Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2023
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
CVSS Score
5.9
EPSS Score
0.002
Published
2023-10-10
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
CVSS Score
5.3
EPSS Score
0.005
Published
2023-10-10
Microsoft SQL Server Denial of Service Vulnerability
CVSS Score
5.5
EPSS Score
0.001
Published
2023-10-10
Named Pipe File System Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.001
Published
2023-10-10
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVSS Score
7.8
EPSS Score
0.005
Published
2023-10-10
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.007
Published
2023-10-10
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.001
Published
2023-10-10
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.002
Published
2023-10-10
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.012
Published
2023-10-10
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.0
EPSS Score
0.009
Published
2023-10-10


Contact Us

Shodan ® - All rights reserved