Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
// weekly digest
// weekly digest
// weekly digest
2023-09-11 00:00 UTC 2023-09-17 23:59 UTC
// total
0
// critical
0
// high
0
// medium
0
// low
0
// new kev
8
// top critical
No CRITICAL CVEs published this week.
// top high
No HIGH CVEs published this week.
// new kev additions
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.
Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.
Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.