2024年1月11日星期四

Microsoft Edge Multiple Vulnerabilities

Release Date: 9 Jan 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge.  A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Microsoft Edge (Stable) prior to 120.0.2210.121

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 120.0.2210.121 or later

Vulnerability Identifier


Source


Related Link

2024年1月5日星期五

F5 BIG-IP 阻斷服務漏洞

發佈日期: 2024年01月05日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。

 

 

影響

  • 阻斷服務

受影響之系統或技術

BIG-IP

 

  • 16.1.0 - 16.1.3
  • 15.1.0 - 15.1.8
  • 14.1.0 - 14.1.5    
  • 13.1.0 - 13.1.5
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

https://my.f5.com/manage/s/article/K000134652

F5 BIG-IP Denial of Service Vulnerability

Release Date: 5 Jan 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

BIG-IP

 

  • 16.1.0 - 16.1.3
  • 15.1.0 - 15.1.8
  • 14.1.0 - 14.1.5    
  • 13.1.0 - 13.1.5

 

 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

https://my.f5.com/manage/s/article/K000134652

三星產品多個漏洞

發佈日期: 2024年01月05日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、權限提升、遠端執行程式碼、篡改及洩露敏感資料。

 

注意:

CVE-2023-33063, CVE-2023-33106 和 CVE-2023-33107 漏洞正在被廣泛利用。這些漏洞允許本地用戶在系統提升權限。


影響

  • 篡改
  • 遠端執行程式碼
  • 權限提升
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Android 11, 12, 13, 14

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 5 Jan 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, elevation of privilege, remote code execution, data manipulation and sensitive information disclosure on the targeted system.

 

Note:

CVE-2023-33063, CVE-2023-33106 and CVE-2023-33107 vulnerabilities are being actively exploited in the wild. These vulnerabilities allow a local user to perform privilege escalation on the system.


Impact

  • Data Manipulation
  • Remote Code Execution
  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Android 11, 12, 13, 14

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2024年1月4日星期四

Android多個漏洞

發佈日期: 2024年01月04日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及洩露敏感資料。


影響

  • 權限提升
  • 資料洩露

受影響之系統或技術

  • 2024-01-05 前的 Android 保安更新級別

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Android Multiple Vulnerabilities

Release Date: 4 Jan 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Android security patch level prior to 2024-01-05

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2024年01月04日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 120.0.6099.199 (Linux) 之前的版本
  • Google Chrome 120.0.6099.199 (Mac) 之前的版本
  • Google Chrome 120.0.6099.199/200 (Windows) 之前的版本
  • Google Chrome 120.0.6099.193 (Android) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 120.0.6099.199 (Linux) 或之後版本
  • 更新至 120.0.6099.199 (Mac) 或之後版本
  • 更新至 120.0.6099.199/200 (Windows) 或之後版本
  • 更新至 120.0.6099.193 (Android) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 4 Jan 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 120.0.6099.199 (Linux)
  • Google Chrome prior to 120.0.6099.199 (Mac)
  • Google Chrome prior to 120.0.6099.199/200 (Windows)
  • Google Chrome prior to 120.0.6099.193 (Android)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 120.0.6099.199 (Linux) or later
  • Update to version 120.0.6099.199 (Mac) or later
  • Update to version 120.0.6099.199/200 (Windows) or later
  • Update to version 120.0.6099.193 (Android) or later

Vulnerability Identifier


Source


Related Link

Debian Linux 內核多個漏洞

發佈日期: 2024年01月03日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 權限提升
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Debian bookworm 6.1.69-1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 3 Jan 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Debian bookworm versions prior to 6.1.69-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...