Weekly digest
Week 41, 2023 (9–15 Oct)
12 new CVEs this week, in line with the recent average. Of those, 2 critical and 3 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 12 that matter most of the 12 published.
CVE-2023-4966Critical· 9.4CISA KEVPoCSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-45853Critical· 9.8⚖ disputedMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…
CVE-2023-39325High· 7.5PoCHTTP/2 rapid reset can cause excessive work in net/http
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-5535High· 7.8⚖ disputedUse After Free in GitHub repository vim/vim prior to v9.0.2010.
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-4822Medium· 6.7grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)
A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…
CVE-2023-42787Medium· 6.5A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access …
A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access …
CVE-2023-36566Medium· 6.5Microsoft Common Data Model SDK Denial of Service Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2023-20902Medium· 5.9Harbor timing attack risk
Harbor timing attack risk
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
Defining resource name as integer may give unintended access in vantage6
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-5578Low· 3.5A vulnerability was detected in Portábilis i-Educar up to 2.7.5
A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the in…
Most-affected vendors
By CVEs published in the period.