Download
| Alert*
oval:org.mitre.oval:def:6888
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 or Apple iTunes 9.2 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lac ... oval:org.secpod.oval:def:4323 The host is installed with Apple Safari 4.0 before 4.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to handle UTF-7 encoded text. Successful exploitation could allow attackers to inject arbitrary code or crash the service. oval:org.secpod.oval:def:4411 The host is missing an important security update according to APPLE-SA-2010-06-16-1. The flaws are present in the application, which fails to sanitize user supplied data. Successful exploitation could allow attackers to crash the service. oval:org.secpod.oval:def:4266 The host is installed with Apple Safari before 4.1 or 5.0 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to handle vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document. oval:org.secpod.oval:def:4277 The host is missing a security update according to Apple advisory, APPLE-SA-2010-06-07-1. The update is required to fix multiple vulnerabilities. The flaws are present in the application, which fails to handle malicious data. Successful exploitation could allow attackers to disclose sensitive inform ... oval:org.secpod.oval:def:300417 Multiple cross-site scripting, denial of service and arbitrary code execution security flaws were discovered in webkit. Please consult the CVE web links for further information. The updated packages have been upgraded to the latest version to correct these issues. |