Weekly digest
Week 52, 2023 (25–31 Dec)
A quiet week: only 3 new CVEs against a recent average of about 16. Severity skewed high: 1 critical and 1 high, 67% of the total. No new KEV entries.
3
New CVEs
1
Critical
0
KEV additions
0
Records changed
New this week, ranked by depth score
The 3 that matter most of the 3 published.
CVE-2023-6879Critical· 9.0Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
▾ Midnightaomedia · aomediaEPSS 1.2%via NVD
CVE-2023-49568High· 7.5Maliciously crafted Git server replies can cause DoS on go-git clients
Maliciously crafted Git server replies can cause DoS on go-git clients
▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.70%via OSV
CVE-2023-5115Medium· 6.3Ansible symlink attack vulnerability
Ansible symlink attack vulnerability
▾ Sunlitansible · ansibleEPSS 1.0%via OSV
Most-affected vendors
By CVEs published in the period.