Weekly digest
Week 31, 2024 (29 Jul – 4 Aug)
17 new CVEs this week, in line with the recent average. Of those, 7 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 5.
New this week, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2024-7340High· 8.8PoCWeave server API vulnerable to arbitrary file leak
Weave server API vulnerable to arbitrary file leak
CVE-2024-41062High· 8.8bluetooth/l2cap: sync sock recv cb and release
In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the…
CVE-2024-41671High· 8.3twisted.web has disordered HTTP pipeline response
twisted.web has disordered HTTP pipeline response
CVE-2024-42088High· 7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") rem…
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
MobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-41950High· 7.5Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
CVE-2023-33976High· 7.5TensorFlow has segfault in array_ops.upper_bound
TensorFlow has segfault in array_ops.upper_bound
CVE-2024-42132High· 7.1In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida a…
In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida a…
CVE-2024-37129Medium· 6.7Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability
Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability
Aim Stored Cross-site Scripting Vulnerability
CVE-2024-41255Medium· 5.9Filestash configured to skip TLS certificate verification when using the FTPS protocol
Filestash configured to skip TLS certificate verification when using the FTPS protocol
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
Most-affected vendors
By CVEs published in the period.