VulnSea

Weekly digest

Week 12, 2023 (20–26 Mar)

A heavy week: 35 new CVEs, well above the recent average of about 9. Severity skewed high: 1 critical and 25 high, 74% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. tensorflow was the most-affected vendor with 19.

35
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2023-1281High· 7.8PoC
3y ago

Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…

Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…

▾ Midnightlinux · linux_kernelEPSS 0.30%via NVD
CVE-2023-27586Critical· 9.9
3y ago

CairoSVG improperly processes SVG files loaded from external resources

CairoSVG improperly processes SVG files loaded from external resources

▾ Midnightcairosvg · cairosvgEPSS 0.72%via OSV
CVE-2023-25801High· 8.0
3y ago

TensorFlow has double free in Fractional(Max/Avg)Pool

TensorFlow has double free in Fractional(Max/Avg)Pool

▾ Twilighttensorflow · tensorflowEPSS 0.15%via OSV
CVE-2023-20035High· 7.8
3y ago

Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2023-20035)

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.22%via CSAF
CVE-2023-28117High· 7.6
3y ago

Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`

Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`

▾ Twilightsentry-sdk · sentry-sdkEPSS 0.65%via OSV
GHSA-cpmr-mw4j-99r7High· 7.5
3y ago

Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/

Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/

▾ Twilightlabel-studio · label-studiovia OSV
CVE-2023-27579High· 7.5
3y ago

TensorFlow has Floating Point Exception in TFLite in conv kernel

TensorFlow has Floating Point Exception in TFLite in conv kernel

▾ Twilighttensorflow · tensorflowEPSS 0.39%via OSV
CVE-2023-25676High· 7.5
3y ago

TensorFlow has null dereference on ParallelConcat with XLA

TensorFlow has null dereference on ParallelConcat with XLA

▾ Twilighttensorflow · tensorflowEPSS 0.39%via OSV
CVE-2023-25675High· 7.5
3y ago

TensorFlow has Segfault in Bincount with XLA

TensorFlow has Segfault in Bincount with XLA

▾ Twilighttensorflow · tensorflowEPSS 0.39%via OSV
CVE-2023-25674High· 7.5
3y ago

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

▾ Twilighttensorflow · tensorflowEPSS 0.39%via OSV
CVE-2023-25673High· 7.5
3y ago

TensorFlow has Floating Point Exception in TensorListSplit with XLA

TensorFlow has Floating Point Exception in TensorListSplit with XLA

▾ Twilighttensorflow · tensorflowEPSS 0.39%via OSV
CVE-2023-25672High· 7.5
3y ago

TensorFlow has Null Pointer Error in LookupTableImportV2

TensorFlow has Null Pointer Error in LookupTableImportV2

▾ Twilighttensorflow · tensorflowEPSS 0.36%via OSV

Most-affected vendors

By CVEs published in the period.