Weekly digest
Week 41, 2024 (7–13 Oct)
13 new CVEs this week, in line with the recent average. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. open-webui was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2024-9680Critical· 9.8CISA KEV0dayPoCAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…
CVE-2024-9675High· 7.8⚖ disputedA vulnerability was found in Buildah
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…
CVE-2024-43590High· 7.8Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-7041Medium· 6.5open-webui Insecure Direct Object Reference (IDOR) vulnerability
open-webui Insecure Direct Object Reference (IDOR) vulnerability
CVE-2024-7037Medium· 6.5open-webui allows writing and deleting arbitrary files
open-webui allows writing and deleting arbitrary files
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-9621Medium· 5.3A vulnerability was found in Quarkus CXF
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP lo…
CVE-2024-25885Medium· 5.3xhtml2pdf Denial of Service via crafted string
xhtml2pdf Denial of Service via crafted string
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
CVE-2024-7038Low· 2.7open-webui allows enumeration of file names and traversal of directories by observing the error messages
open-webui allows enumeration of file names and traversal of directories by observing the error messages
Most-affected vendors
By CVEs published in the period.