2023年12月27日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 9 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2023-47883 Vladymix Tv Browser Code Execution

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Vladymix Tv Browser Code Execution(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-6190 Ikcu University Information Management System Path Traversal

  • CVSS 9.8

新たな重大 Ikcu University Information Management System Path Traversal(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-43481 Tcl Browser Tv Web - Browsehere

  • CVSS 9.8

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-43481 CVSS 9.8

An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute...

CVE-2023-43955 CVSS 9.8

The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView.

CVE-2023-47883 CVSS 9.8

The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an...

CVE-2023-49000 CVSS 9.8

An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with t...

CVE-2023-49001 CVSS 9.8

An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the co...

CVE-2023-50255 CVSS 9.3

Deepin-Compressor is the default archive manager of Deepin Linux OS.

CVE-2023-51084 CVSS 9.8

hyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.

CVE-2023-6190 CVSS 9.8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University...

CVE-2023-6879 CVSS 9

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoratio...

Critical 公開を見る

cvelogic Threat Intelligence