Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-42795

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVE
#vulnerability#apache
CVE-2023-36563

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVE-2023-36710

Windows Media Foundation Core Remote Code Execution Vulnerability

CVE-2023-36731

Win32k Elevation of Privilege Vulnerability

CVE-2023-36557

PrintHTML API Remote Code Execution Vulnerability

CVE-2023-36576

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36570

Microsoft Message Queuing Remote Code Execution Vulnerability

CVE-2023-36722

Active Directory Domain Services Information Disclosure Vulnerability

CVE-2023-36723

Windows Container Manager Service Elevation of Privilege Vulnerability