By michele654 on Wednesday, 08 January 2025
Category: Vulnerabilities

New Vulnerabilities Wednesday 08 January


Monthly Patches are out for Google Pixel. New Alerts for Google Chrome, ABB, Fortra, Nedap Librix, Mozilla, Splunk, and Linux.

Google 

Google has updated Chrome for Desktop to fix 4 security vulnerabilities.
More info.

Google has published Monthly Patches for Pixel, which includes Android and Qualcomm patches.
More info.

ABB 

Multiple vulnerabilities exist in the AC500. Highest CVSSv3 score of 8.8.
More info.

ASPECT-Enterprise, NEXUS, and MATRIX series contain 25 vulnerabilities. Highest CVSSv3 score of 10.
No patches or bulletin from ABB yet.
More info.

Fortra 

PowerHA does not set the secure attribute on authorization tokens or session cookies. A remote attacker can get the cookie values sent to an insecure link and obtain the cookie value by snooping the traffic. CVSSv3 score of 4.3
More info.

Nedap Librix 

Ecoreader contains a missing authentication vulnerability allowing a remote attacker to execute code. CVSSv4 score of 9.3. No patches.
More info.

Mozilla 

Mozilla has published updates for Firefox and Firefox ESR.
More info.

Splunk 

Splunk has published updates for third-party software in Add-on for JBoss.
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated the kernel, kernel-rt, and kpatch. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details