Weekly digest
Week 12, 2023 (20–26 Mar)
A heavy week: 35 new CVEs, well above the recent average of about 9. Severity skewed high: 1 critical and 25 high, 74% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. tensorflow was the most-affected vendor with 19.
New this week, ranked by depth score
The 12 that matter most of the 35 published.
CVE-2023-1281High· 7.8PoCUse After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…
Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()…
CVE-2023-27586Critical· 9.9CairoSVG improperly processes SVG files loaded from external resources
CairoSVG improperly processes SVG files loaded from external resources
CVE-2023-25801High· 8.0TensorFlow has double free in Fractional(Max/Avg)Pool
TensorFlow has double free in Fractional(Max/Avg)Pool
CVE-2023-20035High· 7.8Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2023-20035)
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI…
CVE-2023-28117High· 7.6Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
GHSA-cpmr-mw4j-99r7High· 7.5Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
CVE-2023-27579High· 7.5TensorFlow has Floating Point Exception in TFLite in conv kernel
TensorFlow has Floating Point Exception in TFLite in conv kernel
CVE-2023-25676High· 7.5TensorFlow has null dereference on ParallelConcat with XLA
TensorFlow has null dereference on ParallelConcat with XLA
CVE-2023-25675High· 7.5TensorFlow has Segfault in Bincount with XLA
TensorFlow has Segfault in Bincount with XLA
CVE-2023-25674High· 7.5TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVE-2023-25673High· 7.5TensorFlow has Floating Point Exception in TensorListSplit with XLA
TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVE-2023-25672High· 7.5TensorFlow has Null Pointer Error in LookupTableImportV2
TensorFlow has Null Pointer Error in LookupTableImportV2
Most-affected vendors
By CVEs published in the period.