VulnSea

Weekly digest

Week 6, 2023 (6–12 Feb)

8 new CVEs this week, in line with the recent average. Severity skewed high: 5 high, 63% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

8
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2023-0669High· 7.2CISA KEVPoC
3y ago

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…

▾ Abyssalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
CVE-2023-25307High· 8.8
3y ago

mrpack-install vulnerable to path traversal with dependency

mrpack-install vulnerable to path traversal with dependency

▾ Twilightnothub · github.com/nothub/mrpack-installEPSS 0.60%via OSV
CVE-2023-23631High· 7.5
3y ago

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

▾ Twilightipfs · github.com/ipfs/go-unixfsnodeEPSS 0.91%via OSV
GHSA-74fp-r6jw-h4mpHigh· 7.5
3y ago

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

▾ Twilightapimachinery · k8s.io/apimachineryvia OSV
CVE-2023-23931Medium· 6.5
3y ago

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

▾ Sunlitcryptography · cryptographyEPSS 1.3%via OSV
CVE-2023-23626Medium· 5.9
3y ago

IPFS go-bitfield vulnerable to DoS via malformed size arguments

IPFS go-bitfield vulnerable to DoS via malformed size arguments

▾ Sunlitipfs · github.com/ipfs/go-bitfieldEPSS 0.91%via OSV
CVE-2023-24816Medium· 4.5
3y ago

IPython vulnerable to command injection via set_term_title

IPython vulnerable to command injection via set_term_title

▾ Sunlitipython · ipythonEPSS 1.3%via OSV

Most-affected vendors

By CVEs published in the period.