Weekly digest
Week 1, 2023 (2–8 Jan)
A quiet week: only 4 new CVEs against a recent average of about 9. Severity skewed high: 2 high, 50% of the total. No new KEV entries.
4
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2023-0049High· 7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
▾ Twilightneovim · neovimEPSS 0.57%via NVD
CVE-2023-22460High· 7.5go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Encoding data which cont…
▾ Twilightprotocol · go-ipld-primeEPSS 1.1%via NVD
CVE-2023-0057Medium· 6.1pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames
pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames
▾ Sunlitpyload-ng · pyload-ngEPSS 0.46%via OSV
CVE-2023-0055Medium· 5.3Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
▾ Sunlitpyload-ng · pyload-ngEPSS 0.44%via OSV
Most-affected vendors
By CVEs published in the period.