27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

SeaMonkey < 2.16 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6693 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

attack vectors.\n\nFor your information, the observed version of SeaMonkey is<br />

%L.\n\nVersions of SeaMonkey earlier than 2.16 are potentially affected by multiple<br />

vulnerabilities :\n\n - Numerous memory safety errors exist. (CVE-2013-0783,<br />

CVE-2013-0784)\n\n - An out-of-bounds read error exists related to the handling of GIF<br />

images. (CVE-2013-0772)\n\n - An error exists related to 'WebIDL' object wrapping that<br />

has an unspecified impact. (CVE-2013-0765)\n\n - An error exists related to Chrome<br />

Object Wrappers (COW) or System Only Wrappers (SOW) that could allow security<br />

bypass. (CVE-2013-0773)\n\n - The file system location of the active browser profile could<br />

be disclosed and used in further attacks. (CVE-2013-0774)\n\n - A use-after-free error<br />

exists in the function 'nsImageLoadingContent'. (CVE-2013-0775)\n\n - Spoofing HTTPS<br />

URLs is possible due to an error related to proxy '407' responses and embedded script code.<br />

(CVE-2013-0776)\n\n - A heap-based use-after-free error exists in the function<br />

'nsDisplayBoxShadowOuter::Paint'. (CVE-2013-0777)\n\n - An out-of-bounds read error<br />

exists in the function 'ClusterIterator::NextCluster'. (CVE-2013-0778)\n\n - An<br />

out-of-bounds read error exists in the function 'nsCodingStateMachine::NextState'.<br />

(CVE-2013-0779)\n\n - A heap-based use-after-free error exists in the function<br />

'nsOverflowContinuationTracker::Finish'. (CVE-2013-0780)\n\n - A heap-based<br />

use-after-free error exists in the function 'nsPrintEngine::CommonPrint'.<br />

(CVE-2013-0781)\n\n - A heap-based buffer overflow error exists in the function<br />

'nsSaveAsCharset::DoCharsetConversion'. (CVE-2013-0782)<br />

Solution: Upgrade to Mozilla SeaMonkey 2.16 or later.<br />

CVE-2013-0784<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Google Chrome < 25.0.1364.97 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6694 FAMILY: Web Clients RISK: HIGH NESSUS ID:64813<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Google Chrome is :\n %L<br />

\n\nVersions of Google Chrome earlier than 25.0.1364.97 are potentially affected by the<br />

following vulnerabilities :\n\n - An unspecified memory corruption error exists related to<br />

'web audio node'. (CVE-2013-0879)\n\n - Use-after-free errors exist related to database and<br />

URL handling. (CVE-2013-0880, CVE-2013-0898)\n\n - Improper memory read errors<br />

exist related to Matroska, excessive SVG parameters, and Skia. (CVE-2013-0881,<br />

CVE-2013-0882, CVE-2013-0883, CVE-2013-0888)\n\n - An error exists related to<br />

improper loading of 'NaCl'. (CVE-2013-0884)\n\n - The 'web store' is granted too many<br />

API permissions. (CVE-2013-0885)\n\n - The developer tools process is granted too many<br />

permissions and trusts remote servers incorrectly. (CVE-2013-0887)\n\n - User gestures are<br />

not properly checked with respect to dangerous file downloads. (CVE-2013-0889)\n\n - An<br />

unspecified memory safety issue exists in the IPC layer. (CVE-2013-0890)\n\n - Integer<br />

overflow errors exist related to blob and 'Opus' handling. (CVE-2013-0891,<br />

CVE-2013-0899)\n\n - Numerous, unspecified, lower-severity issues exist related to the<br />

IPC layer. (CVE-2013-0892)\n\n - Race conditions exist related to media handling and<br />

ICU. (CVE-2013-0893, CVE-2013-0900)\n\n - A buffer overflow exists related to vorbis<br />

Family Internet Services 1843

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!