2023年6月6日星期二

Google Chrome Remote Code Execution Vulnerability

Release Date: 6 Jun 2023

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2023-3079 is being exploited in the wild. The vulnerability is caused due to a type confusion error in V8 JavaScript engine and can be exploited to execute arbitrary code via a crafted HTML page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 114.0.5735.106 (Linux)
  • Google Chrome prior to 114.0.5735.106 (Mac)
  • Google Chrome prior to 114.0.5735.110 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 114.0.5735.106 (Linux) or later
  • Update to version 114.0.5735.106 (Mac) or later
  • Update to version 114.0.5735.110 (Windows) or later

Vulnerability Identifier


Source


Related Link

2023年6月5日星期一

ManageEngine Password Manager Pro 多個漏洞

發佈日期: 2023年06月05日

風險: 中度風險

類型: 網站服務 - 網站服務

類型: 網站服務

於 ManageEngine Password Manager Pro 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制及洩露敏感資料。

 

影響

  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • ManageEngine Password Manager Pro 12.3 (Build-12310) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 12.3 (Build-12310) 或之後版本

漏洞識別碼

N/A


資料來源


相關連結

ManageEngine Password Manager Pro Multiple Vulnerabilities

Release Date: 5 Jun 2023

RISK: Medium Risk

TYPE: Web services - Web Servers

TYPE: Web Servers

Multiple vulnerabilities were identified in ManageEngine Password Manager Pro. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • ManageEngine Password Manager Pro prior to version 12.3 (Build-12310)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 12.3 (Build-12310) or later

Vulnerability Identifier

N/A


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2023年06月05日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、阻斷服務、遠端執行程式碼及資料篡改。

 

影響

  • 遠端執行程式碼
  • 篡改
  • 阻斷服務
  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • Microsoft Edge 114.0.1823.37 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 114.0.1823.37 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 5 Jun 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass, denial of service,  remote code execution and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation
  • Denial of Service
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • Microsoft Edge prior to 114.0.1823.37

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 114.0.1823.37 or later

Vulnerability Identifier


Source


Related Link

Splunk 產品多個漏洞

發佈日期: 2023年06月05日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Splunk 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、阻斷服務、繞過保安限制、權限提升及跨網站指令碼。

 

影響

  • 跨網站指令碼
  • 資料洩露
  • 繞過保安限制
  • 阻斷服務
  • 權限提升

受影響之系統或技術

  • Splunk App for Lookup File Editing: 4.0 及 以前版本
  • Splunk App for Stream: Streamfwd 8.1 及 以前版本
  • Splunk Cloud Platform: Splunk Web 9.0.2303 及 以前版本
  • Splunk Enterprise: Splunk Web 8.1.0 至 8.1.13
  • Splunk Enterprise: Splunk Web 8.2.0 至 8.2.10
  • Splunk Enterprise: Splunk Web 9.0.0 至 9.0.4

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Splunk Products Multiple Vulnerabilities

Release Date: 5 Jun 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Splunk Products. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, denial of service, elevation of privilege, security restriction bypass and cross-site scripting on the targeted system.


Impact

  • Cross-Site Scripting
  • Information Disclosure
  • Security Restriction Bypass
  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

  • Splunk App for Lookup File Editing: 4.0 and below
  • Splunk App for Stream: Streamfwd 8.1 and below
  • Splunk Cloud Platform: Splunk Web 9.0.2303 and below
  • Splunk Enterprise: Splunk Web 8.1.0 to 8.1.13
  • Splunk Enterprise: Splunk Web 8.2.0 to 8.2.10
  • Splunk Enterprise: Splunk Web 9.0.0 to 9.0.4
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年6月2日星期五

RedHat Linux 核心多個漏洞

發佈日期: 2023年06月02日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 RedHat Linux 核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.6 aarch64

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

RedHat Linux Kernel Multiple Vulnerabilities

Release Date: 2 Jun 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in RedHat Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.6 aarch64

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2023年06月02日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 2 Jun 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...