Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Today's NIST CVE Issuance's For Vulns In JBoss Enterprise Application Platform, Apache CXF and FFmpeg

$
0
0
Click on the underlined CVE for additional vuln specific info


CVE-2012-4550
Summary: JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB.
Published: 01/05/2013
CVE-2012-4549
Summary: The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.
Published: 01/05/2013
CVE-2012-2378
Summary: Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
Published: 01/05/2013
CVE-2011-3937
Summary: The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has specified impact and attack vectors related to "width/height changing with frame threads."
Published: 01/05/2013

Viewing all articles
Browse latest Browse all 8064

Trending Articles