Weekly digest
Week 24, 2023 (12–18 Jun)
6 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 4 high, 83% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2023-27997Critical· 9.8CISA KEV0dayPoCA heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…
CVE-2023-35788High· 7.8PoCAn issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial…
CVE-2023-34620High· 7.5hjson stack exhaustion vulnerability
hjson stack exhaustion vulnerability
CVE-2023-35823High· 7.0An issue was discovered in the Linux kernel before 6.3.2
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
CVE-2023-3268High· 7.1An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
CVE-2023-2183Medium· 4.1Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Most-affected vendors
By CVEs published in the period.