VulnSea

Weekly digest

Week 40, 2024 (30 Sep – 6 Oct)

A quiet week: only 5 new CVEs against a recent average of about 15. Of those, 1 high. No new KEV entries.

5
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 5 that matter most of the 5 published.

CVE-2024-47534High· 7.5
1y ago

Incorrect delegation lookups can make go-tuf download the wrong artifact

Incorrect delegation lookups can make go-tuf download the wrong artifact

▾ Twilighttheupdateframework · github.com/theupdateframework/go-tuf/v2EPSS 0.51%via OSV
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

▾ Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-9440Medium· 5.4
1y ago

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. S…

▾ Sunlitslimselectjs · slim_selectEPSS 0.36%via NVD
CVE-2024-9341Medium· 5.4
1y ago

A flaw was found in Go

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic …

▾ Sunlitcontainers · commonEPSS 1.0%via NVD
CVE-2024-47211Medium· 5.3
1y ago

OpenStack Ironic fails to verify checksums of supplied image_source URLs

OpenStack Ironic fails to verify checksums of supplied image_source URLs

▾ Sunlitironic · ironicEPSS 0.66%via OSV

Most-affected vendors

By CVEs published in the period.