Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800846
Kategorie:Buffer overflow
Titel:Mozilla Firefox Buffer Overflow Vulnerability (Jul 2009) - Windows
Zusammenfassung:Mozilla Firefox browser is prone to a buffer overflow vulnerability.
Beschreibung:Summary:
Mozilla Firefox browser is prone to a buffer overflow vulnerability.

Vulnerability Insight:
- A NULL pointer dereference error exists due an unspecified vectors, related
to a 'flash bug.' which can cause application crash.

- Stack-based buffer overflow error is caused by sending an overly long string
argument to the 'document.write' method.

Vulnerability Impact:
Successful attacks will let attackers to can cause Denial of Service to the
legitimate user.

Affected Software/OS:
Firefox version 3.5.1 and prior on Windows

Solution:
Upgrade to Firefox version 3.6.3 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-2478
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html
Common Vulnerability Exposure (CVE) ID: CVE-2009-2479
BugTraq ID: 35707
http://www.securityfocus.com/bid/35707
Bugtraq: 20090719 DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome (Google Search)
http://www.securityfocus.com/archive/1/505092/100/0/threaded
http://www.exploit-db.com/exploits/9158
http://websecurity.com.ua/3338/
https://bugzilla.mozilla.org/show_bug.cgi?id=504343
http://osvdb.org/55931
http://www.securitytracker.com/id?1022580
XForce ISS Database: firefox-unicode-data-dos(51729)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51729
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.