Weekly digest
Week 49, 2022 (5–11 Dec)
7 new CVEs this week, in line with the recent average. Of those, 2 critical and 1 high. No new KEV entries.
7
New CVEs
2
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2022-46742Critical· 9.8PaddlePaddle vulnerable to Code Injection
PaddlePaddle vulnerable to Code Injection
▾ Midnightpaddlepaddle · paddlepaddleEPSS 1.1%via OSV
CVE-2022-46741Critical· 9.1PaddlePaddle Out-of-bounds Read vulnerability
PaddlePaddle Out-of-bounds Read vulnerability
▾ Midnightpaddlepaddle · paddlepaddleEPSS 0.68%via OSV
CVE-2022-37325High· 7.5In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
▾ Twilightsangoma · asteriskEPSS 1.2%via NVD
CVE-2022-46153Medium· 6.5Traefik routes exposed with an empty TLSOption
Traefik routes exposed with an empty TLSOption
▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.51%via OSV
CVE-2022-23471Medium· 5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal
containerd CRI stream server vulnerable to host memory exhaustion via terminal
▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 1.1%via OSV
CVE-2022-4396Medium· 5.4pyRdfa3 Cross-site Scripting vulnerability
pyRdfa3 Cross-site Scripting vulnerability
▾ Sunlitpyrdfa3 · pyrdfa3EPSS 0.59%via OSV
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs
Traefik may display authorization header in the debug logs
▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 1.0%via OSV
Most-affected vendors
By CVEs published in the period.