"2025-01-24T16:01:16.461Z","versions":[{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"1f5e352b9088211fa5eb4e1639cd365f4f7d2f65","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"4b81a9f92b3676cb74b907a7a209b3d15bd9a7f9","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"c826502bed93970f2fd488918a7b8d5f1d30e2e3","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"edf7990baa48de5097daa9ac02e06cb4c798a737","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"250051acc21f9d4c5c595e4fcb55986ea08c4691","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"22079b3a423382335f47d9ed32114e6c9fe88d7c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"e89386f62ce9a9ab9a94835a9890883c23d9d52c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"281d464a34f540de166cee74b723e97ac2515ec3","status":"affected","versionType":"git"},{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.4.285","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.227","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.153","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.83","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.23","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.11","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8.2","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix DEVMAP_HASH overflow check on 32-bit arches\n\nThe devmap code allocates a number hash buckets equal to the next power\nof two of the max_entries value provided when creating the map. When\nrounding up to the next power of two, the 32-bit variable storing the\nnumber of buckets can overflow, and the code checks for overflow by\nchecking if the truncated 32-bit value is equal to 0. However, on 32-bit\narches the rounding up itself can overflow mid-way through, because it\nends up doing a left-shift of 32 bits on an unsigned long value. If the\nsize of an unsigned long is four bytes, this is undefined behaviour, so\nthere is no guarantee that we'll end up with a nice and tidy 0-value at\nthe end.\n\nSyzbot managed to turn this ","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-05T11:28:10.593Z","versions":[{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"1f5e352b9088211fa5eb4e1639cd365f4f7d2f65","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"4b81a9f92b3676cb74b907a7a209b3d15bd9a7f9","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"c826502bed93970f2fd488918a7b8d5f1d30e2e3","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"edf7990baa48de5097daa9ac02e06cb4c798a737","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"250051acc21f9d4c5c595e4fcb55986ea08c4691","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"22079b3a423382335f47d9ed32114e6c9fe88d7c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"e89386f62ce9a9ab9a94835a9890883c23d9d52c","status":"affected","versionType":"git"},{"version":"6f9d451ab1a33728adb72d7ff66a7b374d665176","lessThan":"281d464a34f540de166cee74b723e97ac2515ec3","status":"affected","versionType":"git"},{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.4.285","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.227","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.153","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.83","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.23","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.11","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8.2","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix DEVMAP_HASH overflow check on 32-bit arches\n\nThe devmap code allocates a number hash buckets equal to the next power\nof two of the max_entries value provided when creating the map. When\nrounding up to the next power of two, the 32-bit variable storing the\nnumber of buckets can overflow, and the code checks for overflow by\nchecking if the truncated 32-bit value is equal to 0. However, on 32-bit\narches the rounding up itself can overflow mid-way through, because it\nends up doing a left-shift of 32 bits on an unsigned long value. If the\nsize of an unsigned long is four bytes, this is undefined behaviour, so\nthere is no guarantee that we'll end up with a nice and tidy 0-value at\nthe end.\n\nSyzbot managed to turn this ","solutions":null}},"classification":"clean","notes":"0967f2d0867 unaffected 5.10.214; 5eca11e54f8 (2024-10-17) ADDED 5.10.227 beside it (still stated, so no move yet); 6a6c4d448e3 (2025-01-24) removed 5.10.214, leaving 5.10.227. 282 d. The 5.10 line's stated fix genuinely moved. True."},{"cveId":"CVE-2023-53431","cna":"Linux","vendor":"linux","product":"linux","branch":"6.2.*","before":"6.2.3","after":"6.2.12","opBefore":"unaffected_start","opAfter":"unaffected_start","published":"2025-09-18T16:04:11.748Z","correctedAt":"2025-10-02T07:10:45+00:00","lagDays":12.7,"sameDay":false,"bulkCommit":false,"bulkSize":6,"states":{"first":{"commit":"8d00fb9eb55d","state":"PUBLISHED","dateUpdated":"2025-09-18T16:04:11.748Z","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4863fefc8a8cc8e8f6c7635b12d9dffaa0a12d86","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"feefd5232ecb788f0666f75893a7a86faec8bbcc","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6069e04a922a0488bcf4f1017d38d18afda8194c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d68937dfc73ee7f61cf3424fa3225be93cacaa00","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6fce2307650a190e343a84537c278d499fa37c26","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5ca5470b33e5221dd3e5be81108697c22dd38b56","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f182ad02024d3f45374a9e0c9d76f28b776d762d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3fe97ff3d94934649abb0652028dd7296170c8d0","status":"affected","versionType":"git"},{"version":"4.14.308","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.276","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.235","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.173","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.99","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.16","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.3","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Don't attach if enclosure has no components\n\nAn enclosure with no components can't usefully be operated by the driver\n(since effectively it has nothing to manage), so report the problem and\ndon't attach. Not attaching also fixes an oops which could occur if the\ndriver tries to manage a zero component enclosure.