VulnSea

Weekly digest

Week 47, 2022 (21–27 Nov)

A heavy week: 31 new CVEs, well above the recent average of about 7. Of those, 1 critical and 6 high. No new KEV entries. tensorflow was the most-affected vendor with 25.

31
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 31 published.

CVE-2022-45908Critical· 9.8
3y ago

PaddlePaddle vulnerable to code injection via winstr

PaddlePaddle vulnerable to code injection via winstr

▾ Midnightpaddlepaddle · paddlepaddleEPSS 1.4%via OSV
CVE-2022-4141High· 7.8
3y ago

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

▾ Twilightneovim · neovimEPSS 0.45%via NVD
CVE-2022-41131High· 7.8
3y ago

OS Command Injection in Apache Airflow

OS Command Injection in Apache Airflow

▾ Twilightapache-airflow-providers-apache-hive · apache-airflow-providers-apache-hiveEPSS 1.7%via OSV
CVE-2022-45884High· 7.0
3y ago

An issue was discovered in the Linux kernel through 6.0.9

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.

▾ Twilightlinux · linux_kernelEPSS 0.33%via NVD
CVE-2022-41902High· 7.1
3y ago

Out of bounds write in grappler in Tensorflow

Out of bounds write in grappler in Tensorflow

▾ Twilighttensorflow · tensorflowEPSS 0.47%via OSV
CVE-2022-41900High· 7.1
3y ago

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

▾ Twilighttensorflow · tensorflowEPSS 0.63%via OSV
CVE-2022-41894High· 7.1
3y ago

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

▾ Twilighttensorflow · tensorflowEPSS 0.56%via OSV
CVE-2022-41880Medium· 6.8
3y ago

Tensorflow vulnerable to Out-of-Bounds Read

Tensorflow vulnerable to Out-of-Bounds Read

▾ Sunlittensorflow · tensorflowEPSS 0.41%via OSV
CVE-2022-41883Medium· 6.8
3y ago

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

▾ Sunlittensorflow · tensorflowEPSS 0.38%via OSV
CVE-2022-40954Medium· 5.5
3y ago

OS Command Injection in Apache Airflow

OS Command Injection in Apache Airflow

▾ Sunlitapache-airflow · apache-airflowEPSS 1.4%via OSV
CVE-2022-41889Medium· 5.5
3y ago

Segfault via invalid attributes in `pywrap_tfe_src.cc`

Segfault via invalid attributes in `pywrap_tfe_src.cc`

▾ Sunlittensorflow · tensorflowEPSS 0.43%via OSV
CVE-2022-4105Medium· 5.4
3y ago

Cross-site Scripting in kiwitcms

Cross-site Scripting in kiwitcms

▾ Sunlitkiwitcms · kiwitcmsEPSS 0.49%via OSV

Most-affected vendors

By CVEs published in the period.