Weekly digest
Week 47, 2022 (21–27 Nov)
A heavy week: 31 new CVEs, well above the recent average of about 7. Of those, 1 critical and 6 high. No new KEV entries. tensorflow was the most-affected vendor with 25.
New this week, ranked by depth score
The 12 that matter most of the 31 published.
CVE-2022-45908Critical· 9.8PaddlePaddle vulnerable to code injection via winstr
PaddlePaddle vulnerable to code injection via winstr
CVE-2022-4141High· 7.8Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
CVE-2022-41131High· 7.8OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow
CVE-2022-45884High· 7.0An issue was discovered in the Linux kernel through 6.0.9
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.
CVE-2022-41902High· 7.1Out of bounds write in grappler in Tensorflow
Out of bounds write in grappler in Tensorflow
CVE-2022-41900High· 7.1FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
CVE-2022-41894High· 7.1Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
CVE-2022-41880Medium· 6.8Tensorflow vulnerable to Out-of-Bounds Read
Tensorflow vulnerable to Out-of-Bounds Read
CVE-2022-41883Medium· 6.8Out of bounds segmentation fault due to unequal op inputs in Tensorflow
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
CVE-2022-40954Medium· 5.5OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow
CVE-2022-41889Medium· 5.5Segfault via invalid attributes in `pywrap_tfe_src.cc`
Segfault via invalid attributes in `pywrap_tfe_src.cc`
CVE-2022-4105Medium· 5.4Cross-site Scripting in kiwitcms
Cross-site Scripting in kiwitcms
Most-affected vendors
By CVEs published in the period.