CVE-2024-50338 GitHub: CVE-2024-50338 Malformed URL allows information disclosure through git-credential-manager

Posted on Tuesday January 14, 2025

Information published.

 

CVE-2021-45985 Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read

Posted on Tuesday January 14, 2025

The following updates have been made: 1) Added Windows Software to the Security Updates table. Microsoft recommends updating to the latest version of their Windows operating system. 2) Added an FAQ to describe further actions customers need to take to be protected from this vulnerability.

 

CVE-2025-21385 Microsoft Purview Information Disclosure Vulnerability

Posted on Thursday January 09, 2025

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

 

CVE-2025-21380 Azure Marketplace SaaS Resources Information Disclosure Vulnerability

Posted on Thursday January 09, 2025

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

 

CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability

Posted on Monday December 23, 2024

Providing further clarification about how to configure the EnableCertPaddingCheck registry value to implement and revert the improvement to authenticode signature verification. Customers who had successfully followed previous guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met. See the **Suggested Actions** section for more information.

 

Chromium: CVE-2024-12692 Type Confusion in V8

Posted on Thursday December 19, 2024

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024) for more information.

 

Page:   1...525354555657585960...120

Celebrating 35+ Years

Managed Computer Support Services

Contact Us

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016