\n\n[mkp: Switched to KERN_WARNING since this scenario is common]","solutions":null},"parent":{"commit":"46742e651a5f","state":"PUBLISHED","dateUpdated":"2025-10-01T07:39:41.511Z","versions":[{"version":"feefd5232ecb788f0666f75893a7a86faec8bbcc","lessThan":"4e7c498c3713b09bef20c76c7319555637e8bbd5","status":"affected","versionType":"git"},{"version":"6069e04a922a0488bcf4f1017d38d18afda8194c","lessThan":"110d425cdfb15006f3c4fde5264e786a247b6b36","status":"affected","versionType":"git"},{"version":"d68937dfc73ee7f61cf3424fa3225be93cacaa00","lessThan":"176d7345b89ced72020a313bfa4e7f345d1c3aed","status":"affected","versionType":"git"},{"version":"6fce2307650a190e343a84537c278d499fa37c26","lessThan":"05143d90ac90b7abc6692285895a1ef460e008ee","status":"affected","versionType":"git"},{"version":"5ca5470b33e5221dd3e5be81108697c22dd38b56","lessThan":"f8e702c54413eee2d8f94f61d18adadac7c87e87","status":"affected","versionType":"git"},{"version":"f182ad02024d3f45374a9e0c9d76f28b776d762d","lessThan":"eabc4872f172ecb8dd8536bc366a51868154a450","status":"affected","versionType":"git"},{"version":"3fe97ff3d94934649abb0652028dd7296170c8d0","lessThan":"c8e22b7a1694bb8d025ea636816472739d859145","status":"affected","versionType":"git"},{"version":"4863fefc8a8cc8e8f6c7635b12d9dffaa0a12d86","status":"affected","versionType":"git"},{"version":"4.19.276","lessThan":"4.19.281","status":"affected","versionType":"semver"},{"version":"5.4.235","lessThan":"5.4.241","status":"affected","versionType":"semver"},{"version":"5.10.173","lessThan":"5.10.178","status":"affected","versionType":"semver"},{"version":"5.15.99","lessThan":"5.15.108","status":"affected","versionType":"semver"},{"version":"6.1.16","lessThan":"6.1.25","status":"affected","versionType":"semver"},{"version":"6.2.3","lessThan":"6.2.12","status":"affected","versionType":"semver"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Handle enclosure with just a primary component gracefully\n\nThis reverts commit 3fe97ff3d949 (\"scsi: ses: Don't attach if enclosure\nhas no components\") and introduces proper handling of case where there are\nno detected secondary components, but primary component (enumerated in\nnum_enclosures) does exist. That fix was originally proposed by Ding Hui\n<dinghui@sangfor.com.cn>.\n\nCompletely ignoring devices that have one primary enclosure and no\nsecondary one results in ses_intf_add() bailing completely\n\n\tscsi 2:0:0:254: enclosure has no enumerated components\n        scsi 2:0:0:254: Failed to bind enclosure -12ven in valid configurations such\n\neven on valid configurations with 1 primary and 0 secondary enclosures as\n","solutions":null},"located":{"commit":"5755953667b8","state":"PUBLISHED","dateUpdated":"2025-10-02T07:04:20.059Z","versions":[{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"4e7c498c3713b09bef20c76c7319555637e8bbd5","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"110d425cdfb15006f3c4fde5264e786a247b6b36","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"176d7345b89ced72020a313bfa4e7f345d1c3aed","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"05143d90ac90b7abc6692285895a1ef460e008ee","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"f8e702c54413eee2d8f94f61d18adadac7c87e87","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"eabc4872f172ecb8dd8536bc366a51868154a450","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"c8e22b7a1694bb8d025ea636816472739d859145","status":"affected","versionType":"git"},{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","status":"unaffected","versionType":"semver"},{"version":"4.19.281","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.241","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.178","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.108","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.25","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.12","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Handle enclosure with just a primary component gracefully\n\nThis reverts commit 3fe97ff3d949 (\"scsi: ses: Don't attach if enclosure\nhas no components\") and introduces proper handling of case where there are\nno detected secondary components, but primary component (enumerated in\nnum_enclosures) does exist. That fix was originally proposed by Ding Hui\n<dinghui@sangfor.com.cn>.\n\nCompletely ignoring devices that have one primary enclosure and no\nsecondary one results in ses_intf_add() bailing completely\n\n\tscsi 2:0:0:254: enclosure has no enumerated components\n        scsi 2:0:0:254: Failed to bind enclosure -12ven in valid configurations such\n\neven on valid configurations with 1 primary and 0 secondary enclosures as\n","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-05T09:14:06.042Z","versions":[{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"4e7c498c3713b09bef20c76c7319555637e8bbd5","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"110d425cdfb15006f3c4fde5264e786a247b6b36","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"176d7345b89ced72020a313bfa4e7f345d1c3aed","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"05143d90ac90b7abc6692285895a1ef460e008ee","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"f8e702c54413eee2d8f94f61d18adadac7c87e87","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"eabc4872f172ecb8dd8536bc366a51868154a450","status":"affected","versionType":"git"},{"version":"9927c68864e9c39cc317b4f559309ba29e642168","lessThan":"c8e22b7a1694bb8d025ea636816472739d859145","status":"affected","versionType":"git"},{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","status":"unaffected","versionType":"semver"},{"version":"4.19.281","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.241","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.178","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.108","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.25","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.12","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ses: Handle enclosure with just a primary component gracefully\n\nThis reverts commit 3fe97ff3d949 (\"scsi: ses: Don't attach if enclosure\nhas no components\") and introduces proper handling of case where there are\nno detected secondary components, but primary component (enumerated in\nnum_enclosures) does exist. That fix was originally proposed by Ding Hui\n<dinghui@sangfor.com.cn>.\n\nCompletely ignoring devices that have one primary enclosure and no\nsecondary one results in ses_intf_add() bailing completely\n\n\tscsi 2:0:0:254: enclosure has no enumerated components\n        scsi 2:0:0:254: Failed to bind enclosure -12ven in valid configurations such\n\neven on valid configurations with 1 primary and 0 secondary enclosures as\n","solutions":null}},"classification":"clean","notes":"8d00fb9eb55 unaffected 6.2.3; 88b61419425 (2025-10-01) re-pointed the record at the revert: 6.2.3 <6.2.12 affected; 5755953667b unaffected 6.2.12. 