Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-42795

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVE
#vulnerability#apache
CVE-2023-36563

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-45129: Rooms - Synapse

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.

CVE-2023-36710

Windows Media Foundation Core Remote Code Execution Vulnerability

CVE-2023-36557

PrintHTML API Remote Code Execution Vulnerability

CVE-2023-36598

Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability

CVE-2023-36721

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-36576

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36438

Windows TCP/IP Information Disclosure Vulnerability

CVE-2023-36575

Microsoft Message Queuing Remote Code Execution Vulnerability