|
Is affected the system:
Mozilla Firefox < 2.0.0.15
Not affected system:
Mozilla Firefox 2.0.0.15
Description:
--------------------------------------------------------------------------------
BUGTRAQ ID: 30038
CVE(CAN) ID: CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2806, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2810, CVE-2008-2811
Firefox is operates the source WEB browser which Mozilla issued.
In the Firefox many security crack allows the malicious user revelation sensitive information, to bypass the safe limit, the execution deceit attack or the invasion subscriber system. As a result of code sharing, Thunderbird and SeaMonkey also receive these crack's influence.
1) the homepage layout and in JavaScript engine's many cracks possibly cause the memory destruction.
2) processes in the non-privilege XUL documents the crack possibly to cause through the <script> unit to load the Chrome script from the fastload document.
3) in mozIJSSubScriptLoader.LoadScript() function's crack possibly causes to bypass XPCNativeWrappers by the Chrome jurisdiction execution random code. The success attack request installed has used this function the additional software.
4) in the block backflow advancement's crack possibly causes to collapse or the execution random code.
5) handles in the document URL way crack which in the local table of contents tabulation contains possibly to cause to carry out the malicious JavaScript content.
6) JavaScript realizes in homologous strategy way many cracks possibly to cause by the different territory environment execution random script code.
7) confirms in JAR document many cracks which signs possibly to cause by JAR subscriber's jurisdiction execution willfully JavaScript code.
8) realizes in the document upload form way crack possibly to cause through specially made DOM Range and the originalTarget unit to the long-distance web server upload local document.
9) Java LiveConnect X platform realizes the crack in Mac in the OS possibly to cause to found the random sleeve joint character connection.
10), in processing is not correct when the .properties document which codes does not have the initialization memory visit crack, possibly causes through the additional software revelation sensitive memory.
11), in processing by coordinated may trust Alt which the certificate provides in the Names attribute way crack possibly to cause to carry out the deceit attack.
12) processes Windows in the URL quick way the road section possibly to cause by the local document jurisdiction movement long-distance stand. The success uses this crack to request to trap the user to download and to open malicious Windows the URL quick way.
<* origin: moz_bug_r_a4 (moz_bug_r_a4@yahoo.com)
Greg McManus
Masahiro Yamada (masa141421356@gmail.com)
Collin Jackson (collinj@cs.stanford.edu)
Other pages: : 1 * 2 * 3 * Next>>
|