Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.900847
Categoría:Denial of Service
Título:Mozilla Firefox Multiple Vulnerabilities (Sep 2009) - Linux
Resumen:Firefox browser is prone to multiple vulnerabilities.
Descripción:Summary:
Firefox browser is prone to multiple vulnerabilities.

Vulnerability Insight:
- Multiple errors in the browser and JavaScript engines can be exploited to
corrupt memory.

- An error exists when processing operations performed on the columns of a
XUL tree element. This can be exploited to dereference freed memory via a
pointer owned by a column of the XUL tree element.

- An error exists when displaying text in the location bar using the default
Windows font. This can be exploited to spoof the URL of a trusted site via
Unicode characters having a tall line-height.

- An error in the implementation of the 'BrowserFeedWriter' object can be
exploited to execute arbitrary JavaScript code with chrome privileges.

Vulnerability Impact:
A remote, unauthenticated attacker could execute arbitrary code or cause a
vulnerable application to crash.

Affected Software/OS:
Mozilla Firefox version prior to 3.0.14 and 3.5 before 3.5.3 on Linux.

Solution:
Upgrade to Firefox version 3.0.14 or 3.5.3 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-3072
36343
http://www.securityfocus.com/bid/36343
36669
http://secunia.com/advisories/36669
36670
http://secunia.com/advisories/36670
36671
http://secunia.com/advisories/36671
36692
http://secunia.com/advisories/36692
37098
http://secunia.com/advisories/37098
38977
http://secunia.com/advisories/38977
39001
http://secunia.com/advisories/39001
ADV-2010-0648
http://www.vupen.com/english/advisories/2010/0648
ADV-2010-0650
http://www.vupen.com/english/advisories/2010/0650
DSA-1885
http://www.debian.org/security/2009/dsa-1885
RHSA-2009:1430
http://www.redhat.com/support/errata/RHSA-2009-1430.html
RHSA-2009:1431
http://www.redhat.com/support/errata/RHSA-2009-1431.html
RHSA-2009:1432
http://www.redhat.com/support/errata/RHSA-2009-1432.html
RHSA-2010:0153
http://www.redhat.com/support/errata/RHSA-2010-0153.html
RHSA-2010:0154
http://www.redhat.com/support/errata/RHSA-2010-0154.html
SUSE-SA:2009:048
http://www.novell.com/linux/security/advisories/2009_48_firefox.html
SUSE-SR:2010:013
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
USN-915-1
http://www.ubuntu.com/usn/USN-915-1
http://www.mozilla.org/security/announce/2009/mfsa2009-47.html
http://www.mozilla.org/security/announce/2010/mfsa2010-07.html
https://bugzilla.mozilla.org/show_bug.cgi?id=494283
https://bugzilla.mozilla.org/show_bug.cgi?id=501900
https://bugzilla.mozilla.org/show_bug.cgi?id=508074
oval:org.mitre.oval:def:10349
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10349
oval:org.mitre.oval:def:6315
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6315
Common Vulnerability Exposure (CVE) ID: CVE-2009-3077
http://www.mozilla.org/security/announce/2009/mfsa2009-49.html
https://bugzilla.mozilla.org/show_bug.cgi?id=506871
oval:org.mitre.oval:def:10730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10730
oval:org.mitre.oval:def:5606
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5606
Common Vulnerability Exposure (CVE) ID: CVE-2009-3078
1022875
http://www.securitytracker.com/id?1022875
http://www.mozilla.org/security/announce/2009/mfsa2009-50.html
https://bugzilla.mozilla.org/show_bug.cgi?id=453827
oval:org.mitre.oval:def:10871
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10871
oval:org.mitre.oval:def:5418
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5418
Common Vulnerability Exposure (CVE) ID: CVE-2009-3079
1022873
http://www.securitytracker.com/id?1022873
36757
http://secunia.com/advisories/36757
DSA-1886
http://www.debian.org/security/2009/dsa-1886
http://www.mozilla.org/security/announce/2009/mfsa2009-51.html
https://bugzilla.mozilla.org/show_bug.cgi?id=454363
oval:org.mitre.oval:def:10390
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10390
oval:org.mitre.oval:def:6250
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6250
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.