A vulnerability was found in Oracle Agile Engineering Data Management 6.1.3.0/6.2.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component Install. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2016-2107. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
作者:Trevor Dunlap, John Speed Meyers, Bradley Reaves, and William Enck.
译者:知道创宇404实验室翻译组
原文链接:https://www.enck.org/pubs/dunlap-dimva24.pdf
摘要
随着对开源软件依赖性的需求不断增加,管理这些依赖中的安全漏洞变得愈加复杂。当前最先进的工业工具通过代码的可达性分...
A vulnerability, which was classified as critical, was found in Apple iTunes 10.6.3. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2012-3673. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iTunes 10.6.3 and classified as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2012-3675. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iOS up to 5.1.1. It has been classified as critical. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2012-3672. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iOS up to 5.1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2012-3673. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Apple iTunes 10.6.3. This vulnerability affects unknown code of the component WebKit. The manipulation leads to memory corruption.
This vulnerability was named CVE-2012-3671. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Apple iTunes 10.6.3. This issue affects some unknown processing of the component WebKit. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2012-3672. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple iOS up to 5.1.1 and classified as critical. This issue affects some unknown processing of the component WebKit. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2012-3671. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Microsoft Windows 2000. This issue affects some unknown processing of the component Telnet Privilege Handler. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2001-0349. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Microsoft Windows 2000. This issue affects some unknown processing of the component SMTP Service. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2001-0504. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Windows 2000 and classified as problematic. Affected by this issue is some unknown functionality of the component Domain Account Lockout Handler. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2000-1217. An attack has to be approached locally. There is no exploit available. This vulnerability has a historic impact due to its background and reception.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in Microsoft Windows Media Player 6.3/6.4/7.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ASX File Handler. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2001-0242. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.