Weekly digest
Week 52, 2024 (23–29 Dec)
15 new CVEs this week, in line with the recent average. Severity skewed high: 8 high, 53% of the total. No new KEV entries. linux was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2024-56732High· 8.8HarfBuzz is a text shaping engine
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
Jinja has a sandbox breakout through malicious filenames
CVE-2024-56509High· 8.6changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
CVE-2024-12745High· 8.0Amazon Redshift Python Connector vulnerable to SQL Injection
Amazon Redshift Python Connector vulnerable to SQL Injection
CVE-2024-56631High· 7.8In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in loc…
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in loc…
CVE-2024-53170High· 7.8In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done()
In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done(). However, QUEUE_FLA…
CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method
Jinja has a sandbox breakout through indirect reference to format method
CVE-2024-39025High· 7.5Letta (previously MemGPT) incorrect access control vulnerability
Letta (previously MemGPT) incorrect access control vulnerability
CVE-2024-9774Medium· 6.5python-sql SQL injection vulnerability
python-sql SQL injection vulnerability
CVE-2024-56719Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of t…
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of t…
CVE-2024-56703Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under high next hop churn Soft lockups have been observed on a cluster of Linux-based edge routers located in a highly dynam…
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under high next hop churn Soft lockups have been observed on a cluster of Linux-based edge routers located in a highly dynam…
CVE-2024-9427Medium· 5.4Koji Cross-site Scripting
Koji Cross-site Scripting
Most-affected vendors
By CVEs published in the period.