VulnSea

Weekly digest

Week 44, 2023 (30 Oct – 5 Nov)

A quiet week: only 7 new CVEs against a recent average of about 16. Of those, 3 high. No new KEV entries.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2023-46847High· 8.6
2y ago

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

▾ Twilightsquid-cache · squidEPSS 88%via NVD
CVE-2023-3676High· 8.8
2y ago

Kubernetes privilege escalation vulnerability

Kubernetes privilege escalation vulnerability

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2023-46239High· 7.5
2y ago

quic-go vulnerable to pointer dereference that can lead to panic

quic-go vulnerable to pointer dereference that can lead to panic

▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.77%via OSV
CVE-2021-25736Medium· 5.8
2y ago

Kube-proxy may unintentionally forward traffic

Kube-proxy may unintentionally forward traffic

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.92%via OSV
CVE-2023-43796Medium· 5.3
2y ago

Synapse vulnerable to leak of remote user device information

Synapse vulnerable to leak of remote user device information

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-46250Medium· 5.1
2y ago

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

▾ Sunlitpypdf · pypdfEPSS 0.24%via OSV
MAL-2023-8429None
2y ago

Malicious code in littest (crates.io)

Malicious code in littest (crates.io)

▾ Sunlitlittest · littestvia OSV

Most-affected vendors

By CVEs published in the period.