Weekly digest
Week 7, 2023 (13–19 Feb)
A busier-than-usual week with 10 new CVEs (recent average about 8). Severity skewed high: 1 critical and 6 high, 70% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-23376High· 7.8CISA KEV0dayWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-0860High· 7.5PoCImproper Restriction of Excessive Authentication Attempts in modoboa
Improper Restriction of Excessive Authentication Attempts in modoboa
CVE-2023-23947Critical· 9.1Users with any cluster secret update access may update out-of-bounds cluster secrets
Users with any cluster secret update access may update out-of-bounds cluster secrets
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
High resource usage when parsing multipart form data with many fields
CVE-2023-30798High· 7.5MultipartParser denial of service with too many fields or files
MultipartParser denial of service with too many fields or files
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
CVE-2019-17003Medium· 6.1Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
CVE-2023-25153Medium· 5.5containerd: OCI image importer memory exhaustion (CVE-2023-25153)
A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Most-affected vendors
By CVEs published in the period.