VulnSea

Weekly digest

Week 26, 2023 (26 Jun – 2 Jul)

A heavy week: 15 new CVEs, well above the recent average of about 9. Severity skewed high: 1 critical and 7 high, 53% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. hp was the most-affected vendor with 4.

15
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2023-3390High· 7.8PoC
3y ago

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…

▾ Midnightlinux · linux_kernelEPSS 0.91%via NVD
CVE-2023-35175Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

▾ Midnighthp · w1a75a_firmwareEPSS 1.4%via NVD
CVE-2023-22886High· 8.8
3y ago

Apache Airflow JDBC Provider Improper Input Validation vulnerability

Apache Airflow JDBC Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-jdbc · apache-airflow-providers-jdbcEPSS 1.5%via OSV
CVE-2023-35178High· 8.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.

▾ Twilighthp · w1a75a_firmwareEPSS 0.40%via NVD
CVE-2023-35177High· 8.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.

Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.

▾ Twilighthp · w1a75a_firmwareEPSS 0.38%via NVD
CVE-2023-35176High· 8.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.

▾ Twilighthp · w1a75a_firmwareEPSS 0.43%via NVD
CVE-2023-34395High· 7.8
3y ago

Apache Airflow ODBC Provider Argument Injection vulnerability

Apache Airflow ODBC Provider Argument Injection vulnerability

▾ Twilightapache-airflow-providers-odbc · apache-airflow-providers-odbcEPSS 0.76%via OSV
CVE-2023-37306High· 7.5
3y ago

MISP 2.4.172 mishandles different certificate file extensions in server sync

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

▾ Twilightmisp-project · mispEPSS 0.53%via NVD
CVE-2023-37365Medium· 6.5
3y ago

hnswlib Double Free vulnerability

hnswlib Double Free vulnerability

▾ Sunlithnswlib · hnswlibEPSS 0.59%via OSV
CVE-2023-2005Medium· 6.3
3y ago

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

▾ Sunlittenable · nessusEPSS 0.38%via NVD
CVE-2023-36810Medium· 6.2
3y ago

PyPDF2 quadratic runtime with malformed PDF missing xref marker

PyPDF2 quadratic runtime with malformed PDF missing xref marker

▾ Sunlitpypdf2 · pypdf2EPSS 0.63%via OSV
CVE-2023-36807Medium· 6.2
3y ago

PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects

PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects

▾ Sunlitpypdf2 · pypdf2EPSS 0.57%via OSV

Most-affected vendors

By CVEs published in the period.