12.7 d. Same record as the 5.10 row in the 2026-09-05 sample. True."},{"cveId":"CVE-2025-48807","cna":"microsoft","vendor":"microsoft","product":"windows server 2019","branch":"10.0.17763.0","before":"10.0.17763.7558","after":"10.0.17763.7792","opBefore":"lt","opAfter":"lt","published":"2025-08-12T17:10:44.021Z","correctedAt":"2025-09-09T23:53:25+00:00","lagDays":28.3,"sameDay":false,"bulkCommit":false,"bulkSize":16,"states":{"first":{"commit":"27973457af17","state":"PUBLISHED","dateUpdated":"2025-08-12T17:10:44.021Z","versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7558","status":"affected","versionType":"custom"}],"description":"Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.","solutions":null},"parent":{"commit":"b38265a1bf0d","state":"PUBLISHED","dateUpdated":"2025-08-28T19:41:07.241Z","versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7558","status":"affected","versionType":"custom"}],"description":"Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.","solutions":null},"located":{"commit":"b579ab59bc42","state":"PUBLISHED","dateUpdated":"2025-09-09T23:48:25.006Z","versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7792","status":"affected","versionType":"custom"}],"description":"Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-02-26T17:49:04.059Z","versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7792","status":"affected","versionType":"custom"}],"description":"Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.","solutions":null}},"classification":"clean","notes":"27973457af1 <10.0.17763.7558; b579ab59bc4 (2025-09-09) <10.0.17763.7792. 28 d. True by record."},{"cveId":"CVE-2023-36796","cna":"microsoft","vendor":"microsoft","product":"microsoft visual studio 2022 version 17.2","branch":"17.2.0","before":"17.2.19","after":"17.2.21","opBefore":"lt","opAfter":"lt","published":"2023-09-12T16:58:39.186Z","correctedAt":"2023-11-06T23:03:52+00:00","lagDays":55.3,"sameDay":false,"bulkCommit":false,"bulkSize":24,"states":{"first":{"commit":"c9b7883c3547","state":"PUBLISHED","dateUpdated":"2023-09-12T16:58:39.186Z","versions":[{"version":"17.2.0","lessThan":"17.2.19","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"parent":{"commit":"cab742cbbd8d","state":"PUBLISHED","dateUpdated":"2023-09-15T21:43:18.699Z","versions":[{"version":"17.2.0","lessThan":"17.2.19","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"located":{"commit":"84f035c0cf4e","state":"PUBLISHED","dateUpdated":"2023-11-06T23:00:11.846Z","versions":[{"version":"17.2.0","lessThan":"17.2.21","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-10-30T18:18:08.271Z","versions":[{"version":"17.2.0","lessThan":"17.2.21","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null}},"classification":"clean","notes":"c9b7883c354 <17.2.19; 84f035c0cf4 (2023-11-06, 24 counted rows) <17.2.21. 55 d. True by record."},{"cveId":"CVE-2026-34345","cna":"microsoft","vendor":"microsoft","product":"windows 10 version 22h2","branch":"10.0.19045.0","before":"10.0.19045.7291","after":"10.0.19045.7417","opBefore":"lt","opAfter":"lt","published":"2026-05-12T16:58:25.988Z","correctedAt":"2026-06-09T18:40:59+00:00","lagDays":28.1,"sameDay":false,"bulkCommit":true,"bulkSize":54,"states":{"first":{"commit":"9c68433765b3","state":"PUBLISHED","dateUpdated":"2026-05-12T16:58:25.988Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","solutions":null},"parent":{"commit":"82ec24acf6dd","state":"PUBLISHED","dateUpdated":"2026-06-05T16:38:34.044Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","solutions":null},"located":{"commit":"41e153aaa1d3","state":"PUBLISHED","dateUpdated":"2026-06-09T18:08:09.228Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-10T15:12:39.615Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","solutions":null}},"classification":"clean_bulk","notes":"Same event as row 5 (41e153aaa1d, 54 counted rows); description changed too."},{"cveId":"CVE-2026-45500","cna":"microsoft","vendor":"microsoft","product":"microsoft exchange server 2019 cumulative update 14","branch":"15.02.0.0","before":"15.02.1544.041","after":"15.02.1544.043","opBefore":"lt","opAfter":"lt","published":"2026-06-09T17:04:44.979Z","correctedAt":"2026-07-28T22:39:39+00:00","lagDays":49.2,"sameDay":false,"bulkCommit":false,"bulkSize":28,"states":{"first":{"commit":"5837007300b4","state":"PUBLISHED","dateUpdated":"2026-06-09T17:04:44.979Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.1544.041","status":"affected","versionType":"custom"}],"description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","solutions":null},"parent":{"commit":"f58982f85f82","state":"PUBLISHED","dateUpdated":"2026-07-15T20:09:10.742Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.1544.041","status":"affected","versionType":"custom"}],"description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","solutions":null},"located":{"commit":"0e5597791d19","state":"PUBLISHED","dateUpdated":"2026-07-28T22:18:38.317Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.1544.043","status":"affected","versionType":"custom"}],"description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-25T22:43:09.346Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.1544.043","status":"affected","versionType":"custom"}],"description":"Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.","solutions":null}},"classification":"clean","notes":"5837007300b <15.02.1544.041; 0e5597791d1 (2026-07-28) <15.02.1544.043. 49 d. Same event as row 3 and as CVE-2026-47631 in the 2026-09-05 sample. True by record."},{"cveId":"CVE-2025-14756","cna":"TPLink","vendor":"tp-link systems inc.","product":"archer mr600 v5.0","branch":"0","before":"1.0.0 0.9.1 v0001.0 Build 250930 Rel.63611n","after":"1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n","opBefore":"lt","opAfter":"lt","published":"2026-01-26T18:17:09.220Z","correctedAt":"2026-01-27T02:06:37+00:00","lagDays":0.3,"sameDay":true,"bulkCommit":false,"bulkSize":1,"states":{"first":{"commit":"adfd70d0465e","state":"PUBLISHED","dateUpdated":"2026-01-26T18:17:09.220Z","versions":[{"version":"0","lessThan":"1.0.0 0.9.1 v0001.0 Build 250930 Rel.63611n","status":"affected","versionType":"custom"}],"description":"Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.","solutions":null},"parent":{"commit":"d4dbf2b4a8c3","state":"PUBLISHED","dateUpdated":"2026-01-26T22:15:56.577Z","versions":[{"version":"0","lessThan":"1.0.0 0.9.1 v0001.0 Build 250930 