Информационная безопасность
[RU] switch to English


Многочисленные уязвимости безопасности в libxslt
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12615
Тип:библиотека
Уровень опасности:
6/10
Описание:Утечки информации, DoS условия, повреждения памяти.
Затронутые продукты:LIBXLT : libxlt 1.1
CVE:CVE-2012-2893 (Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.)
 CVE-2012-2871 (libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.)
 CVE-2012-2870 (libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.)
 CVE-2012-2825 (The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.)
 CVE-2011-3970 (libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.)
 CVE-2011-1202 (The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.)
Оригинальный текстdocumentUBUNTU, [USN-1595-1] libxslt vulnerabilities (05.10.2012)

Переполнение буфера в XnView
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12616
Тип:локальная
Уровень опасности:
4/10
Описание:Переполнение буфера при просмотре файлов JLS
Затронутые продукты:XNVIEW : XnView 1.99
CVE:CVE-2012-4988 (Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.)
Оригинальный текстdocumentJoseph Sheridan, XnView JLS File Decompression Heap Overflow (05.10.2012)

Утечка информации в HP Network Node Manager i
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12617
Тип:удаленная
Уровень опасности:
5/10
Затронутые продукты:HP : HP Network Node Manager i 9.20
CVE:CVE-2012-3267 (Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors.)
Оригинальный текстdocumentHP, [security bulletin] HPSBMU02817 SSRT100950 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Disclosure of Information (05.10.2012)

Утечка информации в HP IBRIX X9000
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12618
Тип:удаленная
Уровень опасности:
5/10
Затронутые продукты:HP : IBRIX X9000
CVE:CVE-2012-3266 (Unspecified vulnerability in IBRIX 6.1.196 through 6.1.251 on HP IBRIX X9000 Storage allows remote attackers to obtain sensitive information via unknown vectors.)
Оригинальный текстdocumentHP, [security bulletin] HPSBST02818 SSRT100960 rev.1 - HP IBRIX X9000 Storage, Remote Disclosure of Information (05.10.2012)

Многочисленные уязвимости безопасности в HP SiteScope
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12619
Тип:удаленная
Уровень опасности:
5/10
Описание:Утечка информации, выполнение кода.
Затронутые продукты:HP : SiteScope 11.10
 HP : SiteScope 11.11
 HP : SiteScope 11.12
CVE:CVE-2012-3264 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1472.)
 CVE-2012-3263 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1465.)
 CVE-2012-3262 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1464.)
 CVE-2012-3261 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1463.)
 CVE-2012-3260 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.)
 CVE-2012-3259 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.)
Оригинальный текстdocumentHP, [security bulletin] HPSBMU02815 SSRT100715 rev.3 - HP SiteScope SOAP Security Issues, Remote Disclosure of Information, Remote Code Execution (05.10.2012)

Обход защиты RSA SecurID Authentication Agent / RSA Authentication Client
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12620
Тип:локальная
Уровень опасности:
6/10
Описание:При некоторых условиях возможен доступ без двухфакторной аутентификации.
Затронутые продукты:EMC : RSA Authentication Client 3.5
 EMC : RSA Authentication Agent 7.1
CVE:CVE-2012-2287 (The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.)
Оригинальный текстdocumentEMC, ESA-2012-037: RSA(r) Authentication Agent 7.1 for Microsoft Windows(r) and RSA(r) Authentication Client 3.5 Access Control Vulnerability (05.10.2012)

Выполнение кода в HP Operations Orchestration
Опубликовано:5 октября 2012 г.
Источник:
SecurityVulns ID:12621
Тип:удаленная
Уровень опасности:
5/10
Затронутые продукты:HP : HP Operations Orchestration 9.0
CVE:CVE-2012-3258 (Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.)
Оригинальный текстdocumentHP, [security bulletin] HPSBMU02813 SSRT100712 rev.1 - HP Operations Orchestration, Remote Execution of Arbitrary Code (05.10.2012)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород