A vulnerability was found in InsydeH2O up to 05.15.10/05.25.10/05.34.10/05.42.10. It has been rated as critical. Affected by this issue is the function SdLegacySmm
of the component SMI Handler. Upgrading to version 05.15.11, 05.25.11, 05.34.11 or 05.42.11 eliminates this vulnerability.
InsydeH2O up to 05.15.10/05.25.10/05.34.10/05.42.10 SMI SdLegacySmm CommBuffer input validation
- Virtual Patching
- January 6, 2022
- 8:10 am
CVE-2023-42917 : APPLE IOS/IPADOS WEB CONTENTS MEMORY CORRUPTION
Description A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2,
CVE-2023-4474 : ZYXEL NAS326/NAS542 WSGI SERVER OS COMMAND INJECTION
Description The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542
CVE-2023-46589 : APACHE TOMCAT UP TO 8.5.95/9.0.82/10.1.15/11.0.0-M10 HTTP TRAILER HEADER REQUEST SMUGGLING
Description Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82