CVE-2024-10372

Source
https://cve.org/CVERecord?id=CVE-2024-10372
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10372.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10372
Published
2024-10-25T02:00:06Z
Modified
2026-08-22T03:49:48Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
chidiwilliams buzz model_loader.py download_model temp file
Details

A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to insecure temporary file. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-377"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10372.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.1.0"
                },
                {
                    "last_affected": "1.1.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/chidiwilliams/buzz

Affected ranges

Type
GIT
Repo
https://github.com/chidiwilliams/buzz
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:chidiwilliams:buzz:1.1.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.1.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.1.0
v1.*
v1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10372.json"