Weekly digest
Week 37, 2023 (11–17 Sep)
12 new CVEs this week, in line with the recent average. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2023-4863High· 8.8CISA KEV0dayPoClibwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
CVE-2023-20269Medium· 5.0CISA KEVA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
New this week, ranked by depth score
The 12 that matter most of the 12 published.
CVE-2023-4863High· 8.8CISA KEV0dayPoClibwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
CVE-2023-4501Critical· 9.8User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…
CVE-2023-41267High· 7.8Apache HDFS Provider error message suggested
Apache HDFS Provider error message suggested
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability
HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-27169Medium· 6.5Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.
CVE-2023-32611Medium· 5.5A flaw was found in GLib
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
GHSA-jcr6-4frq-9gjjMediumUsers vulnerable to unaligned read of `*const *const c_char` pointer
Users vulnerable to unaligned read of `*const *const c_char` pointer
CVE-2023-4039Medium· 4.8**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…
**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
Gradio arbitrary file upload vulnerability
CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
RUSTSEC-2023-0085NoneHPACK decoder panics on invalid input
HPACK decoder panics on invalid input
Most-affected vendors
By CVEs published in the period.