Численні уразливості в Mozilla Firefox, Thunderbird, Seamonkey

22:44 15.10.2015

Виявлені численні уразливості безпеки в Mozilla Firefox, Thunderbird, Seamonkey.

Уразливі продукти: Mozilla Firefox ESR 38.2, Firefox 40, Thunderbird 38.2, SeaMonkey 2.37.

Пошкодження пам’яті, розкриття інформації, DoS, переповнення буфера, обхід обмежень.

  • MFSA 2015-96 Miscellaneous memory safety hazards (rv:41.0 / rv:38.3) (деталі)
  • MFSA 2015-97 Memory leak in mozTCPSocket to servers (деталі)
  • MFSA 2015-98 Out of bounds read in QCMS library with ICC V4 profile attributes (деталі)
  • MFSA 2015-99 Site attribute spoofing on Android by pasting URL with unknown scheme (деталі)
  • MFSA 2015-101 Buffer overflow in libvpx while parsing vp9 format video (деталі)
  • MFSA 2015-102 Crash when using debugger with SavedStacks in JavaScript (деталі)
  • MFSA 2015-103 URL spoofing in reader mode (деталі)
  • MFSA 2015-104 Use-after-free with shared workers and IndexedDB (деталі)
  • MFSA 2015-105 Buffer overflow while decoding WebM video (деталі)
  • MFSA 2015-106 Use-after-free while manipulating HTML media content (деталі)
  • MFSA 2015-107 Out-of-bounds read during 2D canvas display on Linux 16-bit color depth systems (деталі)
  • MFSA 2015-108 Scripted proxies can access inner window (деталі)
  • MFSA 2015-109 JavaScript immutable property enforcement can be bypassed (деталі)
  • MFSA 2015-110 Dragging and dropping images exposes final URL after redirects (деталі)
  • MFSA 2015-111 Errors in the handling of CORS preflight request headers (деталі)
  • MFSA 2015-112 Vulnerabilities found through code inspection (деталі)
  • MFSA 2015-113 Memory safety errors in libGLES in the ANGLE graphics library (деталі)
  • MFSA 2015-114 Information disclosure via the High Resolution Time API (деталі)

Leave a Reply

You must be logged in to post a comment.