Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

Researcher Spotlight: Dr. Nestori Syynimaa’s Constant Mission Protecting Identities

“When you find the things I find, they really matter. They affect everybody’s security.” Currently streaming : The Expanse and Lost in Space on Netflix Currently listening to : Amorphis, Architects, and Killswitch Engage Currently running : 130 kilometers (or ~80 miles) a month Currently playing : Floorball (a type of floor hockey with five players and a goalkeeper)

msrc-blog
#vulnerability#ios#microsoft#git#c++
CVE-2021-4102: Chromium: CVE-2021-4102 Use after free in V8

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 96.0.1054.57 12/14/2021 96.0.4664.110

CVE-2021-4101: Chromium: CVE-2021-4101 Heap buffer overflow in Swiftshader

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 96.0.1054.57 12/14/2021 96.0.4664.110

CVE-2021-4100: Chromium: CVE-2021-4100 Object lifecycle issue in ANGLE

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 96.0.1054.57 12/14/2021 96.0.4664.110

CVE-2021-4099: Chromium: CVE-2021-4099 Use after free in Swiftshader

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 96.0.1054.57 12/14/2021 96.0.4664.110

CVE-2021-4098: Chromium: CVE-2021-4098 Insufficient data validation in Mojo

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 96.0.1054.57 12/14/2021 96.0.4664.110

CVE-2021-42320: Microsoft SharePoint Server Spoofing Vulnerability

**What privileges are required to exploit this vulnerability?** The attacker must be authenticated to the target site, with the permission to modify their Display Name within SharePoint.

CVE-2021-42309: Microsoft SharePoint Server Remote Code Execution Vulnerability

**What privileges are required to exploit this vulnerability?** The attacker must be authenticated to the target site, with the permission to use Manage Lists within SharePoint.

CVE-2021-42294: Microsoft SharePoint Server Remote Code Execution Vulnerability

**There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?** Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.