Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Townsend Ladd Harris

#20452de 53,635
12.5CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2011-1346
7.1
2011-09-13
Palm · Webos · CVE-2009-5097
**Name of the Vulnerable Software and Affected Versions** Palm Pre WebOS versions 1.1 and earlier **Description** The issue allows remote attackers to execute arbitrary JavaScript in email messages. This is demonstrated by the ability to read PalmDatabase.db3. **Recommendations** For Palm Pre WebOS versions 1.1 and earlier, consider disabling JavaScript processing in email messages as a temporary workaround until a patch is available.
PT-2011-1347
5.4
2011-09-13
Palm · Webos · CVE-2009-5098
**Name of the Vulnerable Software and Affected Versions** Palm Pre WebOS versions 1.1 and earlier **Description** The issue allows remote attackers to cause a denial of service, resulting in a crash, by exploiting a weakness in the LunaSysMgr process. This occurs when a web page containing a long string following a refresh tag is accessed, triggering a floating point exception. The estimated number of potentially affected devices worldwide is not specified. **Recommendations** For Palm Pre WebOS versions 1.1 and earlier, consider avoiding the use of web pages with long strings following refresh tags until a fix is available. As a temporary workaround, users may want to view web pages in landscape mode to potentially mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.