VulnSea

Weekly digest

Week 24, 2023 (12–18 Jun)

6 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 4 high, 83% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

6
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2023-27997Critical· 9.8CISA KEV0dayPoC
3y ago

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

▾ Hadalfortinet · fortiproxyEPSS 86%via NVD
CVE-2023-35788High· 7.8PoC
3y ago

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial…

▾ MidnightEPSS 0.53%via CVEORG
CVE-2023-34620High· 7.5
3y ago

hjson stack exhaustion vulnerability

hjson stack exhaustion vulnerability

▾ Twilighthjson · org.hjson:hjsonEPSS 0.78%via OSV
CVE-2023-35823High· 7.0
3y ago

An issue was discovered in the Linux kernel before 6.3.2

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2023-3268High· 7.1
3y ago

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

▾ Twilightlinux · linux_kernelEPSS 0.48%via NVD
CVE-2023-2183Medium· 4.1
3y ago

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.0%via OSV

Most-affected vendors

By CVEs published in the period.