Weekly digest
Week 9, 2023 (27 Feb – 5 Mar)
A heavy week: 14 new CVEs, well above the recent average of about 8. Of those, 5 high. No new KEV entries. vantage6 was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
vantage6 refresh tokens do not expire
CVE-2023-1118High· 7.8A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device
A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the…
CVE-2023-0567High· 7.7In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an applicatio…
CVE-2023-0594High· 7.3grafana: cross site scripting (CVE-2023-0594)
A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…
CVE-2023-30797High· 7.5Lemur subject to insecure random generation
Lemur subject to insecure random generation
CVE-2023-1175Medium· 6.6Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2023-1170Medium· 6.6Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
vantage6 vulnerable to Observable Response Discrepancy
CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
Most-affected vendors
By CVEs published in the period.