Rel.63611n","status":"affected","versionType":"custom"}],"description":"Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.","solutions":null},"located":{"commit":"ff61f9cd32ea","state":"PUBLISHED","dateUpdated":"2026-01-27T01:58:11.106Z","versions":[{"version":"0","lessThan":"1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n","status":"affected","versionType":"custom"}],"description":"Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-02-26T15:04:51.548Z","versions":[{"version":"0","lessThan":"1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n","status":"affected","versionType":"custom"}],"description":"Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.","solutions":null}},"classification":"hard_fp","notes":"adfd70d0465 <'1.0.0 0.9.1 v0001.0 Build 250930 Rel.63611n'; ff61f9cd32e (+7.8 h) <'1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n'. Only the leading firmware label changed; the build token (0.9.1 v0001.0 Build 250930 Rel.63611n) is byte-identical, so the same image was relabelled within the day. The parser stops at the space and compares [1,0] against [1,1], and product_line_renumbered cannot see the tail. Candidate shape for a class (identical trailing build token); one row in the sample, not implemented."},{"cveId":"CVE-2023-6736","cna":"GitLab","vendor":"gitlab","product":"gitlab","branch":"11.3","before":"16.6.7","after":"16.7.6","opBefore":"lt","opAfter":"lt","published":"2024-02-07T22:02:30.947Z","correctedAt":"2024-02-26T20:36:35+00:00","lagDays":18.9,"sameDay":false,"bulkCommit":false,"bulkSize":2,"states":{"first":{"commit":"09962f07bd35","state":"PUBLISHED","dateUpdated":"2024-02-07T22:02:30.947Z","versions":[{"version":"11.3","lessThan":"16.6.7","status":"affected","versionType":"semver"},{"version":"16.7","lessThan":"16.7.5","status":"affected","versionType":"semver"},{"version":"16.8","lessThan":"16.8.2","status":"affected","versionType":"semver"}],"description":"An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.","solutions":"Upgrade to versions 16.8.2, 16.7.5, 16.6.7 or above."},"parent":{"commit":"b85d9097e4f2","state":"PUBLISHED","dateUpdated":"2024-02-07T22:02:30.947Z","versions":[{"version":"11.3","lessThan":"16.6.7","status":"affected","versionType":"semver"},{"version":"16.7","lessThan":"16.7.5","status":"affected","versionType":"semver"},{"version":"16.8","lessThan":"16.8.2","status":"affected","versionType":"semver"}],"description":"An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.","solutions":"Upgrade to versions 16.8.2, 16.7.5, 16.6.7 or above."},"located":{"commit":"296cbd33749a","state":"PUBLISHED","dateUpdated":"2024-02-26T20:32:17.214Z","versions":[{"version":"11.3","lessThan":"16.7.6","status":"affected","versionType":"semver"},{"version":"16.8","lessThan":"16.8.3","status":"affected","versionType":"semver"},{"version":"16.9","lessThan":"16.9.1","status":"affected","versionType":"semver"}],"description":"An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.","solutions":"Upgrade to versions 16.9.1, 16.8.3, 16.7.6 or above."},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-04-24T04:07:14.453Z","versions":[{"version":"11.3","lessThan":"16.7.6","status":"affected","versionType":"semver"},{"version":"16.8","lessThan":"16.8.3","status":"affected","versionType":"semver"},{"version":"16.9","lessThan":"16.9.1","status":"affected","versionType":"semver"}],"description":"An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.","solutions":"Upgrade to versions 16.9.1, 16.8.3, 16.7.6 or above."}},"classification":"clean","notes":"09962f07bd3 11.3 <16.6.7 (+16.7 <16.7.5, 16.8 <16.8.2); 296cbd33749 (2024-02-26) 11.3 <16.7.6 (+16.8 <16.8.3, 16.9 <16.9.1), description rewritten 'before 16.7.6'. 18.9 d. True: the 11.3 line's stated fix moved to the next release line."},{"cveId":"CVE-2023-36792","cna":"microsoft","vendor":"microsoft","product":"microsoft visual studio 2022 version 17.4","branch":"17.4.0","before":"17.4.11","after":"17.4.13","opBefore":"lt","opAfter":"lt","published":"2023-09-12T16:58:40.779Z","correctedAt":"2023-11-06T23:03:52+00:00","lagDays":55.3,"sameDay":false,"bulkCommit":false,"bulkSize":24,"states":{"first":{"commit":"c9b7883c3547","state":"PUBLISHED","dateUpdated":"2023-09-12T16:58:40.779Z","versions":[{"version":"17.4.0","lessThan":"17.4.11","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"parent":{"commit":"cab742cbbd8d","state":"PUBLISHED","dateUpdated":"2023-09-15T21:43:20.325Z","versions":[{"version":"17.4.0","lessThan":"17.4.11","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"located":{"commit":"84f035c0cf4e","state":"PUBLISHED","dateUpdated":"2023-11-06T23:00:13.544Z","versions":[{"version":"17.4.0","lessThan":"17.4.13","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-10-30T18:18:10.174Z","versions":[{"version":"17.4.0","lessThan":"17.4.13","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null}},"classification":"clean","notes":"c9b7883c354 <17.4.11; 84f035c0cf4 (2023-11-06) <17.4.13. 55 d. Same event as row 12 and as CVE-2023-36799 in the 2026-09-05 sample. True by record."},{"cveId":"CVE-2025-11578","cna":"GitHub_P","vendor":"github","product":"enterprise server","branch":"3.14","before":"3.14.19","after":"3.14.20","opBefore":"unaffected_start","opAfter":"unaffected_start","published":"2025-11-10T22:44:33.200Z","correctedAt":"2025-12-02T20:17:48+00:00","lagDays":21.9,"sameDay":false,"bulkCommit":false,"bulkSize":5,"states":{"first":{"commit":"479d36fbfab2","state":"PUBLISHED","dateUpdated":"2025-11-10T22:44:33.200Z","versions":[{"version":"3.14","lessThanOrEqual":"3.14.18","status":"affected","versionType":"semver","changes":[{"at":"3.14.19","status":"unaffected"}]},{"version":"3.15","lessThanOrEqual":"3.15.13","status":"affected","versionType":"semver","changes":[{"at":"3.15.14","status":"unaffected"}]},{"version":"3.16","lessThanOrEqual":"3.16.9","status":"affected","versionType":"semver","changes":[{"at":"3.16.10","status":"unaffected"}]},{"version":"3.17","lessThanOrEqual":"3.17.6","status":"affected","versionType":"semver","changes":[{"at":"3.17.7","status":"unaffected"}]},{"version":"3.18","lessThanOrEqual":"3.18.0","status":"affected","versionType":"semver","changes":[{"at":"3.18.1","status":"unaffected"}]}],"description":"A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user\u2019s authorized keys\u2014thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.19, 3.15.14, 3.16.10, 3.17.7 and 3.18.1. This vulnerability was reported via the GitHub Bug Bounty