2025年12月2日星期二

Android 多個漏洞

Android 多個漏洞

發佈日期: 2025年12月02日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、阻斷服務狀況及權限提升。

 

注意:

CVE-2025-48633 和 CVE-2025-48572 正被利用作零星攻擊。有跡象顯示這些漏洞可能正受到有限且有針對性的利用。因此,風險等級被評為中度風險。


Android Multiple Vulnerabilities

Android Multiple Vulnerabilities

Release Date: 2 Dec 2025

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, denial of service condition and elevation of privilege on the targeted system.

 

Note:

CVE-2025-48633 and CVE-2025-48572 are being scattered exploited. There are indications that the vulnerabilities may be under limited, targeted exploitation. Hence, the risk level is rated as Medium Risk.


三星產品多個漏洞

三星產品多個漏洞

發佈日期: 2025年12月02日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、敏感資料洩露及遠端執行程式碼。

 

注意:

CVE-2025-48633 正被利用作零星攻擊。有跡象顯示這個漏洞可能正受到有限且有針對性的利用。因此,風險等級被評為中度風險。

 


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • 運行 Android 13, 14, 15, 16 的三星產品
  • Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2200, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-53965/

https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-54326/


解決方案

在安裝軟件之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝軟件供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Samsung Products Multiple Vulnerabilities

Release Date: 2 Dec 2025

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege,  sensitive information disclosure and remote code execution on the targeted system.

 

Note:

CVE-2025-48633 is being scattered exploited. This is indication that the vulnerability may be under limited, targeted exploitation. Hence, the risk level is rated as Medium Risk.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • Samsung mobile devices running Android 13, 14, 15, 16
  • Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2200, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-53965/

https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-54326/


Solutions

Before installation of the software, please visit the vendor website for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2025年12月1日星期一

SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞

發佈日期: 2025年12月01日

風險: 中度風險

類型: 操作系統 - LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、及資料篡改。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務
  • 權限提升
  • 篡改

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP6
  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Real Time 15 SP6
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP6
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Real Time Module 15-SP6
  • openSUSE Leap 15.3
  • openSUSE Leap 15.6

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 1 Dec 2025

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Denial of Service
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP6
  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Real Time 15 SP6
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP6
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Real Time Module 15-SP6
  • openSUSE Leap 15.3
  • openSUSE Leap 15.6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...