Информационная безопасность
[RU] switch to English


Многочисленные уязвимости безопасности в Apple iOS 6.0
Опубликовано:5 ноября 2012 г.
Источник:
SecurityVulns ID:12694
Тип:клиент
Уровень опасности:
6/10
Описание:Утечка информации, обход защиты, повреждение памяти, кратковременные условия.
Затронутые продукты:APPLE : iPhone 3GS
 APPLE : iPhone 4
 APPLE : iPhone 4s
 APPLE : iPhone 5
CVE:CVE-2012-5112 (Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.)
 CVE-2012-3750 (The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.)
 CVE-2012-3749 (The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.)
 CVE-2012-3748 (Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.)
Оригинальный текстdocumentAPPLE, APPLE-SA-2012-11-01-1 iOS 6.0.1 (05.11.2012)

DoS против HP Performance Insight with Sybase
Опубликовано:5 ноября 2012 г.
Источник:
SecurityVulns ID:12696
Тип:удаленная
Уровень опасности:
5/10
Затронутые продукты:HP : Performance Insight 5.41
CVE:CVE-2012-3270 (Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3269.)
 CVE-2012-3269 (Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270.)
Оригинальный текстdocumentHP, [security bulletin] HPSBMU02827 SSRT100924 rev.1 - HP Performance Insight with Sybase, Remote Denial of Service (DoS) and Loss of Data (05.11.2012)

Уязвимости безопасности в WebKit / Appl Safari / Google Chrome
дополнено с 5 ноября 2012 г.
Опубликовано:9 сентября 2013 г.
Источник:
SecurityVulns ID:12695
Тип:библиотека
Уровень опасности:
6/10
Описание:Кратковременные условия, использование памяти после освобождения.
Затронутые продукты:APPLE : Safari 6.0
 GOOGLE : Chrome 22.0
CVE:CVE-2012-5112 (Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.)
 CVE-2012-3748 (Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.)
Оригинальный текстdocumentbugtraq_(at)_packetstormsecurity.org, [PSA-2013-0903-1] Apple Safari Heap Buffer Overflow (09.09.2013)
 documentAPPLE, APPLE-SA-2012-11-01-2 Safari 6.0.2 (05.11.2012)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород