Weekly digest
Week 36, 2023 (4–10 Sep)
A heavy week: 27 new CVEs, well above the recent average of about 11. Of those, 8 high. 5 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. apache-superset was the most-affected vendor with 8.
New this week, ranked by depth score
The 12 that matter most of the 27 published.
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
CVE-2023-39265Medium· 6.5PoCApache Superset Improper Input Validation vulnerability
Apache Superset Improper Input Validation vulnerability
CVE-2023-20269Medium· 5.0CISA KEVA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
CVE-2023-4622High· 7.8PoCA use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…
A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…
CVE-2023-37941Medium· 6.6PoCApache Superset Deserialization of Untrusted Data vulnerability
Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-41319High· 8.8Remote Code Execution in Custom Integration Upload
Remote Code Execution in Custom Integration Upload
CVE-2023-4244High· 7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…
CVE-2023-4781High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
CVE-2023-4752High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1858.
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2023-4750High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1857.
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
CVE-2023-4733High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1840.
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
CVE-2023-41050Medium· 6.8Information disclosure in AccessControl
Information disclosure in AccessControl
Most-affected vendors
By CVEs published in the period.