Weekly digest
Week 25, 2023 (19–25 Jun)
10 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 4 high, 70% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. mozilla was the most-affected vendor with 3.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-3128Critical· 9.4PoCGrafana vulnerable to Authentication Bypass by Spoofing
Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2023-36664High· 7.8PoCArtifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
GHSA-hj8m-9fhf-v7jpCritical· 10.0fief-server Server-Side Template Injection vulnerability
fief-server Server-Side Template Injection vulnerability
CVE-2023-29534Critical· 9.1Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other ve…
CVE-2023-34758High· 8.1Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
CVE-2023-25747High· 7.5A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affe…
CVE-2023-35932High· 7.1jcvi vulnerable to Configuration Injection due to unsanitized user input
jcvi vulnerable to Configuration Injection due to unsanitized user input
CVE-2023-29546Medium· 6.5When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are…
CVE-2023-25499Medium· 5.7When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…
When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…
CVE-2023-25500Low· 3.5Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …
Most-affected vendors
By CVEs published in the period.