2024年7月19日星期五

Microsoft Edge 多個漏洞

發佈日期: 2024年07月19日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


Microsoft Edge Multiple Vulnerabilities

Release Date: 19 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


2024年7月18日星期四

思科產品多個漏洞

發佈日期: 2024年07月18日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、遠端執行程式碼、權限提升及篡改。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升
  • 篡改

受影響之系統或技術

  • Cisco AsyncOS for Secure Email Gateway 15.0、14.2 及之前的版本
  • Cisco AsyncOS for Secure Email Gateway 啟用檔案分析功能或內容過濾功能,且內容掃描工具 23.3.0.4823 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 18 Jul 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Cisco products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, remote code execution, elevation of privilege and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Cisco AsyncOS for Secure Email Gateway 15.0, 14.2 and earlier
  • Cisco AsyncOS for Secure Email Gateway with file analysis feature or content filter feature enabled, and Content scanner tools version is earlier than 23.3.0.4823

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年7月17日星期三

Google Chrome 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。

 

 

影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 126.0.6478.182 (Linux) 之前的版本
  • Google Chrome 126.0.6478.182/183 (Mac) 之前的版本
  • Google Chrome 126.0.6478.182/183 (Windows) 之前的版本
  • Google Chrome 126.0.6478.186 (Android) 之前的版本
  • Google Chrome 126.0.6478.190 (iOS) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 126.0.6478.126 (Linux) 或之後版本
  • 更新至 126.0.6478.182/183 (Mac) 或之後版本
  • 更新至 126.0.6478.182/183 (Windows) 或之後版本
  • 更新至 126.0.6478.186 (Android) 或之後版本
  • 更新至 126.0.6478.190 (iOS) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.

 


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 126.0.6478.182 (Linux)
  • Google Chrome prior to 126.0.6478.182/183 (Mac)
  • Google Chrome prior to 126.0.6478.182/183 (Windows)
  • Google Chrome prior to 126.0.6478.186 (Android)
  • Google Chrome prior to 126.0.6478.190 (iOS)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 126.0.6478.182 (Linux) or later
  • Update to version 126.0.6478.182/183 (Mac) or later
  • Update to version 126.0.6478.182/183 (Windows) or later
  • Update to version 126.0.6478.186 (Android) or later
  • Update to version 126.0.6478.190 (iOS) or later

Vulnerability Identifier


Source


Related Link

Mozilla Thunderbird 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Thunderbird 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 115.13
  • Thunderbird 128

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 115.13
  • Thunderbird 128

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

Versions prior to:

 

  • Thunderbird 115.13
  • Thunderbird 128

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 115.13
  • Thunderbird 128

Vulnerability Identifier


Source


Related Link

甲骨文產品多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

於甲骨文產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpujul2024.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

https://www.oracle.com/security-alerts/cpujul2024.html


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Servers - Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpujul2024.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

https://www.oracle.com/security-alerts/cpujul2024.html


Vulnerability Identifier


Source


Related Link

Xen 多個漏洞

發佈日期: 2024年07月17日

風險: 中度風險

類型: 操作系統 - LINUX

於 Xen 發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,權限提升,敏感資料洩露及仿冒。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 運行 Xapi v1.249.x 的系統
  • Xen 4.4 以後的版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Xen Multiple Vulnerabilities

Release Date: 17 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities have been identified in Xen. An attacker can exploit these vulnerabilities to trigger denial of service condition, elevation of privilege, sensitive information disclosure and spoofing on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • All Xen Systems running Xapi v1.249.x
  • Xen versions 4.4 and newer

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link

2024年7月16日星期二

Citrix 產品多個漏洞

發佈日期: 2024年07月15日

風險: 中度風險

類型: 操作系統 - Network

於 Citrix 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、權限提升、阻斷服務狀況及遠端執行任意程式碼。

 


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • NetScaler Console 14.1 中  14.1-25.56 之前的版本
  • NetScaler Console 13.1  中 13.1-53.24 之前的版本
  • NetScaler Console 13.0 中 13.0-92.31 之前的版本
  • NetScaler SDX (SVM) 14.1 中14.1-25.53 之前的版本
  • NetScaler SDX (SVM) 13.1 中 13.1-53.17 之前的版本
  • NetScaler SDX (SVM) 13.0  中  13.0-92.31 之前的版本
  • NetScaler Agent 14.1 中14.1-25.53之前的版本
  • NetScaler Agent 13.1 中 13.1-53.22 之前的版本
  • NetScaler Agent 13.0 中 13.0-92.31 之前的版本
  • NetScaler ADC and NetScaler Gateway 14.1 中  14.1-25.56 之前的版本
  • NetScaler ADC and NetScaler Gateway 13.1 中 13.1-53.24 之前的版本
  • NetScaler ADC and NetScaler Gateway 13.0 中 13.0-92.31 之前的版本
  • NetScaler ADC 13.1-FIPS 13.1-37.190 之前的版本
  • NetScaler ADC 12.1-FIPS 12.1-55.309 之前的版本
  • NetScaler ADC 12.1-NDcPP 12.1-55.309 之前的版本
  • Citrix Virtual Apps and Desktops 2402 之前的版本
  • Citrix Virtual Apps and Desktops 1912 LTSR CU9 之前的版本
  • Citrix Virtual Apps and Desktops 2203 LTSR CU5 之前的版本

注意:已終止生命週期 (EOL)的NetScaler ADC and NetScaler Gateway 版本 12.1,都會受今次漏洞影響。


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Citrix Products Multiple Vulnerabilities

Release Date: 15 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, elevation of privilege, denial of service condition and remote code execution on the targeted system.

