Tuesday, May 13, 2025

Microsoft May 2025 Security Updates

 

The Microsoft May 2025 security updates have been released and consist of 75 new CVEs to Microsoft products. The additional third-party CVEs bring the combined total to 134 CVEs and 9 non-Microsoft CVEs.


Of the Microsoft CVEs released, 12 are rated critical and the rest are rated important in security. At the time of release, two are listed as being publicly known and five under active attack.

The security updates apply to the following products, features and roles: Windows and Windows Components, Office and Office Components, .NET and Visual Studio, Azure, Nuance PowerScribe, Remote Desktop Gateway Service, and Microsoft Defender.

See the list of KBs at the bottom of the page at May 2025 Security Updates - Release Notes - Security Update Guide - Microsoft for information regarding known issues with the security updates.

Recommended Reading:   See Dustin Childs review and analysis in Zero Day Initiative -- The May 2025 Security Update Review.

Additional Update Notes:

 

References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Mozilla Firefox Version 138.0.3 Released with Updates

   Mozilla sent Firefox Version 138.0.3 to the Release Channel.

Fixed

  • Fixed a crash that could occur when viewing websites that use WebGL. (Bug 1961191)
  • Fixed an issue where the browser could repeatedly crash when certain SVG effects (like blur or drop shadow) were applied to very small areas. (Bug 1924241)
  • On Linux, fixed an issue where video playback would appear washed-out on Wayland when HDR support was unavailable. (Bug 1961610)
  • Fixed an issue where the "Match Case" shortcut Alt+C in the find-in-page toolbar did not toggle the checkbox as expected. (Bug 1952611)

Update: To get the update now, select "Help" from the Firefox menu, then pick "About Firefox".  Mac users need to select "About Firefox" from the Firefox menu.  For non-English versions, Fully Localized Versions are available for download.

Release Notes


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, May 06, 2025

Pale Moon Version 33.7.1 Released with Security Update

  Pale MoonPale Moon has been updated to version 33.7.1.  This is a bugfix and security update.

Changes/fixes:
  • Fixed a crash dealing with BigInt in Javascript compilation.
  • Updated NSS to 3.90.7 to pick up a security fix.
  • Updated devtools to escape some more characters in "Copy as cURL" on POSIX operating systems. (*DiD).

    Notes:  *DiD This means that a fix is "Defense-in-Depth": It is a fix that does not apply to a (potentially) actively exploitable vulnerability in Pale Moon, but prevents future vulnerabilities caused by the same code, e.g. when surrounding code changes, exposing the problem, or when new attack vectors are discovered.

    Pale Moon includes both 32- and 64-bit versions for Windows: Pale Moon for Windows downloads.

    Update: To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.

    Release Notes
    Release Cycle

    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...