27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2011-3665<br />

Mozilla Thunderbird 8 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6110 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:57361<br />

Description: Synopsis :\n\nThe remote host has a email client installed that is vulnerable to multiple<br />

attack vectors.\n\nThe remote host has a email client installed that is vulnerable to multiple<br />

attack vectors.\n\nFor your information, the observed version of Thunderbird is : \n %L<br />

\n\nVersions of Thunderbird 8.0 are potentially affected by the following security issues :<br />

\n\n - An out-of-bounds memory access error exists in the 'SVG' implementation and can be<br />

triggered when 'SVG' elements are removed during a 'DOMAttrModified' event handler.<br />

(CVE-2011-3658)\n\n - Various memory safety errors exist that can lead to memory<br />

corruption and possible code execution. (CVE-2011-3660)\n\n - An error exists in the<br />

'YARR' regular expression library that can cause application crashes when handling certain<br />

JavaScript statements. (CVE-2011-3661)\n\n - It is possible to detect keystrokes using<br />

'SVG' animation 'accesskey' events even when JavaScript is disabled.<br />

(CVE-2011-3663)\n\n - AN error exists related to plugins that can allow a null pointer to be<br />

dereferenced when a plugin deletes its containing DOM frame during a call from that<br />

frame. It may be possible for a non-null pointer to be dereferenced thereby opening up the<br />

potential for further exploitation. (CVE-2011-3664)\n\n - It is possible to crash the<br />

application when 'OGG' 'video' elements are scaled to extreme sizes. (CVE-2011-3665)<br />

Solution: Upgrade to Thunderbird 9.0 or later.<br />

Windows OS detection<br />

CVE-2011-3665<br />

<strong>PVS</strong> ID: 6111 FAMILY: Operating System Detection RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running a windows device version: %L<br />

Solution: N/A<br />

CVE Not available<br />

Shavlik Software Management Detection<br />

<strong>PVS</strong> ID: 6112 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Shavlik software management package. This tool is used to<br />

track and monitor software being utilized on the client system.<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

HP Managed Printing Administration < 2.6.4 Multiple Vulnerabilities<br />

Family Internet Services 1669

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!