program","solutions":null},"parent":{"commit":"1531326e31ba","state":"PUBLISHED","dateUpdated":"2025-11-12T20:12:10.957Z","versions":[{"version":"3.14","lessThanOrEqual":"3.14.18","status":"affected","versionType":"semver","changes":[{"at":"3.14.19","status":"unaffected"}]},{"version":"3.15","lessThanOrEqual":"3.15.13","status":"affected","versionType":"semver","changes":[{"at":"3.15.14","status":"unaffected"}]},{"version":"3.16","lessThanOrEqual":"3.16.9","status":"affected","versionType":"semver","changes":[{"at":"3.16.10","status":"unaffected"}]},{"version":"3.17","lessThanOrEqual":"3.17.6","status":"affected","versionType":"semver","changes":[{"at":"3.17.7","status":"unaffected"}]},{"version":"3.18","lessThanOrEqual":"3.18.0","status":"affected","versionType":"semver","changes":[{"at":"3.18.1","status":"unaffected"}]}],"description":"A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user\u2019s authorized keys\u2014thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.19, 3.15.14, 3.16.10, 3.17.7 and 3.18.1. This vulnerability was reported via the GitHub Bug Bounty program","solutions":null},"located":{"commit":"cbaee8a97ed0","state":"PUBLISHED","dateUpdated":"2025-12-02T20:08:21.684Z","versions":[{"version":"3.14","lessThanOrEqual":"3.14.19","status":"affected","versionType":"semver","changes":[{"at":"3.14.20","status":"unaffected"}]},{"version":"3.15","lessThanOrEqual":"3.15.14","status":"affected","versionType":"semver","changes":[{"at":"3.15.15","status":"unaffected"}]},{"version":"3.16","lessThanOrEqual":"3.16.10","status":"affected","versionType":"semver","changes":[{"at":"3.16.11","status":"unaffected"}]},{"version":"3.17","lessThanOrEqual":"3.17.7","status":"affected","versionType":"semver","changes":[{"at":"3.17.8","status":"unaffected"}]},{"version":"3.18","lessThanOrEqual":"3.18.1","status":"affected","versionType":"semver","changes":[{"at":"3.18.2","status":"unaffected"}]}],"description":"A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user\u2019s authorized keys\u2014thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.20, 3.15.15, 3.16.11, 3.17.8, 3.18.2. This vulnerability was reported via the GitHub Bug Bounty program.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-12-02T20:08:21.684Z","versions":[{"version":"3.14","lessThanOrEqual":"3.14.19","status":"affected","versionType":"semver","changes":[{"at":"3.14.20","status":"unaffected"}]},{"version":"3.15","lessThanOrEqual":"3.15.14","status":"affected","versionType":"semver","changes":[{"at":"3.15.15","status":"unaffected"}]},{"version":"3.16","lessThanOrEqual":"3.16.10","status":"affected","versionType":"semver","changes":[{"at":"3.16.11","status":"unaffected"}]},{"version":"3.17","lessThanOrEqual":"3.17.7","status":"affected","versionType":"semver","changes":[{"at":"3.17.8","status":"unaffected"}]},{"version":"3.18","lessThanOrEqual":"3.18.1","status":"affected","versionType":"semver","changes":[{"at":"3.18.2","status":"unaffected"}]}],"description":"A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their own SSH key to the root user\u2019s authorized keys\u2014thereby granting themselves root SSH access to the server. To exploit this vulnerability, the attacker needed to have enterprise admin privileges. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.19, and was fixed in versions 3.14.20, 3.15.15, 3.16.11, 3.17.8, 3.18.2. This vulnerability was reported via the GitHub Bug Bounty program.","solutions":null}},"classification":"clean","notes":"479d36fbfab 3.14 <=3.14.18 changes[] unaffected 3.14.19; cbaee8a97ed (2025-12-02) <=3.14.19 changes[] 3.14.20 (every line +1). 21.9 d. True by record."},{"cveId":"CVE-2025-24036","cna":"microsoft","vendor":"microsoft","product":"microsoft autoupdate for mac","branch":"0","before":"4.77.24121924","after":"4.78.25022527","opBefore":"lt","opAfter":"lt","published":"2025-02-11T17:58:19.653Z","correctedAt":"2025-03-11T16:51:59+00:00","lagDays":28.0,"sameDay":false,"bulkCommit":false,"bulkSize":1,"states":{"first":{"commit":"9fd69b7105ca","state":"PUBLISHED","dateUpdated":"2025-02-11T17:58:19.653Z","versions":[{"version":"0","lessThan":"4.77.24121924","status":"affected","versionType":"custom"}],"description":"Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability","solutions":null},"parent":{"commit":"e80d02114ad2","state":"PUBLISHED","dateUpdated":"2025-02-21T18:42:48.906Z","versions":[{"version":"0","lessThan":"4.77.24121924","status":"affected","versionType":"custom"}],"description":"Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability","solutions":null},"located":{"commit":"96f5993e8fd6","state":"PUBLISHED","dateUpdated":"2025-03-11T16:50:20.156Z","versions":[{"version":"0","lessThan":"4.78.25022527","status":"affected","versionType":"custom"}],"description":"Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-02-26T19:09:02.689Z","versions":[{"version":"4.0.0","lessThan":"4.78.25022527","status":"affected","versionType":"custom"}],"description":"Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability","solutions":null}},"classification":"clean","notes":"9fd69b7105c <4.77.24121924; 96f5993e8fd (2025-03-11) <4.78.25022527; 93c94dec3d3 (2026-02-13) start rewritten 0 -> 4.0.0, boundary unchanged. 28 d. True by record."},{"cveId":"CVE-2026-33841","cna":"microsoft","vendor":"microsoft","product":"windows 10 version 22h2","branch":"10.0.19045.0","before":"10.0.19045.7291","after":"10.0.19045.7417","opBefore":"lt","opAfter":"lt","published":"2026-05-12T16:58:20.770Z","correctedAt":"2026-06-09T18:40:59+00:00","lagDays":28.1,"sameDay":false,"bulkCommit":true,"bulkSize":54,"states":{"first":{"commit":"9c68433765b3","state":"PUBLISHED","dateUpdated":"2026-05-12T16:58:20.770Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","solutions":null},"parent":{"commit":"82ec24acf6dd","state":"PUBLISHED","dateUpdated":"2026-06-05T16:39:53.406Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","solutions":null},"located":{"commit":"41e153aaa1d3","state":"PUBLISHED","dateUpdated":"2026-06-09T18:08:04.309Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-10T15:14:00.053Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","solutions":null}},"classification":"clean_bulk","notes":"Same event as row 5 (41e153aaa1d)."},{"cveId":"CVE-2026-40377","cna":"microsoft","vendor":"microsoft","product":"windows 10 version 22h2","branch":"10.0.19045.0","before":"10.0.19045.7291","after":"10.0.19045.7417","opBefore":"lt","opAfter":"lt","published":"2026-05-12T16:58:40.526Z","correctedAt":"2026-06-09T18:40:59+00:00","lagDays":28.1,"sameDay":false,"bulkCommit":true,"bulkSize":54,"states":{"first":{"commit":"9c68433765b3","state":"PUBLISHED","dateUpdated":"2026-05-12T16:58:40.526Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.","solutions":null},"parent":{"commit":"82ec24acf6dd","state":"PUBLISHED","dateUpdated":"2026-06-05T16:38:47.430Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7291","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.","solutions":null},"located":{"commit":"41e153aaa1d3","state":"PUBLISHED","dateUpdated":"2026-06-09T18:08:23.385Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-10T15:12:52.509Z","versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7417","status":"affected","versionType":"custom"}],"description":"Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.","solutions":null}},"classification":"clean_bulk","notes":"Same event as row 5 (41e153aaa1d)."