Weekly digest
Week 47, 2023 (20–26 Nov)
11 new CVEs this week, in line with the recent average. Of those, 2 critical and 2 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries.
New this week, ranked by depth score
The 11 that matter most of the 11 published.
CVE-2023-49105Critical· 9.8CISA KEVPoCAn issue was discovered in ownCloud owncloud/core before 10.13.1
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…
CVE-2023-49060Critical· 9.8An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
CVE-2023-48699High· 8.4Eval Injection in fastbots
Eval Injection in fastbots
CVE-2023-47890High· 7.6Download to arbitrary folder can lead to RCE
Download to arbitrary folder can lead to RCE
CVE-2023-47821Medium· 6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jannis Thuemmig Email Encoder plugin <= 2.1.8 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jannis Thuemmig Email Encoder plugin <= 2.1.8 versions.
CVE-2023-49061Medium· 6.1An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
CVE-2023-49092Medium· 5.9Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
CVE-2023-48700Medium· 5.7Clear Text Credentials Exposed via Onboarding Task
Clear Text Credentials Exposed via Onboarding Task
CVE-2023-48299Medium· 5.3TorchServe ZipSlip
TorchServe ZipSlip
GHSA-2c7c-3mj9-8fqhMediumDecryption of malicious PBES2 JWE objects can consume unbounded system resources
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
CVE-2023-48706Low· 3.6Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that t…
Most-affected vendors
By CVEs published in the period.