Weekly digest
Week 27, 2024 (1–7 Jul)
A quiet week: only 10 new CVEs against a recent average of about 26. Severity skewed high: 5 high, 50% of the total. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2024-6387High· 8.1PoCA security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by f…
CVE-2024-39478High· 7.8In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in su…
CVE-2024-38519High· 7.8yt-dlp File system modification and RCE through improper file-extension sanitization
yt-dlp File system modification and RCE through improper file-extension sanitization
CVE-2024-5753High· 7.5Vanna vulnerable to SQL Injection
Vanna vulnerable to SQL Injection
CVE-2024-31223Medium· 5.3PoCInformation Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
CVE-2024-37298High· 7.5Potential memory exhaustion attack due to sparse slice deserialization
Potential memory exhaustion attack due to sparse slice deserialization
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2024-39689LowPoCCertifi removes GLOBALTRUST root certificate
Certifi removes GLOBALTRUST root certificate
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
Weblate vulnerable to improper sanitization of project backups
CVE-2024-38537None· 0.0PoCInclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Most-affected vendors
By CVEs published in the period.