Weekly digest
Week 31, 2023 (31 Jul – 6 Aug)
10 new CVEs this week, in line with the recent average. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2023-38950High· 7.5CISA KEVPoCA path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates
CVE-2023-38200High· 7.5Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
CVE-2023-37896High· 7.5Nuclei Path Traversal vulnerability
Nuclei Path Traversal vulnerability
CVE-2023-3978Medium· 6.1Improper rendering of text nodes in golang.org/x/net/html
Improper rendering of text nodes in golang.org/x/net/html
CVE-2023-3766Medium· 5.9odoh-rs's Invalid Slice Split Results in Server Panic
odoh-rs's Invalid Slice Split Results in Server Panic
CVE-2023-38559Medium· 5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
GHSA-jm77-qphf-c4w8Lowpyca/cryptography's wheels include vulnerable OpenSSL
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-4010NoneRejected reason: Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function (usb_giveback_urb()) and the reported issue cannot be mapped to any valid codebase.
Rejected reason: Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function (usb_giveback_urb()) and the reported issue cannot be mapped to any valid codebase.
Most-affected vendors
By CVEs published in the period.