Risk
8/5/2010
10:48 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Brace For Heavy Patch Tuesday

This Tuesday Microsoft is expected to release a record number of security bulletins that affect many versions of Windows and an assortment of applications.

This Tuesday Microsoft is expected to release a record number of security bulletins that affect many versions of Windows and an assortment of applications.The Microsoft Security Bulletin Advance Notification for August 2010 warns of 14 bulletins that address 34 vulnerabilities in Windows, Microsoft Office, Internet Explorer, SQL, and Silverlight.

In total there are 8 bulletins rated as Critcial, and six have the less severe rating of Important. No version of Windows goes unscathed this month as every version of Windows has at least 1 critcal vulnerability. For those who have to deploy these patches in a large environment, many of these updates will require a reboot. Most versions of Office (including the Mac version) are also affected.

According to this post at the Microsoft Security Response Center, this month comprises the most bulletins published since Microsoft started the program, however the 34 vulnerabilities being fixed ties the all-time monthly record set just two months ago.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1291
Published: 2015-09-03
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web s...

CVE-2015-1292
Published: 2015-09-03
The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.

CVE-2015-1293
Published: 2015-09-03
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVE-2015-1294
Published: 2015-09-03
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an...

CVE-2015-1295
Published: 2015-09-03
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC m...

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.