2022年8月4日星期四

VMWare Products Multiple Vulnerabilities

Release Date: 4 Aug 2022

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities were identified in VMware products. An attacker could exploit some of these vulnerabilities to trigger security restriction bypass, remote code execution, cross-site scripting and elevation of privilege.


Impact

  • Security Restriction Bypass
  • Elevation of Privilege
  • Cross-Site Scripting
  • Remote Code Execution

System / Technologies affected

  • VMware Workspace ONE Access (Access)
  • VMware Workspace ONE Access Connector (Access Connector)
  • VMware Identity Manager (vIDM)
  • VMware Identity Manager Connector (vIDM Connector)
  • VMware vRealize Automation (vRA)
  • VMware Cloud Foundation
  • vRealize Suite Lifecycle Manager

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2022年8月3日星期三

Google Chrome 多個漏洞

發佈日期: 2022年08月03日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、敏感資料洩露及繞過保安限制。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 104.0.5112.79 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 104.0.5112.79 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 3 Aug 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 104.0.5112.79

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 104.0.5112.79 or later

Vulnerability Identifier


Source


Related Link

2022年8月2日星期二

Apache HTTP Server 多個漏洞

發佈日期: 2022年08月02日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache HTTP Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、跨網站指令碼及繞過保安限制。

 


影響

  • 阻斷服務
  • 資料洩露
  • 跨網站指令碼
  • 繞過保安限制

受影響之系統或技術

  • Apache HTTP Server 2.4.54 之前的版本

 

對於IBM產品

詳情請參閱以下連結:

https://www.ibm.com/support/pages/node/6595149

 

對於F5產品

詳情請參閱以下連結:

https://support.f5.com/csp/article/K21192332

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache HTTP Server 2.4.54 版本

 

對於IBM產品

詳情請參閱以下連結:

https://www.ibm.com/support/pages/node/6595149

 

對於F5產品

詳情請參閱以下連結:

https://support.f5.com/csp/article/K21192332


漏洞識別碼


資料來源


相關連結

Apache HTTP Server Multiple Vulnerabilities

Release Date: 2 Aug 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities were identified in Apache HTTP Server. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, cross-site scripting and security restriction bypass on the targeted system.

 


Impact

  • Denial of Service
  • Information Disclosure
  • Cross-Site Scripting
  • Security Restriction Bypass

System / Technologies affected

  • Apache HTTP Server versions prior to 2.4.54

 

For IBM Products

For detail, please refer to the links below:

https://www.ibm.com/support/pages/node/6595149

 

For F5 Products

For detail, please refer to the links below:

https://support.f5.com/csp/article/K21192332


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache HTTP Server versions 2.4.54

 

For IBM Products

For detail, please refer to the links below:

https://www.ibm.com/support/pages/node/6595149

 

For F5 Products

For detail, please refer to the links below:

https://support.f5.com/csp/article/K21192332


Vulnerability Identifier


Source


Related Link

Android多個漏洞

發佈日期: 2022年08月02日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、權限提升、遠端執行程式碼及阻斷服務狀況。


Android Multiple Vulnerabilities

Release Date: 2 Aug 2022

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, elevation of privilege, remote code execution and denial of service condition on the targeted system.


Mozilla Thunderbird 多個漏洞

發佈日期: 2022年08月02日

風險: 中度風險

類型: 用戶端 - 電郵用戶端

類型: 電郵用戶端

於 Mozilla Thunderbird 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 仿冒
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Thunderbird 91.12 之前版本
  • Thunderbird 102.1 之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

  • 更新至版本 91.12
  • 更新至版本 102.1

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 2 Aug 2022

RISK: Medium Risk

TYPE: Clients - Email Clients

TYPE: Email Clients

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Spoofing
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Thunderbird version prior to 91.12
  • Thunderbird version prior to 102.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to version 91.12
  • Update to version 102.1

Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2022年08月02日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

在Ubuntu Linux 核心發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。


Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 2 Aug 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernel. An attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...