Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2021-37985: Chromium: CVE-2021-37985 Use after free in V8

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

Microsoft Security Response Center
#Microsoft Edge (Chromium-based)#Security Vulnerability#microsoft
CVE-2021-37984: Chromium: CVE-2021-37984 Heap buffer overflow in PDFium

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

CVE-2021-37983: Chromium: CVE-2021-37983 Use after free in Dev Tools

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

CVE-2021-37982: Chromium: CVE-2021-37982 Use after free in Incognito

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

CVE-2021-37981: Chromium: CVE-2021-37981 Heap buffer overflow in Skia

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

CVE-2021-42307: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

Security News: Microsoft Patch Tuesday October 2021, Autodiscover, MysterySnail, Exchange, DNS, Apache, HAProxy, VMware vCenter, Moodle

Hello everyone! This episode will be about relatively recent critical vulnerabilities. Let’s start with Microsoft Patch Tuesday for October 2021. Specifically, with the vulnerability that I expected there, but it didn’t get there. Autodiscover leak discovered by Guardicore Labs “Autodiscover, a protocol used by Microsoft Exchange for automatic configuration of clients such as Microsoft Outlook, […]

Microsoft-Signed Rootkit Targets Gaming Environments in China

FiveSys is the second publicly known rootkit since June that attackers have managed to sneak past Microsoft's driver certification process.

Microsoft, Intel, and Goldman Sachs to Lead New TCG Work Group to Tackle Supply Chain Security Challenges

Led by representatives from the three companies, the work group will create guidance that defines, implements, and upholds security standards for the entire supply chain.