},{"cveId":"CVE-2024-49040","cna":"microsoft","vendor":"microsoft","product":"microsoft exchange server 2019 cumulative update 14","branch":"15.02.0","before":"15.02.1544.013","after":"15.02.1544.014","opBefore":"lt","opAfter":"lt","published":"2024-11-12T17:53:54.655Z","correctedAt":"2024-11-27T18:05:55+00:00","lagDays":15.0,"sameDay":false,"bulkCommit":false,"bulkSize":3,"states":{"first":{"commit":"1a10cc19e9e8","state":"PUBLISHED","dateUpdated":"2024-11-12T17:53:54.655Z","versions":[{"version":"15.02.0","lessThan":"15.02.1544.013","status":"affected","versionType":"custom"}],"description":"Microsoft Exchange Server Spoofing Vulnerability","solutions":null},"parent":{"commit":"280e010dff41","state":"PUBLISHED","dateUpdated":"2024-11-26T20:00:56.124Z","versions":[{"version":"15.02.0","lessThan":"15.02.1544.013","status":"affected","versionType":"custom"}],"description":"Microsoft Exchange Server Spoofing Vulnerability","solutions":null},"located":{"commit":"230d27132dc3","state":"PUBLISHED","dateUpdated":"2024-11-27T18:05:13.617Z","versions":[{"version":"15.02.0","lessThan":"15.02.1544.014","status":"affected","versionType":"custom"}],"description":"Microsoft Exchange Server Spoofing Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-07-08T15:41:22.025Z","versions":[{"version":"15.02.0","lessThan":"15.02.1544.014","status":"affected","versionType":"custom"}],"description":"Microsoft Exchange Server Spoofing Vulnerability","solutions":null}},"classification":"clean","notes":"1a10cc19e9e <15.02.1544.013; 230d27132dc (2024-11-27) <15.02.1544.014. 15.0 d, revision-only, one day outside the 14 d shipped-build window. True by record (the November 2024 Exchange SU was re-released on 2024-11-27)."},{"cveId":"CVE-2026-68480","cna":"Linux","vendor":"linux","product":"linux","branch":"6.6.*","before":"6.6.149","after":"6.6.150","opBefore":"unaffected_start","opAfter":"unaffected_start","published":"2026-08-06T17:36:43.654Z","correctedAt":"2026-08-07T06:33:35+00:00","lagDays":0.5,"sameDay":true,"bulkCommit":false,"bulkSize":4,"states":{"first":{"commit":"050d3c2be52d","state":"PUBLISHED","dateUpdated":"2026-08-06T17:36:43.654Z","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9de1a49e8f1fbf7c372902573a27a97d4ab4d0af","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9c0b8105e919be5208c81d5516a194a28c58fe1e","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"95b08cdd603fe79d2e9d5212fbb13d577c835f4f","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"608c8f5dccaaf8b8d2b28c0fbdd439d144be62b0","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfe7f9993467ba431b2731437949ac1e2634e771","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61649a2d61cb0dbc673f0f232f0f0c298bf50442","status":"affected","versionType":"git"},{"version":"0","lessThan":"5.10.263","status":"affected","versionType":"semver"},{"version":"0","lessThan":"5.15.214","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.1.181","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.6.149","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.18.43","status":"affected","versionType":"semver"},{"version":"0","lessThan":"7.1.7","status":"affected","versionType":"semver"},{"version":"5.10.263","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.214","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.181","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.149","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.18.43","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.7","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","solutions":null},"parent":{"commit":"89a678d76601","state":"PUBLISHED","dateUpdated":"2026-08-06T17:36:43.654Z","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9de1a49e8f1fbf7c372902573a27a97d4ab4d0af","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9c0b8105e919be5208c81d5516a194a28c58fe1e","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"95b08cdd603fe79d2e9d5212fbb13d577c835f4f","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"608c8f5dccaaf8b8d2b28c0fbdd439d144be62b0","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfe7f9993467ba431b2731437949ac1e2634e771","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61649a2d61cb0dbc673f0f232f0f0c298bf50442","status":"affected","versionType":"git"},{"version":"0","lessThan":"5.10.263","status":"affected","versionType":"semver"},{"version":"0","lessThan":"5.15.214","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.1.181","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.6.149","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.18.43","status":"affected","versionType":"semver"},{"version":"0","lessThan":"7.1.7","status":"affected","versionType":"semver"},{"version":"5.10.263","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.214","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.181","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.149","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.18.43","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.7","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","solutions":null},"located":{"commit":"238621d97459","state":"PUBLISHED","dateUpdated":"2026-08-07T06:17:28.653Z","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"dfefa3c51370f84acb643cddf98bb42c885d0483","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"52db77a13be224e09eb4ba6b4252ae8ab9085c2c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d0208e08d64d99383e09852a76cc3038c5a4c3ab","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e262f28a69ae9e0791248f93b0173c1d1f3e1d5d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfe7f9993467ba431b2731437949ac1e2634e771","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61649a2d61cb0dbc673f0f232f0f0c298bf50442","status":"affected","versionType":"git"},{"version":"0","lessThan":"5.10.264","status":"affected","versionType":"semver"},{"version":"0","lessThan":"5.15.215","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.1.182","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.6.150","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.12.102","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.18.43","status":"affected","versionType":"semver"},{"version":"0","lessThan":"7.1.7","status":"affected","versionType":"semver"},{"version":"5.10.264","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.215","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