27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2009-0609<br />

Google Chrome < 1.0.154.48 Cross-browser Command Injection<br />

<strong>PVS</strong> ID: 4935 FAMILY: Web Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:35689<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is prone to a cross-browser<br />

scripting attack.\n\nThe version of Google Chrome installed on the remote host is earlier<br />

than 1.0.154.48. Such versions are reportedly affected by a protocol-handler command<br />

injection vulnerability that could allow an attacker to carry out cross-browser scripting<br />

attacks.<br />

Solution: Upgrade to version 1.0.154.48 or higher.<br />

CVE-2007-3670<br />

Dropbox Software Detection<br />

<strong>PVS</strong> ID: 4936 FAMILY: Internet Services RISK: INFO NESSUS ID:35717<br />

Description: Dropbox is installed on the remote host. Dropbox is an application for storing and<br />

synchronizing files between computers, possibly outside the organization.<br />

Solution: Remove this software if its use does not match your organization's security policy.<br />

CVE Not available<br />

Flash Player APSB09-01 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4937 FAMILY: Web Clients RISK: HIGH NESSUS ID:35742<br />

Description: Synopsis :\n\nThe remote Windows host contains a browser plugin that is affected by<br />

multiple vulnerabilities.\n\nThe remote Windows host contains a version of Adobe Flash<br />

Player that is earlier than 10.0.22.87 / 9.0.159.0. Such versions are reportedly affected by<br />

multiple vulnerabilities : \n\n - A buffer overflow issue that could allow an attacker to<br />

execute arbitrary code with the privileges of the user running the application.<br />

(CVE-2009-0520) \n\n - An input validation vulnerability that leads to a denial of service<br />

attack and could possibly allow for an attacker to execute arbitrary code. (CVE-2009-0519)<br />

\n\n - A vulnerability in the Flash Player settings manager that could contribute to a<br />

clickjacking attack. (CVE-2009-0014)\n\n - A vulnerability with the mouse pointer display<br />

that could contribute to a clickjacking attack. (CVE-2009-0522)<br />

Solution: Upgrade to version 10.0.22.87 or higher. If you are unable to upgrade to version 10,<br />

upgrade to version 9.0.159.0 or higher.<br />

CVE-2009-0522<br />

Novell GroupWise MTA Web Console Accessible<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1303

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!