A vulnerability has been found in Mayan EDMS 0.13 and classified as problematic. This vulnerability affects unknown code of the component Bootstrap. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2014-3840. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Bioinformatics OrderSys up to 1.6.3. This vulnerability affects unknown code of the file index.php. The manipulation of the argument where_clause leads to sql injection.
This vulnerability was named CVE-2011-5183. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in Oracle Agile Engineering Data Management 6.1.3.0/6.2.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component Install. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2016-2107. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
作者:Trevor Dunlap, John Speed Meyers, Bradley Reaves, and William Enck.
译者:知道创宇404实验室翻译组
原文链接:https://www.enck.org/pubs/dunlap-dimva24.pdf
摘要
随着对开源软件依赖性的需求不断增加,管理这些依赖中的安全漏洞变得愈加复杂。当前最先进的工业工具通过代码的可达性分...
A vulnerability, which was classified as critical, was found in Apple iTunes 10.6.3. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2012-3673. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iTunes 10.6.3 and classified as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2012-3675. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iOS up to 5.1.1. It has been classified as critical. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2012-3672. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iOS up to 5.1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2012-3673. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Apple iTunes 10.6.3. This vulnerability affects unknown code of the component WebKit. The manipulation leads to memory corruption.
This vulnerability was named CVE-2012-3671. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.