VulnSea

Weekly digest

Week 37, 2023 (11–17 Sep)

12 new CVEs this week, in line with the recent average. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

12
New CVEs
1
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 12 published.

CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
CVE-2023-4501Critical· 9.8
3y ago

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

▾ Midnightmicrofocus · cobol_serverEPSS 0.75%via NVD
CVE-2023-41267High· 7.8
3y ago

Apache HDFS Provider error message suggested

Apache HDFS Provider error message suggested

▾ Twilightapache-airflow-providers-apache-hdfs · apache-airflow-providers-apache-hdfsEPSS 0.60%via OSV
CVE-2023-4785High· 7.5
3y ago

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

▾ Twilightgrpc · grpcEPSS 0.77%via OSV
CVE-2023-4680Medium· 6.8
3y ago

HashiCorp Vault Improper Input Validation vulnerability

HashiCorp Vault Improper Input Validation vulnerability

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-27169Medium· 6.5
3y ago

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

▾ Sunlitxpand-it · write-back_managerEPSS 0.32%via NVD
CVE-2023-32611Medium· 5.5
3y ago

A flaw was found in GLib

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

▾ Sunlitgnome · glibEPSS 0.38%via NVD
GHSA-jcr6-4frq-9gjjMedium
3y ago

Users vulnerable to unaligned read of `*const *const c_char` pointer

Users vulnerable to unaligned read of `*const *const c_char` pointer

▾ Sunlitusers · usersvia OSV
CVE-2023-4039Medium· 4.8
3y ago

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…

▾ Sunlitgnu · gccEPSS 0.76%via NVD
CVE-2023-41626Medium· 4.8
3y ago

Gradio arbitrary file upload vulnerability

Gradio arbitrary file upload vulnerability

▾ Sunlitgradio · gradioEPSS 0.41%via OSV
CVE-2023-41880Low· 2.2
3y ago

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

▾ Sunlitwasmtime · wasmtimeEPSS 0.67%via OSV
RUSTSEC-2023-0085None
3y ago

HPACK decoder panics on invalid input

HPACK decoder panics on invalid input

▾ Sunlithpack · hpackvia OSV

Most-affected vendors

By CVEs published in the period.