 


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • NetScaler Console 14.1 before 14.1-25.56
  • NetScaler Console 13.1 before 13.1-53.24
  • NetScaler Console 13.0 before 13.0-92.31
  • NetScaler SDX (SVM) 14.1 before 14.1-25.53
  • NetScaler SDX (SVM) 13.1 before 13.1-53.17
  • NetScaler SDX (SVM) 13.0 before 13.0-92.31
  • NetScaler Agent 14.1 before 14.1-25.53
  • NetScaler Agent 13.1 before 13.1-53.22
  • NetScaler Agent 13.0 before 13.0-92.31
  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-25.56
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-53.24
  • NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.31
  • NetScaler ADC 13.1-FIPS before 13.1-37.190
  • NetScaler ADC 12.1-FIPS before 12.1-55.309
  • NetScaler ADC 12.1-NDcPP before 12.1-55.309
  • Citrix Virtual Apps and Desktops versions before 2402 
  • Citrix Virtual Apps and Desktops 1912 LTSR before CU9
  • Citrix Virtual Apps and Desktops 2203 LTSR before CU5 

Note: NetScaler ADC and NetScaler Gateway version 12.1 is now End Of Life (EOL) and is vulnerable.


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Exim 繞過保安限制漏洞

發佈日期: 2024年07月15日

風險: 高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於 Exim 發現漏洞,遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。

 

注意:

CVE-2024-39929的概念驗證碼已被公開。


影響

  • 繞過保安限制

受影響之系統或技術

  • Exim 4.98 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 更新至版本 4.98

漏洞識別碼


資料來源


相關連結

Exim Security Restriction Bypass Vulnerability

Release Date: 15 Jul 2024

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Exim, a remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.

 

Note:

Proof of concept exploit for CVE-2024-39929 exists on the internet.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Exim versions prior to 4.98

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to version 4.98

Vulnerability Identifier


Source


Related Link

Netgear 產品多個漏洞

發佈日期: 2024年07月15日

風險: 中度風險

類型: 操作系統 - Network

於 Netgear 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼及繞過保安限制。

 


影響

  • 跨網站指令碼
  • 繞過保安限制

受影響之系統或技術

  • NETGEAR XR1000 1.0.0.72 之前的版本
  • NETGEAR CAX30 2.2.2.2 之前的版本

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼

Note: No CVE information is available for this vulnerability


資料來源


相關連結

Netgear Products Multiple Vulnerabilities

Release Date: 15 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Netgear Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting and security restriction bypass on the targeted system.

 


Impact

  • Cross-Site Scripting
  • Security Restriction Bypass

System / Technologies affected

  • NETGEAR XR1000 version prior to 1.0.0.72
  • NETGEAR CAX30 version prior to 2.2.2.2

 


Solutions

Before installation of the software, please visit the vendor's web-site for more details.

 


Vulnerability Identifier

Note: No CVE information is available for this vulnerability


Source


Related Link

Palo Alto Cortex XDR Agent 繞過保安限制漏洞

發佈日期: 2024年07月15日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在 Palo Alto Cortex XDR Agent 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Cortex XDR Agent 8.2.2 之前的版本
  • Cortex XDR Agent 7.9.102-CE 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto Cortex XDR Agent Security Restriction Bypass Vulnerability

Release Date: 15 Jul 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability has been identified in Palo Alto Cortex XDR Agent. A remote attacker can exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Cortex XDR Agent 8.2 versions prior to 8.2.2
  • Cortex XDR Agent 7.9-CE versions prior to 7.9.102-CE

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2024年7月12日星期五

Juniper Junos OS 多個漏洞

發佈日期: 2024年07月12日

風險: 中度風險

類型: 操作系統 - Network

於 Juniper Junos OS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、遠端執行程式碼、權限提升及繞過保安限制。


影響

  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • Junos OS
  • Junos OS Evolved

詳情請參閱以下連結﹕

https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

請參閱 2024-07 安全公告


漏洞識別碼


資料來源


相關連結

Juniper Junos OS Multiple Vulnerabilities

Release Date: 12 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Juniper Junos OS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, remote code execution, elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • Junos OS
  • Junos OS Evolved

Please refer to the link below for detail:

https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Please refer to 2024-07 Security Bulletin.


Vulnerability Identifier


Source


Related Link

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...