27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

(CVE-2012-1955)\n\n - Cross-site scripting attacks are possible due to an error related to<br />

the '' tag within an RSS '' element. (CVE-2012-1957)\n\n - A<br />

use-after-free error exists related to the method 'nsGlobalWindow::PageHidden'.<br />

(CVE-2012-1958)\n\n - An error exists that can allow 'same-compartment security<br />

wrappers' (SCSW) to be bypassed.(CVE-2012-1959)\n\n - An out-of-bounds read error<br />

exists related to the color management library (QCMS). (CVE-2012-1960)\n\n - The<br />

'X-Frames-Options' header is ignored if it is duplicated. (CVE-2012-1961)\n\n - A memory<br />

corruption error exists related to the method 'JSDependentString::undepend'.<br />

(CVE-2012-1962)\n\n - An error related to the 'Content <strong>Security</strong> Policy' (CSP)<br />

implementation can allow the disclosure of OAuth 2.0 access tokens and OpenID<br />

credentials. (CVE-2012-1963)\n\n - An error exists related to the certificate warning page<br />

that can allow 'clickjacking' thereby tricking a user into accepting unintended certificates.<br />

(CVE-2012-1964)\n\n - An error exists related to the 'javascript:' URL that can allow<br />

scripts to run at elevated privileges outside the sandbox. (CVE-2012-1967)<br />

Solution: Upgrade to SeaMonkey 2.11 or later.<br />

CVE-2012-1967<br />

Safari < 6.0 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6522 FAMILY: Web Clients RISK: HIGH NESSUS ID:60127<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is vulnerable to multiple attack<br />

vectors.\n\nThe remote host has Safari installed. For your information, the observed version<br />

of Safari is: \n %L \n\nVersions of Safari earlier than 6.0 are reportedly affected by several<br />

issues :\n\n - An unspecified cross-site scripting issue exists. (CVE-2012-0678)\n\n - An<br />

error in the handling of 'feed://' URLs can allow local files to be disclosed to remote<br />

servers. (CVE-2012-0679)\n\n - Password input elements are auto completed even when a<br />

webpage specifically forbids it. (CVE-2012-0680)\n\n - A cross-site scripting issue exists<br />

due to improper handling of the HTTP 'Content-Disposition' header value of 'attachment'.<br />

(CVE-2011-3426)\n\n - Numerous issues exist in WebKit. (CVE-2011-2845,<br />

CVE-2011-3016, CVE-2011-3021, CVE-2011-3027, CVE-2011-3032, CVE-2011-3034,<br />

CVE-2011-3035, CVE-2011-3036, CVE-2011-3037, CVE-2011-3038, CVE-2011-3039,<br />

CVE-2011-3040, CVE-2011-3041, CVE-2011-3042, CVE-2011-3043, CVE-2011-3044,<br />

CVE-2011-3050, CVE-2011-3053, CVE-2011-3059, CVE-2011-3060, CVE-2011-3064,<br />

CVE-2011-3067, CVE-2011-3068, CVE-2011-3069, CVE-2011-3071, CVE-2011-3073,<br />

CVE-2011-3074, CVE-2011-3075, CVE-2011-3076, CVE-2011-3078, CVE-2011-3081,<br />

CVE-2011-3086, CVE-2011-3089, CVE-2011-3090, CVE-2011-3913, CVE-2011-3924,<br />

CVE-2011-3926, CVE-2011-3958, CVE-2011-3966, CVE-2011-3968, CVE-2011-3969,<br />

CVE-2011-3971, CVE-2012-0682, CVE-2012-0683, CVE-2012-1520, CVE-2012-1521,<br />

CVE-2012-2815, CVE-2012-3589, CVE-2012-3590, CVE-2012-3591, CVE-2012-3592,<br />

CVE-2012-3593, CVE-2012-3594, CVE-2012-3595, CVE-2012-3596, CVE-2012-3597,<br />

CVE-2012-3599, CVE-2012-3600, CVE-2012-3603, CVE-2012-3604, CVE-2012-3605,<br />

CVE-2012-3608, CVE-2012-3609, CVE-2012-3610, CVE-2012-3611, CVE-2012-3615,<br />

CVE-2012-3618, CVE-2012-3620, CVE-2012-3625, CVE-2012-3626, CVE-2012-3627,<br />

CVE-2012-3628, CVE-2012-3629, CVE-2012-3630, CVE-2012-3631, CVE-2012-3633,<br />

CVE-2012-3634, CVE-2012-3635, CVE-2012-3636, CVE-2012-3637, CVE-2012-3638,<br />

CVE-2012-3639, CVE-2012-3640, CVE-2012-3641, CVE-2012-3642, CVE-2012-3644,<br />

CVE-2012-3645, CVE-2012-3646, CVE-2012-3650, CVE-2012-3653, CVE-2012-3655,<br />

Family Internet Services 1783

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!