Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.803659
Kategorie:General
Titel:Mozilla Seamonkey Multiple Vulnerabilities - Oct 12 (Mac OS X)
Zusammenfassung:The host is installed with Mozilla Seamonkey and is prone to multiple; vulnerabilities.
Beschreibung:Summary:
The host is installed with Mozilla Seamonkey and is prone to multiple
vulnerabilities.

Vulnerability Insight:
The flaws are due to

- An error while handling navigation away from a web page that has multiple
menus of SELECT elements active, which allows remote attackers to conduct
clickjacking attacks.

- An invalid cast when using the instance of operator on certain types of
JavaScript objects.

- An error when implementing the HTML5 Same Origin Policy, which allows
remote attackers to conduct cross-site scripting (XSS) attacks by
leveraging initial-origin access after document.domain has been set.

Vulnerability Impact:
Successful exploitation will let attackers to conduct cross-site scripting,
clickjacking attacks or cause a denial of service or possibly execute
arbitrary code.

Affected Software/OS:
SeaMonkey versions before 2.13 on Mac OS X

Solution:
Upgrade to SeaMonkey version 2.13 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 55856
Common Vulnerability Exposure (CVE) ID: CVE-2012-5354
http://osvdb.org/86171
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16972
http://secunia.com/advisories/50856
http://secunia.com/advisories/50935
Common Vulnerability Exposure (CVE) ID: CVE-2012-3989
http://osvdb.org/86097
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16814
http://secunia.com/advisories/50892
http://secunia.com/advisories/50904
http://secunia.com/advisories/50984
SuSE Security Announcement: SUSE-SU-2012:1351 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
http://www.ubuntu.com/usn/USN-1611-1
Common Vulnerability Exposure (CVE) ID: CVE-2012-3985
http://osvdb.org/86106
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16108
Common Vulnerability Exposure (CVE) ID: CVE-2012-3984
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16184
CopyrightCopyright (C) 2013 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.