Weekly digest
Week 44, 2023 (30 Oct – 5 Nov)
A quiet week: only 7 new CVEs against a recent average of about 16. Of those, 3 high. No new KEV entries.
7
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2023-46847High· 8.6Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
▾ Twilightsquid-cache · squidEPSS 88%via NVD
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
Kubernetes privilege escalation vulnerability
▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic
quic-go vulnerable to pointer dereference that can lead to panic
▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.77%via OSV
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
Kube-proxy may unintentionally forward traffic
▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.92%via OSV
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-46250Medium· 5.1Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
▾ Sunlitpypdf · pypdfEPSS 0.24%via OSV
MAL-2023-8429NoneMalicious code in littest (crates.io)
Malicious code in littest (crates.io)
▾ Sunlitlittest · littestvia OSV
Most-affected vendors
By CVEs published in the period.