2026年9月3日星期四

思科產品多個漏洞

思科產品多個漏洞

發佈日期: 2026年09月03日

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。


影響

  • 阻斷服務
  • 繞過保安限制
  • 篡改
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Cisco IOS XR

請參考供應商發佈的連結以了解受影響的版本:


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Cisco Products Multiple Vulnerabilities

Release Date: 3 Sep 2026

Multiple vulnerabilities were identified in Cisco products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Data Manipulation
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Cisco IOS XR

For affected versions, please refer to the link issued by the vendor:


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitHub Enterprise Server 多個漏洞

GitHub Enterprise Server 多個漏洞

發佈日期: 2026年09月03日 

於 GitHub Enterprise Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、遠端執行任意程式碼及彷冒。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • GitHub Enterprise Server 3.21.5 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • 更新至 GitHub Enterprise Server 3.21.5 版本

漏洞識別碼


資料來源


相關連結

GitHub Enterprise Server Multiple Vulnerabilities

GitHub Enterprise Server Multiple Vulnerabilities

Release Date: 3 Sep 2026

Multiple vulnerabilities were identified in GitHub Enterprise Server. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, remote code execution and spoofing on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • GitHub Enterprise Server versions prior to 3.21.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Update to GitHub Enterprise Server versions 3.21.5

Vulnerability Identifier


Source


Related Link

2026年9月2日星期三

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2026年09月02日

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及彷冒。

 


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 阻斷服務
  • 權限提升
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2
  • Firefox for iOS 155
  • Thunderbird 140.15
  • Thunderbird 153.2
  • Thunderbird 155

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2
  • Firefox for iOS 155
  • Thunderbird 140.15
  • Thunderbird 153.2
  • Thunderbird 155

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 2 Sep 2026

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution and spoofing on the targeted system.

 


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Denial of Service
  • Elevation of Privilege
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2
  • Firefox for iOS 155
  • Thunderbird 140.15
  • Thunderbird 153.2
  • Thunderbird 155

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2
  • Firefox for iOS 155
  • Thunderbird 140.15
  • Thunderbird 153.2
  • Thunderbird 155

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年09月02日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、彷冒、遠端執行任意程式碼及資料篡改。


影響

  • 遠端執行程式碼
  • 權限提升
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 篡改
  • 仿冒

受影響之系統或技術

  • Google Chrome 152.0.7977.75 (Linux) 之前的版本
  • Google Chrome 152.0.7977.75/.76 (Mac) 之前的版本
  • Google Chrome 152.0.7977.75/.76 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 152.0.7977.75 (Linux) 或之後版本
  • Google Chrome 152.0.7977.75/.76 (Mac) 或之後版本
  • Google Chrome 152.0.7977.75/.76 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

思科產品多個漏洞

思科產品多個漏洞 發佈日期: 2026年09月03日 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。 影響 阻斷服務 繞過保安限制 篡改 遠端執行程式碼 資料洩露 受影響之系統或技術 Cis...