27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

uninitialized memory access issue in ImageIO's handling of BMP images could result in<br />

sending of data from Safari's memory to a website. (CVE-2010-0041)\n\n - An uninitialized<br />

memory access issue in ImageIO's handling of TIFF images could result in sending of data<br />

from Safari's memory to a website. (CVE-2010-0042)\n\n - A memory corruption issue in<br />

the handling of TIFF images could lead to a crash or arbitrary code execution.<br />

(CVE-2010-0043)\n\n - An implementation issue in the handling of cookies set by RSS and<br />

Atom feeds could result in a cookie being set when visiting or updating a feed even if<br />

Safari is configured to block cookies via the 'Accept Cookies' preference.<br />

(CVE-2010-0044)\n\n - An issue in Safari's handling of external URL schemes could cause<br />

a local file to be opened in response to a URL encountered on a web page, which could<br />

allow a malicious web server to execute arbitrary code. (CVE-2010-0045)\n\n - A memory<br />

corruption issue in WebKit's handling of CSS format() arguments could lead to a crash or<br />

arbitrary code execution. (CVE-2010-0046)\n\n - A use-after-free issue in the handling of<br />

HTML object element fallback content could lead to a crash or arbitrary code execution.<br />

(CVE-2010-0047)\n\n - A use-after-free issue in WebKit's parsing of XML documents<br />

could lead to a crash or arbitrary code execution. (CVE-2010-0048)\n\n - A use-after-free<br />

issue in the handling of HTML elements containing right-to-left displayed text could lead<br />

to a crash or arbitrary code execution. (CVE-2010-0049)\n\n - A use-after-free issue in<br />

WebKit's handling of incorrectly nested HTML tags could lead to a crash or arbitrary code<br />

execution. (CVE-2010-0050)\n\n - An implementation issue in WebKit''s handling of<br />

cross-origin stylesheet requests when visiting a malicious website could result in disclosure<br />

of the content of protected resources on another website. (CVE-2010-0051)\n\n - A<br />

use-after-free issue in WebKit's handling of callbacks for HTML elements could lead to a<br />

crash or arbitrary code execution. (CVE-2010-0052)\n\n - A use-after-free issue in the<br />

rendering of content with a CSS display property set to 'run-in' could lead to a crash or<br />

arbitrary code execution. (CVE-2010-0053)\n\n - A use-after-free issue in WebKit's<br />

handling of HTML image elements could lead to a crash or arbitrary code execution.<br />

(CVE-2010-0054)\n\nFor your information, the observed version of is: \n %L<br />

Solution: Upgrade to Safari 4.0.5 or later.<br />

CVE-2010-0054<br />

Skype < 4.2.0.155 URI Handler <strong>Security</strong> Vulnerability<br />

<strong>PVS</strong> ID: 5362 FAMILY: Internet Messengers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:45061<br />

Description: Synopsis : \n\nThe remote host is running an instant messaging application that is<br />

vulnerable to a security bypass attack.\n\nThe version of Skype installed on the remote host<br />

is earlier than 4.2.0.155. Such versions are potentially affected by a flaw in the handling of<br />

specially crafted 'skype: ' URIs. An attacker, exploiting this flaw, could control certain<br />

Skype settings and possibly gain access to sensitive information. For your information, the<br />

observed version of Skype is: \n %L<br />

Solution: Upgrade to Skype 4.2.0.155 or later.<br />

CVE Not available<br />

eScan Anti-Virus Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1437

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!