Skip to content

Commit f8a35df

Browse files

File tree

5 files changed

+155
-0
lines changed

5 files changed

+155
-0
lines changed
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2275-6765-h9pg",
4+
"modified": "2026-01-24T03:30:54Z",
5+
"published": "2026-01-24T03:30:54Z",
6+
"aliases": [
7+
"CVE-2025-13952"
8+
],
9+
"details": "A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device.\n\nThe shader code contained in the web page executes a path in the compiler that held onto an out of date pointer, pointing to a freed memory object.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13952"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [
24+
"CWE-416"
25+
],
26+
"severity": null,
27+
"github_reviewed": false,
28+
"github_reviewed_at": null,
29+
"nvd_published_at": "2026-01-24T03:16:00Z"
30+
}
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-83vr-2q27-pm8v",
4+
"modified": "2026-01-24T03:30:53Z",
5+
"published": "2026-01-24T03:30:53Z",
6+
"aliases": [
7+
"CVE-2026-22586"
8+
],
9+
"details": "Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22586"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://help.salesforce.com/s/articleView?id=005299346&type=1"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [
24+
"CWE-321"
25+
],
26+
"severity": null,
27+
"github_reviewed": false,
28+
"github_reviewed_at": null,
29+
"nvd_published_at": "2026-01-24T01:15:50Z"
30+
}
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-gh85-7c93-rfh2",
4+
"modified": "2026-01-24T03:30:53Z",
5+
"published": "2026-01-24T03:30:53Z",
6+
"aliases": [
7+
"CVE-2026-22583"
8+
],
9+
"details": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22583"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://help.salesforce.com/s/articleView?id=005299346&type=1"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [
24+
"CWE-88"
25+
],
26+
"severity": null,
27+
"github_reviewed": false,
28+
"github_reviewed_at": null,
29+
"nvd_published_at": "2026-01-24T01:15:50Z"
30+
}
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-h763-98v5-2w53",
4+
"modified": "2026-01-24T03:30:53Z",
5+
"published": "2026-01-24T03:30:53Z",
6+
"aliases": [
7+
"CVE-2026-22585"
8+
],
9+
"details": "Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22585"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://help.salesforce.com/s/articleView?id=005299346&type=1"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [
24+
"CWE-327"
25+
],
26+
"severity": null,
27+
"github_reviewed": false,
28+
"github_reviewed_at": null,
29+
"nvd_published_at": "2026-01-24T01:15:50Z"
30+
}
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-vpvw-rgv5-vh74",
4+
"modified": "2026-01-24T03:30:53Z",
5+
"published": "2026-01-24T03:30:53Z",
6+
"aliases": [
7+
"CVE-2026-22582"
8+
],
9+
"details": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22582"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://help.salesforce.com/s/articleView?id=005299346&type=1"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [
24+
"CWE-88"
25+
],
26+
"severity": null,
27+
"github_reviewed": false,
28+
"github_reviewed_at": null,
29+
"nvd_published_at": "2026-01-24T01:15:49Z"
30+
}
31+
}

0 commit comments

Comments
 (0)