Weekly digest
Week 18, 2023 (1–7 May)
A quiet week: only 4 new CVEs against a recent average of about 14. Severity skewed high: 4 high, 100% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
4
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2023-30861High· 7.5PoCFlask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
▾ Midnightflask · flaskEPSS 1.3%via OSV
CVE-2023-2235High· 7.8A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation. The perf_group_detach function did not check the event's siblings' attach_state before calling add_ev…
A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation. The perf_group_detach function did not check the event's siblings' attach_state before calling add_ev…
▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2023-30837High· 7.5vyper vulnerable to storage allocator overflow
vyper vulnerable to storage allocator overflow
▾ Twilightvyper · vyperEPSS 0.70%via OSV
CVE-2023-30551High· 7.5Rekor's compressed archives can result in OOM conditions
Rekor's compressed archives can result in OOM conditions
▾ Twilightsigstore · github.com/sigstore/rekorEPSS 1.1%via OSV
Most-affected vendors
By CVEs published in the period.