27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2008-5024<br />

Safari < 3.2 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4754 FAMILY: Web Clients RISK: HIGH NESSUS ID:34772<br />

Description: Synopsis : \n\nThe remote host contains a web browser that is affected by several<br />

issues.\n\nThe version of Safari installed on the remote Windows host is earlier than 3.2.<br />

Such versions are potentially affected by several issues : \n\n\n - Safari includes a version<br />

of zlib that is affected by multiple vulnerabilities. (CVE-2005-2096)\n - A heap buffer<br />

overflow issue in the libxslt library could lead to a crash or arbitrary code execution.<br />

(CVE-2008-1767)\n - A signedness issue in Safari's handling of JavaScript array indices<br />

could lead to a crash or arbitrary code execution. (CVE-2008-2303)\n - A memory<br />

corruption issue in WebCore's handling of style sheet elements could lead to a crash or<br />

arbitrary code execution. (CVE-2008-2317)\n - Multiple uninitialized memory access<br />

issues in libTIFF's handling of LZW-encoded TIFF images could lead to a crash or<br />

arbitrary code execution. (CVE-2008-2327)\n - A memory corruption issue in ImageIO's<br />

handling of TIFF images could lead to a crash or arbitrary code execution.<br />

(CVE-2008-2332).\n - A memory corruption issue in ImageIO's handling of embedded ICC<br />

profiles in JPEG images could lead to a crash or arbitrary code execution.<br />

(CVE-2008-3608)\n - A heap buffer overflow in CoreGraphics' handling of color spaces<br />

could lead to a crash or arbitrary code execution. (CVE-2008-3623)\n - A buffer overflow<br />

in the handling of images with an embedded ICC profile could lead to a crash or arbitrary<br />

code execution. (CVE-2008-3642)\n - Disabling autocomplete on a form field may not<br />

prevent the data in the field from being stored in the browser page cache.<br />

(CVE-2008-3644)\n - WebKit's plug-in interface does not block plug-ins from launching<br />

local URLs, which could allow a remote attacker to launch local files in Safari and lead to<br />

the disclosure of sensitive information. (CVE-2008-4216)\n\nThe reported version of Safari<br />

is: \n %L \nIAVB Reference : 2008-B-0078\nSTIG Finding Severity : Category I<br />

Solution: Upgrade to version 3.2 or higher.<br />

CVE-2008-4216<br />

Sun Java System Identity Manager Version Detection<br />

<strong>PVS</strong> ID: 4755 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Sun Java System Identity Manager. This system is used to<br />

manage and audit user rights across an enterprise. <strong>PVS</strong> has observed version: \n %L<br />

Solution: N/A<br />

CVE Not available<br />

Microsoft Web Service client Version Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4756 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1251

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!