.182","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.150","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.102","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.43","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.7","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-18T06:56:07.999Z","versions":[{"version":"3f9b7101bea1dcb63410c016ceb266f6e9f733c9","lessThan":"dfefa3c51370f84acb643cddf98bb42c885d0483","status":"affected","versionType":"git"},{"version":"b35087763a44d1eb45857f799579a351332be505","lessThan":"52db77a13be224e09eb4ba6b4252ae8ab9085c2c","status":"affected","versionType":"git"},{"version":"ac41e90d8daa8815d8bee774a1975435fbfe1ae7","lessThan":"d0208e08d64d99383e09852a76cc3038c5a4c3ab","status":"affected","versionType":"git"},{"version":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855","lessThan":"6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096","status":"affected","versionType":"git"},{"version":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855","lessThan":"e262f28a69ae9e0791248f93b0173c1d1f3e1d5d","status":"affected","versionType":"git"},{"version":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855","lessThan":"bfe7f9993467ba431b2731437949ac1e2634e771","status":"affected","versionType":"git"},{"version":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855","lessThan":"61649a2d61cb0dbc673f0f232f0f0c298bf50442","status":"affected","versionType":"git"},{"version":"fb3bd914b3ec28f5fb697ac55c4846ac2d542855","lessThan":"7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9","status":"affected","versionType":"git"},{"version":"acdc883eb61efbe01b954e782e1124790bd391a8","status":"affected","versionType":"git"},{"version":"5.10.189","lessThan":"5.10.264","status":"affected","versionType":"semver"},{"version":"5.15.125","lessThan":"5.15.215","status":"affected","versionType":"semver"},{"version":"6.1.44","lessThan":"6.1.182","status":"affected","versionType":"semver"},{"version":"6.4.9","lessThan":"6.5","status":"affected","versionType":"semver"},{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","status":"unaffected","versionType":"semver"},{"version":"5.10.264","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.215","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.182","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.150","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.102","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.43","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.7","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","solutions":null}},"classification":"clean_same_day","notes":"050d3c2be52 unaffected 6.6.149; 238621d9745 (+8 h) 6.6.150 on every stable line (+6.12.102 added). 0.5 d. True by record; now one row (the open `0 < 6.6.149` spelling collapsed into it)."},{"cveId":"CVE-2023-36794","cna":"microsoft","vendor":"microsoft","product":".net 6.0","branch":"6.0.0","before":"6.0.22","after":"6.0.24","opBefore":"lt","opAfter":"lt","published":"2023-09-12T16:58:39.719Z","correctedAt":"2023-11-06T23:03:52+00:00","lagDays":55.3,"sameDay":false,"bulkCommit":false,"bulkSize":24,"states":{"first":{"commit":"c9b7883c3547","state":"PUBLISHED","dateUpdated":"2023-09-12T16:58:39.719Z","versions":[{"version":"6.0.0","lessThan":"6.0.22","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"parent":{"commit":"cab742cbbd8d","state":"PUBLISHED","dateUpdated":"2023-09-15T21:43:19.240Z","versions":[{"version":"6.0.0","lessThan":"6.0.22","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"located":{"commit":"84f035c0cf4e","state":"PUBLISHED","dateUpdated":"2023-11-06T23:00:12.447Z","versions":[{"version":"6.0.0","lessThan":"6.0.24","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-10-30T18:18:08.911Z","versions":[{"version":"6.0.0","lessThan":"6.0.24","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null}},"classification":"clean","notes":"c9b7883c354 <6.0.22; 84f035c0cf4 (2023-11-06) <6.0.24. 55 d. Same event as rows 12/17/29. True by record."},{"cveId":"CVE-2024-47196","cna":"siemens","vendor":"siemens","product":"questa","branch":"0","before":"V2024.3","after":"V2025.2","opBefore":"lt","opAfter":"lt","published":"2024-10-08T08:40:49.065Z","correctedAt":"2025-06-17T08:22:50+00:00","lagDays":252.0,"sameDay":false,"bulkCommit":false,"bulkSize":2,"states":{"first":{"commit":"dc29f53da5db","state":"PUBLISHED","dateUpdated":"2024-10-08T08:40:49.065Z","versions":[{"version":"0","lessThan":"V2024.3","status":"affected","versionType":"custom"}],"description":"A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory.","solutions":null},"parent":{"commit":"e3b4f7b6e467","state":"PUBLISHED","dateUpdated":"2024-10-08T16:49:55.857Z","versions":[{"version":"0","lessThan":"V2024.3","status":"affected","versionType":"custom"}],"description":"A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory.","solutions":null},"located":{"commit":"bd4899f83a69","state":"PUBLISHED","dateUpdated":"2025-06-17T08:11:22.933Z","versions":[{"version":"0","lessThan":"V2025.2","status":"affected","versionType":"custom"}],"description":"A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-06-17T08:11:22.933Z","versions":[{"version":"0","lessThan":"V2025.2","status":"affected","versionType":"custom"}],"description":"A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory.","solutions":null}},"classification":"clean","notes":"dc29f53da5d <V2024.3 'All versions < V2024.3'; bd4899f83a6 (2025-06-17) <V2025.2, description rewritten. 252 d. True by record."},{"cveId":"CVE-2025-0138","cna":"palo_alto","vendor":"palo alto networks","product":"prisma cloud compute edition","branch":"1","before":"34.00.141","after":"34.01.129","opBefore":"lt","opAfter":"lt","published":"2025-05-14T18:10:16.979Z","correctedAt":"2025-06-23T15:13:51+00:00","lagDays":39.9,"sameDay":false,"bulkCommit":false,"bulkSize":1,"states":{"first":{"commit":"9af3ad9241a1","state":"PUBLISHED","dateUpdated":"2025-05-14T18:10:16.979Z","versions":[{"version":"1","lessThan":"34.00.141","status":"affected","versionType":"custom","changes":[{"at":"34.00.141","status":"unaffected"}]}],"description":"Web sessions in the web interface of Palo Alto Networks Prisma\u00ae Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.\n\nCompute in Prisma Cloud Enterprise Edition is not affected by this issue.","solutions":"This issue is fixed in Prisma Cloud Compute Edition 34.00.141, and all later Prisma Cloud Compute Edition versions."},"parent":{"commit":"1da3ed07f01e","state":"PUBLISHED","dateUpdated":"2025-05-14T19:45:01.477Z","versions":[{"version":"1","lessThan":"34.00.141","status":"affected","versionType":"custom","changes":[{"at":"34.00.141","status":"unaffected"}]}],"description":"Web sessions in the web interface of Palo Alto Networks Prisma\u00ae Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.