27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-2012-3180<br />

BigFix Client Patch Update<br />

<strong>PVS</strong> ID: 6612 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is a BigFix client downloading the following patches from the BigFix<br />

server<br />

Solution: N/A<br />

realtimeonly<br />

CVE Not available<br />

Mozilla SeaMonkey 2.13.x < 2.13.2 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6613 FAMILY: Web Clients RISK: HIGH NESSUS ID:62747<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

vulnerabilities.\n\nFor your information, the observed version of SeaMonkey is : \n %L<br />

\n\nVersions of SeaMonkey 2.13.1 and earlier are potentially affected by the following<br />

security issues :\n\n - The true value of 'window.location' can be shadowed by user content<br />

through the use of the 'valueOf' method, which can be combined with some plugins to<br />

perform cross-site scripting attacks. (CVE-2012-4194)\n\n - The 'CheckURL' function of<br />

'window.location' can be forced to return the wrong calling document and principal,<br />

allowing a cross-site scripting attack. (CVE-2012-4195)\n\n - It is possible to use property<br />

injection by prototype to bypass security wrapper protections on the 'Location' object,<br />

allowing the cross-origin reading of the 'Location' object. (CVE-2012-4196)\n<br />

Solution: Upgrade to SeaMonkey 2.13.2 or later.<br />

CVE-2012-4196<br />

Mozilla Thunderbird 16.x < 16.0.2 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6614 FAMILY: SMTP Clients<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:62746<br />

Description: Synopsis :\n\nThe remote host has a mail client installed that is vulnerable to multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Thunderbird is : \n %L<br />

\n\nVersions earlier than Thunderbird 16.0.2 are potentially affected by the following<br />

security issues :\n\n - The true value of 'window.location' can be shadowed by user content<br />

through the use of the 'valueOf' method, which can be combined with some plugins to<br />

perform cross-site scripting attacks. (CVE-2012-4194)\n\n - The 'CheckURL' function of<br />

'window.location' can be forced to return the wrong calling document and principal,<br />

allowing a cross-site scripting attack. (CVE-2012-4195)\n\n - It is possible to use property<br />

injection by prototype to bypass security wrapper protections on the 'Location' object,<br />

allowing the cross-origin reading of the 'Location' object. (CVE-2012-4196)\n<br />

Solution: Upgrade to Thunderbird 16.0.2 or later.<br />

Family Internet Services 1814

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!