VulnSea

Weekly digest

Week 51, 2022 (19–25 Dec)

9 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 4 high, 67% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mozilla was the most-affected vendor with 4.

9
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2022-26486Critical· 9.6CISA KEV0day
3y ago

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.…

▾ Hadalmozilla · firefoxEPSS 2.3%via NVD
CVE-2022-26485High· 8.8CISA KEV0dayPoC
3y ago

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A…

▾ Abyssalmozilla · firefoxEPSS 14%via NVD
CVE-2022-44940Critical· 9.1
3y ago

Patchelf out-of-bounds read

Patchelf out-of-bounds read

▾ Midnightpatchelf · patchelfEPSS 1.1%via OSV
CVE-2022-47633High· 8.1
3y ago

kyverno verifyImages rule bypass possible with malicious proxy/registry

kyverno verifyImages rule bypass possible with malicious proxy/registry

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.96%via OSV
CVE-2022-38060High· 7.8
3y ago

OpenStack Kolla sudo privilege escalation vulnerability

OpenStack Kolla sudo privilege escalation vulnerability

▾ Twilightkolla · kollaEPSS 0.21%via OSV
CVE-2022-40897High· 7.5
3y ago

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Twilightsetuptools · setuptoolsEPSS 2.6%via OSV
CVE-2022-31746Medium· 6.5
3y ago

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

▾ Sunlitmozilla · firefox_mobileEPSS 0.41%via NVD
CVE-2022-47928Medium· 6.1
3y ago

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2022-38474Medium· 4.3
3y ago

A website that had permission to access the microphone could record audio without the audio notification being shown

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once perm…

▾ Sunlitmozilla · firefox_mobileEPSS 0.39%via NVD

Most-affected vendors

By CVEs published in the period.