27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-2012-0648<br />

Safari < 5.1.4 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6346 FAMILY: Web Clients RISK: HIGH NESSUS ID:58323<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is vulnerable to multiple attack<br />

vectors.\n\nThe remote host has Safari installed. For your information, the observed version<br />

of Safari is: \n %L \n\nVersions of Safari earlier than 5.1.4 are reportedly affected by<br />

several issues :\n\n - Look-alike characters in a URL could be used to masquerade a<br />

website. (CVE-2012-0584)\n\n - Web page visits may be recorded in browser history even<br />

when private browsing is active. (CVE-2012-0585)\n\n - Multiple cross-site scripting issues<br />

existed in WebKit. (CVE-2011-3881, CVE-2012-0586, CVE-2012-0587, CVE-2012-0588,<br />

CVE-2012-0589)\n\n - A cross-origin issue existed in WebKit, which may allow cookies to<br />

be disclosed across origins. (CVE-2011-3887)\n\n - Visiting a maliciously crafted website<br />

and dragging content with the mouse may lead to a cross-site scripting attack.<br />

(CVE-2012-0590)\n\n - Multiple memory corruption issues existed in WebKit.<br />

(CVE-2011-2825, CVE-2011-2833, CVE-2011-2846, CVE-2011-2847, CVE-2011-2854,<br />

CVE-2011-2855, CVE-2011-2857, CVE-2011-2860, CVE-2011-2866, CVE-2011-2867,<br />

CVE-2011-2868, CVE-2011-2869, CVE-2011-2870, CVE-2011-2871, CVE-2011-2872,<br />

CVE-2011-2873, CVE-2011-2877, CVE-2011-3885, CVE-2011-3888, CVE-2011-3897,<br />

CVE-2011-3908, CVE-2011-3909, CVE-2011-3928, CVE-2012-0591, CVE-2012-0592,<br />

CVE-2012-0593, CVE-2012-0594, CVE-2012-0595, CVE-2012-0596, CVE-2012-0597,<br />

CVE-2012-0598, CVE-2012-0599, CVE-2012-0600, CVE-2012-0601, CVE-2012-0602,<br />

CVE-2012-0603, CVE-2012-0604, CVE-2012-0605, CVE-2012-0606, CVE-2012-0607,<br />

CVE-2012-0608, CVE-2012-0609, CVE-2012-0610, CVE-2012-0611, CVE-2012-0612,<br />

CVE-2012-0613, CVE-2012-0614, CVE-2012-0615, CVE-2012-0616, CVE-2012-0617,<br />

CVE-2012-0618, CVE-2012-0619, CVE-2012-0620, CVE-2012-0621, CVE-2012-0622,<br />

CVE-2012-0623, CVE-2012-0624, CVE-2120-0625, CVE-2012-0626, CVE-2012-0627,<br />

CVE-2012-0628, CVE-2012-0629, CVE-2012-0630, CVE-2012-0631, CVE-2012-0632,<br />

CVE-2012-0633, CVE-2012-0635, CVE-2012-0636, CVE-2012-0637, CVE-2012-0638,<br />

CVE-2012-0639, CVE-2012-0648(\n\n - Cookies may be set by third-parties, even when<br />

Safari is configured to block them. (CVE-2012-0640)\n\n - If a site uses HTTP<br />

authentication and redirects to another site, the authentication credentials may be sent to the<br />

other site. (CVE-2012-0647)<br />

Solution: Upgrade to Safari 5.1.4 or later.<br />

CVE-2012-0648<br />

DB2 9.5 < Fix Pack 9 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6347 FAMILY: Database RISK: HIGH NESSUS ID:58293<br />

Description: Synopsis :\n\nThe remote database server is vulnerable to multiple attack vectors.\n\nFor<br />

your information, the observed version of IBM DB2 is %L\n\nVersions of IBM DB2 9.5<br />

earlier than Fix Pack 9 are potentially affected by multiple issues : - Incorrect,<br />

world-writable file permissions are in place for the file 'NODES.REG'. (IC79518)\n\n - An<br />

unspecified error can allow attacks to cause a denial of service via unspecified vectors.<br />

(IC76899)\n\n - A local user can exploit a vulnerability in the bundled IBM Tivoli<br />

Monitoring Agent (ITMA) to escalate their privileges. (IC79970)\n\n - An unspecified error<br />

Family Internet Services 1735

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!