Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.67992
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: webkit-gtk2
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to the system as announced in the referenced advisory.

The following package is affected: webkit-gtk2

CVE-2010-1782
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial
of service.

CVE-2010-1784
The counters functionality in the CSS implementation in WebKit in Apple Safari before 5.0.1
on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote
attackers to execute arbitrary code or cause a denial of service.

CVE-2010-1785
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, accesses uninitialized memory during processing of the (1)
:first-letter and (2) :first-line pseudo-elements in an SVG text element, which allows remote
attackers to execute arbitrary code or cause a denial of service.

CVE-2010-1786
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through
10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute
arbitrary code or cause a denial of service via a foreignObject element in an SVG document.

CVE-2010-1787
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial
of service.

CVE-2010-1788
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial
of service.

CVE-2010-1790
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, does not properly handle just-in-time (JIT) compiled JavaScript
stubs, which allows remote attackers to execute arbitrary code or cause a denial of service
via a crafted HTML document, related to a 'reentrancy issue.'

CVE-2010-1792
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before
4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial
of service.

CVE-2010-1793
Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X
10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allow remote attackers to
execute arbitrary code or cause a denial of service via a (1) font-face or (2) use element
in an SVG document.

CVE-2010-2648
The implementation of the Unicode Bidirectional Algorithm in Google Chrome before 5.0.375.99
allows remote attackers to cause a denial of service or possibly have unspecified other impact
via unknown vectors.

Solution:
Update your system with the appropriate patches or software upgrades.

http://gitorious.org/webkitgtk/stable/commit/9d07fda89aab7105962d933eef32ca15dda610d8
http://www.vuxml.org/freebsd/9bcfd7b6-bcda-11df-9a6a-0015f2db7bde.html

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-1781
http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
BugTraq ID: 43077
http://www.securityfocus.com/bid/43077
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://secunia.com/advisories/41856
http://secunia.com/advisories/42314
http://secunia.com/advisories/43068
SuSE Security Announcement: SUSE-SR:2010:018 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2010/2722
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0552
XForce ISS Database: appleios-inline-elements-code-exec(61698)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61698
Common Vulnerability Exposure (CVE) ID: CVE-2010-1782
http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html
BugTraq ID: 42020
http://www.securityfocus.com/bid/42020
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11935
http://www.redhat.com/support/errata/RHSA-2011-0177.html
http://secunia.com/advisories/43086
http://www.vupen.com/english/advisories/2011/0216
Common Vulnerability Exposure (CVE) ID: CVE-2010-1784
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11766
Common Vulnerability Exposure (CVE) ID: CVE-2010-1785
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11941
Common Vulnerability Exposure (CVE) ID: CVE-2010-1786
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11837
Common Vulnerability Exposure (CVE) ID: CVE-2010-1787
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11877
Common Vulnerability Exposure (CVE) ID: CVE-2010-1788
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11962
Common Vulnerability Exposure (CVE) ID: CVE-2010-1790
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11777
Common Vulnerability Exposure (CVE) ID: CVE-2010-1792
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11898
Common Vulnerability Exposure (CVE) ID: CVE-2010-1793
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11923
Common Vulnerability Exposure (CVE) ID: CVE-2010-2648
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11900
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2022 E-Soft Inc. All rights reserved.