Computer Security
[EN] securityvulns.ru no-pyccku


libxslt multiple security vulnerabilities
Published:05.10.2012
Source:
SecurityVulns ID:12615
Type:library
Threat Level:
6/10
Description:Information leakages, DoS conditions, memory corruptions.
Affected:LIBXLT : libxlt 1.1
CVE:CVE-2012-2893 (Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.)
 CVE-2012-2871 (libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.)
 CVE-2012-2870 (libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.)
 CVE-2012-2825 (The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.)
 CVE-2011-3970 (libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.)
 CVE-2011-1202 (The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.)
Original documentdocumentUBUNTU, [USN-1595-1] libxslt vulnerabilities (05.10.2012)

XnView buffer overflow
Published:05.10.2012
Source:
SecurityVulns ID:12616
Type:local
Threat Level:
4/10
Description:Buffer overflow on JLS files parsing.
Affected:XNVIEW : XnView 1.99
CVE:CVE-2012-4988 (Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.)
Original documentdocumentJoseph Sheridan, XnView JLS File Decompression Heap Overflow (05.10.2012)

HP Network Node Manager i information leakage
Published:05.10.2012
Source:
SecurityVulns ID:12617
Type:remote
Threat Level:
5/10
Affected:HP : HP Network Node Manager i 9.20
CVE:CVE-2012-3267 (Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors.)
Original documentdocumentHP, [security bulletin] HPSBMU02817 SSRT100950 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Disclosure of Information (05.10.2012)

HP IBRIX X9000 information leakage
Published:05.10.2012
Source:
SecurityVulns ID:12618
Type:remote
Threat Level:
5/10
Affected:HP : IBRIX X9000
CVE:CVE-2012-3266 (Unspecified vulnerability in IBRIX 6.1.196 through 6.1.251 on HP IBRIX X9000 Storage allows remote attackers to obtain sensitive information via unknown vectors.)
Original documentdocumentHP, [security bulletin] HPSBST02818 SSRT100960 rev.1 - HP IBRIX X9000 Storage, Remote Disclosure of Information (05.10.2012)

HP SiteScope multiple security vulnerabilities
Published:05.10.2012
Source:
SecurityVulns ID:12619
Type:remote
Threat Level:
5/10
Description:Information leakage, code execution.
Affected:HP : SiteScope 11.10
 HP : SiteScope 11.11
 HP : SiteScope 11.12
CVE:CVE-2012-3264 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1472.)
 CVE-2012-3263 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1465.)
 CVE-2012-3262 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1464.)
 CVE-2012-3261 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1463.)
 CVE-2012-3260 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.)
 CVE-2012-3259 (Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.)
Original documentdocumentHP, [security bulletin] HPSBMU02815 SSRT100715 rev.3 - HP SiteScope SOAP Security Issues, Remote Disclosure of Information, Remote Code Execution (05.10.2012)

RSA SecurID Authentication Agent / RSA Authentication Client protection bypass
Published:05.10.2012
Source:
SecurityVulns ID:12620
Type:local
Threat Level:
6/10
Description:Under some condition user may login with windows credentials only.
Affected:EMC : RSA Authentication Client 3.5
 EMC : RSA Authentication Agent 7.1
CVE:CVE-2012-2287 (The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.)
Original documentdocumentEMC, ESA-2012-037: RSA(r) Authentication Agent 7.1 for Microsoft Windows(r) and RSA(r) Authentication Client 3.5 Access Control Vulnerability (05.10.2012)

HP Operations Orchestration code execution
Published:05.10.2012
Source:
SecurityVulns ID:12621
Type:remote
Threat Level:
5/10
Affected:HP : HP Operations Orchestration 9.0
CVE:CVE-2012-3258 (Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.)
Original documentdocumentHP, [security bulletin] HPSBMU02813 SSRT100712 rev.1 - HP Operations Orchestration, Remote Execution of Arbitrary Code (05.10.2012)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod