ALAS-2023-1872
ALAS-2023-1872: squid (critical)
CVEs:CVE-2023-46847
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| squid | affected | Amazon | squid | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild — see the Exploited section.
ALAS-2023-1872: squid (critical)
CVEs:CVE-2023-46847
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| squid | affected | Amazon | squid | — |
ALAS-2023-1856: ImageMagick (medium)
CVEs:CVE-2023-5341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ImageMagick | affected | Amazon | ImageMagick | — |
ALAS-2023-1857: cups (medium)
CVEs:CVE-2023-4504
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cups | affected | Amazon | cups | — |
ALAS-2023-1858: nss-softokn (medium)
CVEs:CVE-2023-4421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nss-softokn | affected | Amazon | nss-softokn | — |
ALAS-2023-1859: libX11 (medium)
CVEs:CVE-2023-43785CVE-2023-43787
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libX11 | affected | Amazon | libX11 | — |
ALAS-2023-1860: exim (important)
CVEs:CVE-2023-42116CVE-2023-42117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exim | affected | Amazon | exim | — |
ALAS-2023-1861: tomcat8 (important)
CVEs:CVE-2023-24998CVE-2023-41080
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat8 | affected | Amazon | tomcat8 | — |
ALAS-2023-1862: cacti (important)
CVEs:CVE-2023-39362CVE-2023-39364
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cacti | affected | Amazon | cacti | — |
ALAS-2023-1863: apache-ivy (important)
CVEs:CVE-2022-46751
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-ivy | affected | Amazon | apache-ivy | — |
ALAS-2023-1864: java-1.8.0-openjdk (important)
CVEs:CVE-2022-40433
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.8.0-openjdk | affected | Amazon | java-1.8.0-openjdk | — |
ALAS-2023-1865: mutt (medium)
CVEs:CVE-2022-1328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mutt | affected | Amazon | mutt | — |
ALAS-2023-1866: amazon-ssm-agent (important)
CVEs:CVE-2021-43565CVE-2022-41723CVE-2023-24538CVE-2023-24540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| amazon-ssm-agent | affected | Amazon | amazon-ssm-agent | — |
ALAS-2023-1867: ghostscript (medium)
CVEs:CVE-2020-16294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ghostscript | affected | Amazon | ghostscript | — |
CVE-2023-5528
CVEs:CVE-2023-5528
ALAS-2023-1868: tomcat8 (important)
CVEs:CVE-2023-42795CVE-2023-44487CVE-2023-45648
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat8 | affected | Amazon | tomcat8 | — |
ALAS-2023-1869: nghttp2 (important)
CVEs:CVE-2023-44487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nghttp2 | affected | Amazon | nghttp2 | — |
ALAS-2023-1870: nginx (important)
CVEs:CVE-2023-44487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nginx | affected | Amazon | nginx | — |
ALAS-2023-1871: golang (important)
CVEs:CVE-2023-39323CVE-2023-39325CVE-2023-44487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Amazon | golang | — |
CVE-2023-44487 - HTTP/2 Rapid Reset Attack
CVEs:CVE-2023-44487
Issue with Amazon WorkSpaces Windows Client Version 5.9 and 5.10
ALAS-2023-1836: mutt (medium)
CVEs:CVE-2023-4874CVE-2023-4875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mutt | affected | Amazon | mutt | — |
ALAS-2023-1837: vim (important)
CVEs:CVE-2023-4733CVE-2023-4750CVE-2023-4752
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| vim | affected | Amazon | vim | — |
ALAS-2023-1838: kernel (important)
CVEs:CVE-2023-3772CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-4207CVE-2023-4244CVE-2023-42753CVE-2023-42755CVE-2023-45871CVE-2023-4622CVE-2023-4623CVE-2023-4921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2023-1839: libtiff (medium)
CVEs:CVE-2023-41175
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libtiff | affected | Amazon | libtiff | — |
ALAS-2023-1840: axis (important)
CVEs:CVE-2023-40743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| axis | affected | Amazon | axis | — |
ALAS-2023-1841: libxml2 (medium)
CVEs:CVE-2023-39615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libxml2 | affected | Amazon | libxml2 | — |
ALAS-2023-1842: cacti (important)
CVEs:CVE-2023-39357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cacti | affected | Amazon | cacti | — |
ALAS-2023-1843: openssl (medium)
CVEs:CVE-2023-3446CVE-2023-3817
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openssl | affected | Amazon | openssl | — |
ALAS-2023-1844: ImageMagick (medium)
CVEs:CVE-2023-34151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ImageMagick | affected | Amazon | ImageMagick | — |
ALAS-2023-1845: bind (important)
CVEs:CVE-2023-3341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bind | affected | Amazon | bind | — |
ALAS-2023-1846: libtiff (medium)
CVEs:CVE-2023-3316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libtiff | affected | Amazon | libtiff | — |
ALAS-2023-1847: libtiff (medium)
CVEs:CVE-2023-30774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libtiff | affected | Amazon | libtiff | — |
ALAS-2023-1848: golang (important)
CVEs:CVE-2022-41717CVE-2022-41722CVE-2022-41724CVE-2022-41725CVE-2023-24532CVE-2023-24537CVE-2023-24538CVE-2023-24540CVE-2023-29400CVE-2023-29403CVE-2023-29404CVE-2023-29405CVE-2023-29406CVE-2023-29409CVE-2023-39319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Amazon | golang | — |
ALAS-2023-1849: containerd (important)
CVEs:CVE-2022-41723CVE-2023-29406CVE-2023-29409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | Amazon | containerd | — |
ALAS-2023-1850: poppler (medium)
CVEs:CVE-2020-36023CVE-2020-36024CVE-2022-38349
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| poppler | affected | Amazon | poppler | — |
ALAS-2023-1851: gsl (medium)
CVEs:CVE-2020-35357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gsl | affected | Amazon | gsl | — |
ALAS-2023-1852: poppler (medium)
CVEs:CVE-2020-23804
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| poppler | affected | Amazon | poppler | — |
ALAS-2023-1853: ghostscript (medium)
CVEs:CVE-2020-21710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ghostscript | affected | Amazon | ghostscript | — |
ALAS-2023-1854: ghostscript (medium)
CVEs:CVE-2020-16305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ghostscript | affected | Amazon | ghostscript | — |
ALAS-2023-1855: libtiff (medium)
CVEs:CVE-2016-5321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libtiff | affected | Amazon | libtiff | — |
Reported TorchServe Issue (CVE-2023-43654)
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.