思科 Webex Meetings App 資料篡改漏洞
風險: 中度風險
類型: 保安軟件及應用設備 - 保安軟件及應用設備

在思科 Webex Meetings App 發現一個漏洞,遠端攻擊者可利用這個漏洞在目標系統觸發資料篡改。
影響
- 篡改
受影響之系統或技術
- 思科 Webex Meetings App 42.7 之前版本
解決方案
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Cisco Webex Meetings App. A remote attacker could exploit this vulnerability to trigger data manipulation on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 操作系統 - 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及洩露敏感資料。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 操作系統 - 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Operating Systems - Others OS

Multiple vulnerabilities were identified in . A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 操作系統 - LINUX

於 Linux 內核發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
對於 SUSE
安裝供應商提供的修補程式:
對於 Ubuntu
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Linux Kernel. A attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
For SUSE
Apply fixes issued by the vendor:
For Ubuntu
Apply fixes issued by the vendor:
風險: 中度風險
類型: 操作系統 - Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、跨網站指令碼及繞過保安限制。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, cross-site scripting and security restriction bypass on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
RISK: High Risk
TYPE: Clients - Browsers

A vulnerability has been identified in Microsoft Edge. A remote attacker can exploit this vulnerability to trigger security restriction bypass on the targeted system.
Note:
CVE-2022-3075 is being exploited in the wild.
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
RISK: High Risk
TYPE: Clients - Browsers

A vulnerability has been identified in Google Chrome. A remote user can exploit this vulnerability to trigger security restriction bypass on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝軟件供應商提供的修補程式:
RISK: Medium Risk
TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
RISK: Medium Risk
TYPE: Clients - Email Clients

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、跨網站指令碼、遠端執行程式碼、阻斷服務狀況及繞過保安限制。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, cross-site scripting, remote code execution, denial of service condition and security restriction bypass on the targeted system.
Before installation of the software, please visit the software vendor web-site for more details.
風險: 極高度風險
類型: 操作系統 - 流動裝置及操作系統

於 Apple Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼。
注意﹕
CVE-2022-32893 及 CVE-2022-32894 漏洞正被廣泛利用。
CVE-2022-32893 漏洞允許惡意網頁內容於目標系統上以運行任意程式碼。
CVE-2022-32894 漏洞允許惡意應用程式於目標系統上以內核權限運行任意程式碼。
[更新於 2022-09-01] 蘋果公司發布了針對 CVE-2022-32893 的 iOS 12 安全修補,以及iOS 12 不受 CVE-2022-32894 的影響。更新“解決方案”及“受影響之系統或技術”部分。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Extremely High Risk
TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.
Note:
CVE-2022-32893 and CVE-2022-32894 are being exploited in the wild.
CVE-2022-32893 vulnerability can exploit the WebKit that allows crafted web content to run arbitrary code on the targeted system.
CVE-2022-32894 vulnerability can exploit the Kernel that allows malicious apps to run arbitrary code with kernel privileges on the targeted system.
[Updated on 2022-09-01] Apple Inc. released security patch for iOS 12 regarding to CVE-2022-32893, and iOS 12 is not impacted by CVE-2022-32894. "Solutions" and "System / Technologies affected" section has been updated.
Before installation of the software, please visit the vendor web-site for more details.
思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...