βΌ CVE-2023-36569 βΌ
π Read
via "National Vulnerability Database".
Microsoft Office Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36718 βΌ
π Read
via "National Vulnerability Database".
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36790 βΌ
π Read
via "National Vulnerability Database".
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36721 βΌ
π Read
via "National Vulnerability Database".
Windows Error Reporting Service Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36780 βΌ
π Read
via "National Vulnerability Database".
Skype for Business Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-42795 βΌ
π Read
via "National Vulnerability Database".
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next.Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41771 βΌ
π Read
via "National Vulnerability Database".
Layer 2 Tunneling Protocol Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-41765 βΌ
π Read
via "National Vulnerability Database".
Layer 2 Tunneling Protocol Remote Code Execution Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36713 βΌ
π Read
via "National Vulnerability Database".
Windows Common Log File System Driver Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36579 βΌ
π Read
via "National Vulnerability Database".
Microsoft Message Queuing Denial of Service Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-36567 βΌ
π Read
via "National Vulnerability Database".
Windows Deployment Services Information Disclosure Vulnerabilityπ Read
via "National Vulnerability Database".
π1
βΌ CVE-2023-41763 βΌ
π Read
via "National Vulnerability Database".
Skype for Business Elevation of Privilege Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-5497 βΌ
π Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Tongda OA 2017 11.10. Affected is an unknown function of the file general/hr/salary/welfare_manage/delete.php. The manipulation of the argument WELFARE_ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-241650 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36703 βΌ
π Read
via "National Vulnerability Database".
DHCP Server Service Denial of Service Vulnerabilityπ Read
via "National Vulnerability Database".
βΌ CVE-2023-45648 βΌ
π Read
via "National Vulnerability Database".
Improper Input Validation vulnerability in Apache Tomcat.TomcatΓ from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.π Read
via "National Vulnerability Database".
π΄ Badbox Operation Targets Android Devices in Fraud Schemes π΄
π Read
via "Dark Reading".
Researchers believe that more than 70,000 Android devices may have been affected.π Read
via "Dark Reading".
Dark Reading
Badbox Operation Targets Android Devices in Fraud Schemes
Researchers believe that more than 70,000 Android devices may have been affected with preloaded Peachpit malware that was installed on the electronics before being sold at market.
π΄ New One-Click Exploit Is a Supply Chain Risk for Linux OSes π΄
π Read
via "Dark Reading".
An overlooked library contains a vulnerability that could enable full remote takeover simply by clicking a link.π Read
via "Dark Reading".
Dark Reading
One-Click 'Gnome' Exploit Is a Supply Chain Risk for Linux OSes
An overlooked library contains a vulnerability that could enable full remote takeover simply by clicking a link.
π΄ Microsoft Patch Tuesday Haunted by Zero-Days, Wormable Bug π΄
π Read
via "Dark Reading".
October's CVE update is here. Here's which security vulnerabilities to patch now to exorcise your Microsoft systems demons.π Read
via "Dark Reading".
Dark Reading
Microsoft Patch Tuesday Haunted by Zero-Days, Wormable Bug
October's CVE update is here. Here's which security vulnerabilities to patch now to exorcise your Microsoft systems demons.
βοΈ Patch Tuesday, October 2023 Edition βοΈ
π Read
via "Krebs on Security".
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS.π Read
via "Krebs on Security".
Krebs on Security
Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updatesβ¦
β€1
βΌ CVE-2023-26220 βΌ
π Read
via "National Vulnerability Database".
The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server: versions 11.4.11 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, and 12.0.5, versions 12.1.0 and 12.1.1.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36127 βΌ
π Read
via "National Vulnerability Database".
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.π Read
via "National Vulnerability Database".