\n\nCompute in Prisma Cloud Enterprise Edition is not affected by this issue.","solutions":"This issue is fixed in Prisma Cloud Compute Edition 34.00.141, and all later Prisma Cloud Compute Edition versions."},"located":{"commit":"a273a652a381","state":"PUBLISHED","dateUpdated":"2025-06-23T15:09:31.123Z","versions":[{"version":"1","lessThan":"34.01.129","status":"affected","versionType":"custom","changes":[{"at":"34.01.129","status":"unaffected"}]}],"description":"Web sessions in the web interface of Palo Alto Networks Prisma\u00ae Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.\n\nCompute in Prisma Cloud Enterprise Edition is not affected by this issue.","solutions":"This issue is fixed in Prisma Cloud Compute Edition 34.01.129, and all later Prisma Cloud Compute Edition versions."},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-06-23T15:09:31.123Z","versions":[{"version":"1","lessThan":"34.01.129","status":"affected","versionType":"custom","changes":[{"at":"34.01.129","status":"unaffected"}]}],"description":"Web sessions in the web interface of Palo Alto Networks Prisma\u00ae Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access.\n\nCompute in Prisma Cloud Enterprise Edition is not affected by this issue.","solutions":"This issue is fixed in Prisma Cloud Compute Edition 34.01.129, and all later Prisma Cloud Compute Edition versions."}},"classification":"clean","notes":"9af3ad9241a 1 <34.00.141 with changes[] unaffected 34.00.141; a273a652a38 (2025-06-23) <34.01.129 with changes[] 34.01.129. 39.9 d. True by record."},{"cveId":"CVE-2025-34439","cna":"VulnCheck","vendor":"world wide broadcast network","product":"avideo","branch":"0","before":"20.0","after":"20.1","opBefore":"lt","opAfter":"lt","published":"2025-12-17T19:49:38.297Z","correctedAt":"2025-12-19T15:30:59+00:00","lagDays":1.8,"sameDay":false,"bulkCommit":false,"bulkSize":9,"states":{"first":{"commit":"5f59110806d4","state":"PUBLISHED","dateUpdated":"2025-12-17T19:49:38.551Z","versions":[{"version":"0","lessThan":"20.0","status":"affected","versionType":"semver"}],"description":"AVideo versions prior to 20.0 are\u00a0vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.","solutions":null},"parent":{"commit":"24295b07ddb2","state":"PUBLISHED","dateUpdated":"2025-12-17T20:30:27.065Z","versions":[{"version":"0","lessThan":"20.0","status":"affected","versionType":"semver"}],"description":"AVideo versions prior to 20.0 are\u00a0vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.","solutions":null},"located":{"commit":"f26fe8ee3f49","state":"PUBLISHED","dateUpdated":"2025-12-19T15:26:47.317Z","versions":[{"version":"0","lessThan":"20.1","status":"affected","versionType":"semver"}],"description":"AVideo versions prior to 20.1 are\u00a0vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-06-23T16:13:31.993Z","versions":[{"version":"0","lessThan":"20.1","status":"affected","versionType":"custom"}],"description":"AVideo versions prior to 20.1 are\u00a0vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.","solutions":null}},"classification":"clean","notes":"5f59110806d <20.0 'prior to 20.0'; f26fe8ee3f4 (2025-12-19) <20.1 'prior to 20.1'. 1.8 d. Same event as CVE-2025-34434 in the 2026-09-05 sample. True by record."},{"cveId":"CVE-2026-45583","cna":"microsoft","vendor":"microsoft","product":"microsoft exchange server subscription edition rtm","branch":"15.02.0.0","before":"15.02.2562.043","after":"15.02.2562.045","opBefore":"lt","opAfter":"lt","published":"2026-06-09T17:04:47.793Z","correctedAt":"2026-07-28T22:39:39+00:00","lagDays":49.2,"sameDay":false,"bulkCommit":false,"bulkSize":28,"states":{"first":{"commit":"5837007300b4","state":"PUBLISHED","dateUpdated":"2026-06-09T17:04:47.793Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.043","status":"affected","versionType":"custom"}],"description":"Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.","solutions":null},"parent":{"commit":"f58982f85f82","state":"PUBLISHED","dateUpdated":"2026-07-15T20:09:13.413Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.043","status":"affected","versionType":"custom"}],"description":"Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.","solutions":null},"located":{"commit":"0e5597791d19","state":"PUBLISHED","dateUpdated":"2026-07-28T22:18:41.087Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.045","status":"affected","versionType":"custom"}],"description":"Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2026-08-25T22:43:12.067Z","versions":[{"version":"15.02.0.0","lessThan":"15.02.2562.045","status":"affected","versionType":"custom"}],"description":"Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.","solutions":null}},"classification":"clean","notes":"5837007300b <15.02.2562.043; 0e5597791d1 (2026-07-28) <15.02.2562.045. 49 d. Same event as row 3. True by record."},{"cveId":"CVE-2023-36793","cna":"microsoft","vendor":"microsoft","product":".net 7.0","branch":"7.0.0","before":"7.0.11","after":"7.0.13","opBefore":"lt","opAfter":"lt","published":"2023-09-12T16:58:40.256Z","correctedAt":"2023-11-06T23:03:52+00:00","lagDays":55.3,"sameDay":false,"bulkCommit":false,"bulkSize":24,"states":{"first":{"commit":"c9b7883c3547","state":"PUBLISHED","dateUpdated":"2023-09-12T16:58:40.256Z","versions":[{"version":"7.0.0","lessThan":"7.0.11","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"parent":{"commit":"cab742cbbd8d","state":"PUBLISHED","dateUpdated":"2023-09-15T21:43:19.799Z","versions":[{"version":"7.0.0","lessThan":"7.0.11","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"located":{"commit":"84f035c0cf4e","state":"PUBLISHED","dateUpdated":"2023-11-06T23:00:12.973Z","versions":[{"version":"7.0.0","lessThan":"7.0.13","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null},"head":{"commit":"HEAD","state":"PUBLISHED","dateUpdated":"2025-10-30T18:18:09.586Z","versions":[{"version":"7.0.0","lessThan":"7.0.13","status":"affected","versionType":"custom"}],"description":"Visual Studio Remote Code Execution Vulnerability","solutions":null}},"classification":"clean","notes":"c9b7883c354 <7.0.11; 84f035c0cf4 (2023-11-06) <7.0.13. 55 d. Same event as rows 12/17/24. True by record."}],"hardFalsePositives":1,"hardFalsePositiveRate":0.0333,"wilson95":[0.0059,0.1667],"note":"Seeded random sample of counted fix_version_moved rows, each read back at four commits. `classification` is filled in by a human; the summary fields are computed from it and nothing else.","classified":30,"byClass":{"clean":22,"clean_same_day":2,"clean_bulk":4,"hard_fp":1,"ambiguous":1}}
