Weekly digest
Week 26, 2023 (26 Jun – 2 Jul)
A heavy week: 15 new CVEs, well above the recent average of about 9. Severity skewed high: 1 critical and 7 high, 53% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. hp was the most-affected vendor with 4.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2023-3390High· 7.8PoCA use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction caus…
CVE-2023-35175Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
CVE-2023-22886High· 8.8Apache Airflow JDBC Provider Improper Input Validation vulnerability
Apache Airflow JDBC Provider Improper Input Validation vulnerability
CVE-2023-35178High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.
CVE-2023-35177High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.
Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.
CVE-2023-35176High· 8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.
CVE-2023-34395High· 7.8Apache Airflow ODBC Provider Argument Injection vulnerability
Apache Airflow ODBC Provider Argument Injection vulnerability
CVE-2023-37306High· 7.5MISP 2.4.172 mishandles different certificate file extensions in server sync
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
CVE-2023-37365Medium· 6.5hnswlib Double Free vulnerability
hnswlib Double Free vulnerability
CVE-2023-2005Medium· 6.3Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…
CVE-2023-36810Medium· 6.2PyPDF2 quadratic runtime with malformed PDF missing xref marker
PyPDF2 quadratic runtime with malformed PDF missing xref marker
CVE-2023-36807Medium· 6.2PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
Most-affected vendors
By CVEs published in the period.