diff --git a/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json b/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json new file mode 100644 index 00000000000..5696272531b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hv9-vfr9-4mh3", + "modified": "2024-09-05T06:31:34Z", + "published": "2024-09-05T06:31:34Z", + "aliases": [ + "CVE-2024-45288" + ], + "details": "A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45288" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:09.libnv.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-170" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json new file mode 100644 index 00000000000..cad4068f84f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94j5-29m8-f8jq", + "modified": "2024-09-05T06:31:34Z", + "published": "2024-09-05T06:31:34Z", + "aliases": [ + "CVE-2024-32668" + ], + "details": "An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller.\n\nA malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32668" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:12.bhyve.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-193" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json b/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json new file mode 100644 index 00000000000..7c3d2f463e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9qxr-9qr6-7x7w/GHSA-9qxr-9qr6-7x7w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qxr-9qr6-7x7w", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-8178" + ], + "details": "The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8178" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:11.ctl.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c77x-v69r-5vpg/GHSA-c77x-v69r-5vpg.json b/advisories/unreviewed/2024/09/GHSA-c77x-v69r-5vpg/GHSA-c77x-v69r-5vpg.json new file mode 100644 index 00000000000..536cad9809f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c77x-v69r-5vpg/GHSA-c77x-v69r-5vpg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c77x-v69r-5vpg", + "modified": "2024-09-05T06:31:33Z", + "published": "2024-09-05T06:31:33Z", + "aliases": [ + "CVE-2024-41928" + ], + "details": "Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41928" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:10.bhyve.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T04:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json new file mode 100644 index 00000000000..de39e39bfd7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgfp-qxpq-6q7w", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-42416" + ], + "details": "The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42416" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:11.ctl.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-790" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json b/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json new file mode 100644 index 00000000000..5c23983f1cc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrwf-vh6j-2grj", + "modified": "2024-09-05T06:31:33Z", + "published": "2024-09-05T06:31:33Z", + "aliases": [ + "CVE-2024-45287" + ], + "details": "A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45287" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:09.libnv.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json b/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json new file mode 100644 index 00000000000..7f1ba9b5a87 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p8gg-cp5h-w499/GHSA-p8gg-cp5h-w499.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8gg-cp5h-w499", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-45063" + ], + "details": "The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45063" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:11.ctl.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json b/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json new file mode 100644 index 00000000000..510e21d33f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r58j-7299-f87q", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-43110" + ], + "details": "The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43110" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:11.ctl.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json b/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json new file mode 100644 index 00000000000..e0e0a15cca6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v72r-7947-x8jx", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-43102" + ], + "details": "Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early.\n\nA malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43102" + }, + { + "type": "WEB", + "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:14.umtx.asc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json b/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json new file mode 100644 index 00000000000..db148f5fa9b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x54p-439w-h3mq", + "modified": "2024-09-05T06:31:35Z", + "published": "2024-09-05T06:31:35Z", + "aliases": [ + "CVE-2024-6846" + ], + "details": "The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6846" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T06:15:03Z" + } +} \ No newline at end of file