Weekly digest
Week 15, 2023 (10–16 Apr)
10 new CVEs this week, in line with the recent average. Severity skewed high: 6 high, 60% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-2008High· 8.20dayPoCA flaw was found in the Linux kernel's udmabuf device driver, within a fault handler
A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allo…
CVE-2023-1829High· 7.8PoCA use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect…
A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect…
CVE-2023-29491High· 7.8ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…
CVE-2023-29013High· 7.5Traefik HTTP header parsing could cause a denial of service
Traefik HTTP header parsing could cause a denial of service
CVE-2023-29005High· 7.5Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
CVE-2023-2106High· 7.3Weak Password Requirements in calibreweb
Weak Password Requirements in calibreweb
CVE-2023-25392Medium· 5.9Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
CVE-2023-0645Medium· 5.3An out of bounds read exists in libjxl
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/21…
CVE-2022-2525MediumImproper Restriction of Excessive Authentication Attempts in calibreweb
Improper Restriction of Excessive Authentication Attempts in calibreweb
CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces
vitess allows users to create keyspaces that can deny access to already existing keyspaces
Most-affected vendors
By CVEs published in the period.