2024年7月19日星期五

Microsoft Edge 多個漏洞

發佈日期: 2024年07月19日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


Microsoft Edge Multiple Vulnerabilities

Release Date: 19 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


2024年7月18日星期四

思科產品多個漏洞

發佈日期: 2024年07月18日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、遠端執行程式碼、權限提升及篡改。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升
  • 篡改

受影響之系統或技術

  • Cisco AsyncOS for Secure Email Gateway 15.0、14.2 及之前的版本
  • Cisco AsyncOS for Secure Email Gateway 啟用檔案分析功能或內容過濾功能,且內容掃描工具 23.3.0.4823 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 18 Jul 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Cisco products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, remote code execution, elevation of privilege and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Cisco AsyncOS for Secure Email Gateway 15.0, 14.2 and earlier
  • Cisco AsyncOS for Secure Email Gateway with file analysis feature or content filter feature enabled, and Content scanner tools version is earlier than 23.3.0.4823

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年7月17日星期三

Google Chrome 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。

 

 

影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 126.0.6478.182 (Linux) 之前的版本
  • Google Chrome 126.0.6478.182/183 (Mac) 之前的版本
  • Google Chrome 126.0.6478.182/183 (Windows) 之前的版本
  • Google Chrome 126.0.6478.186 (Android) 之前的版本
  • Google Chrome 126.0.6478.190 (iOS) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 126.0.6478.126 (Linux) 或之後版本
  • 更新至 126.0.6478.182/183 (Mac) 或之後版本
  • 更新至 126.0.6478.182/183 (Windows) 或之後版本
  • 更新至 126.0.6478.186 (Android) 或之後版本
  • 更新至 126.0.6478.190 (iOS) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.

 


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 126.0.6478.182 (Linux)
  • Google Chrome prior to 126.0.6478.182/183 (Mac)
  • Google Chrome prior to 126.0.6478.182/183 (Windows)
  • Google Chrome prior to 126.0.6478.186 (Android)
  • Google Chrome prior to 126.0.6478.190 (iOS)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 126.0.6478.182 (Linux) or later
  • Update to version 126.0.6478.182/183 (Mac) or later
  • Update to version 126.0.6478.182/183 (Windows) or later
  • Update to version 126.0.6478.186 (Android) or later
  • Update to version 126.0.6478.190 (iOS) or later

Vulnerability Identifier


Source


Related Link

Mozilla Thunderbird 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Thunderbird 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 115.13
  • Thunderbird 128

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 115.13
  • Thunderbird 128

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

Versions prior to:

 

  • Thunderbird 115.13
  • Thunderbird 128

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 115.13
  • Thunderbird 128

Vulnerability Identifier


Source


Related Link

甲骨文產品多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

於甲骨文產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpujul2024.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

https://www.oracle.com/security-alerts/cpujul2024.html


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Servers - Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpujul2024.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

https://www.oracle.com/security-alerts/cpujul2024.html


Vulnerability Identifier


Source


Related Link

Xen 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 操作系統 - LINUX

於 Xen 發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,權限提升,敏感資料洩露及仿冒。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 運行 Xapi v1.249.x 的系統
  • Xen 4.4 以後的版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...