VulnSea

Weekly digest

Week 27, 2024 (1–7 Jul)

A quiet week: only 10 new CVEs against a recent average of about 26. Severity skewed high: 5 high, 50% of the total. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2024-6387High· 8.1PoC
2y ago

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…

▾ Midnightopenbsd · opensshEPSS 100%via NVD
CVE-2024-39478High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-38519High· 7.8
2y ago

yt-dlp File system modification and RCE through improper file-extension sanitization

yt-dlp File system modification and RCE through improper file-extension sanitization

▾ Twilightyt-dlp · yt-dlpEPSS 0.33%via OSV
CVE-2024-5753High· 7.5
2y ago

Vanna vulnerable to SQL Injection

Vanna vulnerable to SQL Injection

▾ Twilightvanna · vannaEPSS 0.60%via OSV
CVE-2024-31223Medium· 5.3PoC
2y ago

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.1%via OSV
CVE-2024-37298High· 7.5
2y ago

Potential memory exhaustion attack due to sparse slice deserialization

Potential memory exhaustion attack due to sparse slice deserialization

▾ Twilightgorilla · github.com/gorilla/schemaEPSS 1.1%via OSV
CVE-2024-32498Medium· 6.5
2y ago

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

▾ Sunlitcinder · cinderEPSS 0.83%via OSV
CVE-2024-39689LowPoC
2y ago

Certifi removes GLOBALTRUST root certificate

Certifi removes GLOBALTRUST root certificate

▾ Twilightcertifi · certifiEPSS 1.0%via OSV
CVE-2024-39303Medium· 4.4
2y ago

Weblate vulnerable to improper sanitization of project backups

Weblate vulnerable to improper sanitization of project backups

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2024-38537None· 0.0PoC
2y ago

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.4%via OSV

Most-affected vendors

By CVEs published in the period.