Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 11 May


Monthly Patches are out for Microsoft and Adobe. New Alerts for Adminer, Google (Chrome for Desktop), TIBCO, Phoenix Contact, Mitsubishi Electric, curl, and Linux.

Microsoft 

Microsoft Monthly Patches are out, with 75 vulnerabilities. Of these, 8 are Critical, 3 were previously disclosed, and one is already being exploited. Highest CVSSv3 score of 9.8
More info. And here. And here.

Windows Network File System and Windows LDAP contain remotely exploitable RCE vulnerabilities. CVSSv3 score of 9.8
More info. And here.

Adobe 

Adobe Monthly Patches include updates Critical vulnerabilities in Character Animator, ColdFusion, InDesign, Framemaker, and InCopy.
More info.

Adminer 

Adminer database management tool used in Industrial products contains a vulnerability that allows a remote attacker to read database credentials and steal data. CVSSv3 score of 7.5
More info.

Google 

Google has published an update for Chrome for Desktop with 13 security fixes.
More info.

Microsoft is aware and working on chromium-based Edge. More info.

Phoenix Contact 

Phoenix Contact RAD-ISM-900-EN-BD devices use third-party software with multiple vulnerabilities. CVSSv3 score of 9.1
More info.

TIBCO 

TIBCO Managed File Transfer Command Center and Internet Server contain a XXE vulnerability exploitable by remote attackers. CVSSv3 swcore of 8.6
More info.

Mitsubishi Electric 

Information disclosure and DoS vulnerabilities due to out-of-bounds read and integer overflow in OpenSSL exist in the MELSOFT GT OPC UA Client. Highest CVSSv3 score of 7.5
More info.

curl 

curl has several Medium and Low vulnerabilities that have been fixed in the latest release.
More info.

Linux 

Red Hat has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 25 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/