Weekly digest
Week 19, 2023 (8–14 May)
8 new CVEs this week, in line with the recent average. Severity skewed high: 4 high, 50% of the total. CISA added one CVE to the Known Exploited Vulnerabilities catalog. vyper was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2023-2610High· 7.8Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
CVE-2023-32058High· 7.5Vyper vulnerable to integer overflow in loop
Vyper vulnerable to integer overflow in loop
CVE-2023-31146High· 7.5Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
CVE-2023-25309Medium· 6.1Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.
Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.
CVE-2023-2609Medium· 5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
CVE-2023-1732Medium· 5.3Improper random reading in CIRCL
Improper random reading in CIRCL
CVE-2023-32082Low· 3.1etcd Key name can be accessed via LeaseTimeToLive API
etcd Key name can be accessed via LeaseTimeToLive API
Most-affected vendors
By CVEs published in the period.