Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52210
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: firefox
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

firefox, mozilla, linux-mozilla, linux-mozilla-devel, de-linux-mozillafirebird, el-linux-mozillafirebird,
ja-linux-mozillafirebird-gtk1, ja-mozillafirebird-gtk2, linux-mozillafirebird, ru-linux-mozillafirebird,
zhCN-linux-mozillafirebird, zhTW-linux-mozillafirebird, de-netscape7, fr-netscape7, ja-netscape7, netscape7,
pt_BR-netscape7, mozilla-gtk1, de-linux-netscape, fr-linux-netscape, ja-linux-netscape, linux-netscape, linux-phoenix,
mozilla+ipv6, mozilla-embedded, mozilla-firebird, mozilla-gtk2, mozilla-gtk, mozilla-thunderbird, phoenix, kdebase,
kdelibs, opera, opera-devel, linux-opera

CVE-2004-1156
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote
attackers to spoof arbitrary web sites by injecting content from one
window into a target window whose name is known but resides in a
different domain, as demonstrated using a pop-up window on a trusted
web site, aka the 'window injection' vulnerability.

CVE-2004-1157
Opera 7.x up to 7.54, and possibly other versions, allows remote
attackers to spoof arbitrary web sites by injecting content from one
window into a target window whose name is known but resides in a
different domain, as demonstrated using a pop-up window on a trusted
web site, aka the 'window injection' vulnerability.

CVE-2004-1158
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows
remote attackers to spoof arbitrary web sites by injecting content
from one window into a target window or tab whose name is known but
resides in a different domain, as demonstrated using a pop-up window
on a trusted web site, aka the 'window injection' vulnerability.

CVE-2004-1160
Netscape 7.x to 7.2, and possibly other versions, allows remote
attackers to spoof arbitrary web sites by injecting content from one
window into a target window whose name is known but resides in a
different domain, as demonstrated using a pop-up window on a trusted
web site, aka the 'window injection' vulnerability.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2004-1156
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
http://secunia.com/secunia_research/2004-13/advisory/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100045
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10117
http://www.redhat.com/support/errata/RHSA-2005-176.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://secunia.com/advisories/13129/
Common Vulnerability Exposure (CVE) ID: CVE-2004-1157
http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml
http://secunia.com/advisories/13253/
Common Vulnerability Exposure (CVE) ID: CVE-2004-1158
BugTraq ID: 11853
http://www.securityfocus.com/bid/11853
Bugtraq: 20041213 KDE Security Advisory: Konqueror Window Injection Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110296048613575&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11056
http://www.redhat.com/support/errata/RHSA-2005-009.html
http://secunia.com/advisories/13254
http://secunia.com/advisories/13477
http://secunia.com/advisories/13486
http://secunia.com/advisories/13560
SuSE Security Announcement: SUSE-SR:2005:001 (Google Search)
http://www.novell.com/linux/security/advisories/2005_01_sr.html
Common Vulnerability Exposure (CVE) ID: CVE-2004-1160
BugTraq ID: 11852
http://www.securityfocus.com/bid/11852
http://secunia.com/advisories/13402/
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.